Security Operations Lead

New York Technology Partners

Chicago (IL)

On-site

USD 120,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

New York Technology Partners in Chicago is seeking an experienced SOC leader to drive modernization and standardize end-to-end SOC workflows. You will partner with the Director of Information Security to map a modernization roadmap and deliver measurable improvements across people, process, and technology.

Responsibilities include implementing AI-assisted SOC capabilities, coordinating SIEM/EDR/SOAR integrations, and defining guardrails, metrics, and governance.

Qualifications

  • 5+ years in security operations / SOC engineering or incident response.
  • Strong understanding of SOC workflows and escalation/handoff patterns.
  • Experience with SIEM/EDR ecosystems and API/webhook integrations.
  • Proven ability to drive operational change with playbooks, metrics, and training.
  • Strong written communication and stakeholder management.

Responsibilities

  • Build and execute a SOC modernization roadmap with the Director of Information Security.
  • Standardize SOC workflows: intake, triage, investigation, escalation, closure.
  • Establish operational rhythms: queue health checks, weekly ops review, monthly metrics.
  • Lead AI-assisted SOC capabilities and automation initiatives.
  • Oversee tooling integrations across SIEM/EDR/SOAR and cloud telemetry.
  • Define KPIs and drive continuous improvement via reviews and post-case learnings.

Skills

SOC operations experience
SOC workflows & escalation
SIEM/EDR integration
operational change management
written communication & stakeholder mg

Tools

SIEM/EDR ecosystems
APIs & webhooks
SOAR tooling

Job description

  • Work with the Director of Information Security to build and execute a SOC modernization roadmap
  • Standardize SOC workflows: intake, triage, investigation, escalation/handoff, closure
  • Establish operational rhythms: queue health checks, weekly ops review, monthly metrics and outcomes, tabletop exercises & reviews
AI SOC agents & workflow automation
  • Implement AI-assisted SOC capabilities that support analysts, including:
  • Alert clustering/deduplication and prioritization support
  • Automated enrichment (asset/user context, baselines, threat intel, cloud context)
  • Investigation copilots (timeline generation, query suggestions, correlation summaries)
  • Draft case notes and executive-ready incident summaries with links back to source evidence
  • Assist with defining guardrails for AI usage: human approval gates, scoped permissions, audit trails, redaction/data handling, and “no unsupported claims” standards
  • Evaluate vendors and/or internal approaches; run pilots, measure results, and lead production rollouts
Tooling & integration leadership
  • Coordinate integrations across SIEM, EDR, SOAR, cloud telemetry, ticketing, and collaboration/on-call tooling
  • Partner with Platform Engineering to improve telemetry pipelines (parsing, normalization, enrichment, retention)
  • Define operational acceptance criteria for changes (signal quality, latency, reliability, access controls)
  • Partner with the Director of Information Security to drive SOC operational KPIs (e.g., time-to-triage, case aging, escalation completeness, automation coverage)
  • Drive continuous improvement via regular reviews, quality sampling, and post-case learnings
  • Identify recurring pain points and implement targeted fixes (playbooks, automation, training, data improvements)
  • Train and mentor analysts on standard workflows and effective use of AI-assisted tooling
  • Improve cross-functional handoffs between SOC, Engineering, IT, and Platform teams
  • Provide concise operational updates to the Director of Information Security and leadership stakeholders
Required qualifications
  • 5+ years in security operations / SOC engineering / incident response operations (or equivalent)
  • Strong understanding of SOC workflows, incident lifecycle, and escalation/handoff patterns
  • Experience with SIEM/EDR ecosystems and integrating security tooling via APIs/webhooks
  • Demonstrated ability to drive operational change: playbooks, metrics, quality, training, adoption
  • Strong written communication and stakeholder management
Preferred qualifications
  • Experience deploying AI-assisted SOC tooling (copilots/agents) with governance
  • SOAR/automation experience with approval-gated actions and safe defaults
  • Familiarity with WQL (Wazuh), SPL (Splunk) and/or KQL (Microsoft Sentinel) and light scripting (Python/Bash)
  • Cloud and identity familiarity (AWS/Azure/GCP, SSO/MFA/IAM)
What success looks like
  • SOC workflows are consistent and measurable across analysts/shifts
  • Alert noise is reduced, and investigations start with better context and faster handoffs
  • AI-assisted tooling improves analyst throughput and documentation quality with strong guardrails
  • Integrations and telemetry quality improvements materially reduce friction and case aging
  • Leadership has clear metrics that show SOC operational uplift over time
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Engineer
SOC Engineer

TENEX.AI • United States

On-site
USD 100,000 - 130,000
SOC Engineer
SOC Engineer

TENEX.AI • Town of Florida (NY)

On-site
USD 100,000 - 130,000
SOC Lead
SOC Lead

Soni • Philadelphia

On-site
USD 140,000 - 180,000
SOC Manager
SOC Manager

Stellar IT Solutions LLC • St. Louis (MO)

On-site
USD 120,000 - 160,000
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
SOC Engineer
SOC Engineer

Tenex • Sarasota (FL), Scottsdale (AZ), Kansas City (MO)

On-site
USD 90,000 - 140,000
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
Agentic SOC Analyst
Agentic SOC Analyst

Arcitix Security • United States

On-site
USD 75,000 - 95,000
Security Operations Center Analyst
Security Operations Center Analyst

Diligente Technologies • San Jose (CA)

On-site
USD 80,000 - 100,000
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • California (MO)

Remote
USD 163,000 - 184,000