Security Operations Lead

ASM Global LLC.

Legends (SC)

Hybrid

USD 120,000 - 180,000

Full time

10 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision insurance
Life insurance
Disability insurance
Paid vacation
401k plan

Job summary

Legends Global is seeking a Security Operations Lead in a Hybrid role, located at Dallas/Frisco, TX or Conshohocken, PA. You will guide complex incidents, tune detections, and advance enterprise detection, while mentoring SOC analysts and shaping playbooks.

The role reports to the VP, Cyber Security within Technology, offering a comprehensive benefits package and opportunities to influence security strategy across a global venue network.

Qualifications

  • Three to five years of experience in Security Operations, Detection and Response, or Incident Handling; SOC experience required.
  • Hands-on experience with SIEMs like Google Security Operations, Microsoft Sentinel, or QRadar; EDR like CrowdStrike, Microsoft Defender, or SentinelOne; and SOAR platforms.
  • Proficiency in scripting for automation, enrichment, and data analysis; strong executive-ready incident summaries.

Responsibilities

  • Independently lead complex or high-impact security incidents and improve SOC processes, tools, and response capabilities.
  • Provide technical guidance and mentorship to SOC Analysts; establish standards for documentation and delivery.
  • Build and operationalize SOC playbooks and escalation workflows; lead alert triage and false-positive suppression.

Skills

Python scripting
PowerShell scripting
Bash scripting
Written communication
Incident handling
Threat detection

Tools

Google Security Operations
Microsoft Sentinel
IBM QRadar
CrowdStrike
Microsoft Defender
SentinelOne
SOAR platforms

Job description

Position

Security Operations Lead

Location

Hybrid (This person can be based out of our Dallas/Frisco, TX or Conshohocken, PA Corporate Headquarters)

Department

Technology

Reports To

VP, Cyber Security

Company Overview

LEGENDS GLOBAL Legends Global is the premier partner to the world’s greatest live events, venues, and brands. We deliver a fully integrated suite of premium services through a white-label model that keeps our partners front and center - from feasibility and project development to sales, partnerships, hospitality, merchandise, venue management, and world-class content and booking. With a global network of more than 450 venues, hosting 20,000 events and welcoming 165 million guests annually, Legends Global brings unmatched scale, expertise, and connectivity to help our partners grow. The Legends Global Way guides how we operate: Align, Scale, Connect, Team, Win - shared success, repeatable systems, connected solutions, unstoppable teams, and wins that are earned every day.

Key Responsibilities
  • Independently lead complex or high-impact security incidents and identify opportunities to improve SOC processes, tools, and response capabilities.
  • Provide technical guidance and mentorship to SOC Analysts, sharing best practices and establishing standards for documentation, communication, and delivery.
  • Build and operationalize SOC playbooks and escalation workflows.
  • Lead alert triage, enrichment, prioritization, and false-positive suppression.
  • Author detection requirements and write and tune SIEM rules.
  • Develop threat-hunting hypotheses and lead hunt efforts using advanced telemetry and threat intelligence.
  • Design detection strategies across the kill chain and help advance the enterprise detection strategy.
  • Execute complex incidents end-to-end, including containment, eradication, documentation, and communication.
  • Conduct post-incident reviews and drive remediation and control improvements.
  • Promote industry collaboration and embed resilient detection engineering practices.
  • Advocate for and implement automation-first incident response.
  • Provide technical guidance and mentorship to SOC Analysts, sharing best practices and setting standards for documentation, communication, and delivery.
Education and Experience

Proven experience in a SOC or equivalent detection and response function, with a focus on high-fidelity detections, repeatable playbooks, and measurable outcomes. Three to five years of experience in Security Operations, Detection and Response, or Incident Handling; SOC experience is required. Hands-on experience with SIEM platforms, such as Google Security Operations, Microsoft Sentinel, or IBM QRadar; EDR platforms, such as CrowdStrike, Microsoft Defender, or SentinelOne; and SOAR platforms. Proficiency in authoring detections, tuning rules, developing enrichment pipelines, and improving alert routing. Demonstrated experience building and executing incident-response playbooks and containment and eradication plans. Experience conducting post-incident reviews and root-cause analyses and delivering corrective action plans to engineering teams. Scripting skills in Python, PowerShell, or Bash for automation, enrichment, and data analysis. Excellent written communication skills, including case documentation and executive-ready incident summaries. Proficient in authoring detections, rule tuning, enrichment pipelines, and alert routing. Demonstrated capability in building and executing IR playbooks and containment/eradication plans. Experience conducting post-incident reviews and RCAs, and delivering corrective action plans to engineering teams. Scripting skills (Python/PowerShell/Bash) for automation, enrichment, and data wrangling. Excellent written communication for case documentation and executive-ready incident summaries.

Desired Skills and Abilities
  • Demonstrates the ability to influence technical direction and cross-functional outcomes through expertise and sound judgment, without formal people-management responsibility.
  • Transforms noisy telemetry into actionable signals.
  • Is detail-oriented and disciplined in organizing information, developing repeatable playbooks, maintaining clear documentation, and closing feedback loops.
  • Is prepared to mentor other analysts and set standards for SOC communication and delivery.
  • Influences technical direction and cross-functional outcomes through expertise and sound judgment.
  • Is comfortable presenting complex technical information to the CISO and other executive leaders.
Compensation

Competitive salary, commensurate with experience, and a generous benefits package that includes medical, dental, vision, life and disability insurance, paid vacation, and 401k plan.

Working Conditions

Location: Hybrid (This person can be based out of our Dallas/Frisco, TX or Conshohocken, PA Corporate Headquarters) NOTE: The essential responsibilities of this position are described under the headings above. They may be subject to change at any time due to reasonable accommodation or other reasons. Also, this document in no way states or implies that these are the only duties to be performed by the employee occupying this position. Legends Global is an Equal Opportunity/Affirmative Action employer, and encourages Women, Minorities, Individuals with Disabilities, and protected Veterans to apply. VEVRAA Federal Contractor. Our Work Experience is the combination of everything that's unique about us: our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people. Our employees are self-disciplined, hard working, curious, trustworthy, humble, and truthful. They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the #1 Top Workplace in the area.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Lead
Security Operations Lead

Legends Global • West Conshohocken (PA)

On-site
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+3
Security Operations Lead
Security Operations Lead

Legends Global • Frisco (TX)

Hybrid
USD 120,000 - 150,000
Medical insurance
Dental and Vision insurance
Life and Disability insurance
+2
Senior SOC Lead – Detection & Response
Senior SOC Lead – Detection & Response

Legends Global • Frisco (TX)

Hybrid
USD 120,000 - 150,000
Medical insurance
Dental and Vision insurance
Life and Disability insurance
+2
Senior SOC Lead — Hybrid Incident Response
Senior SOC Lead — Hybrid Incident Response

Legends Global • West Conshohocken (PA)

Hybrid
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior SOC Lead — Incident Response & Threat Hunting
Senior SOC Lead — Incident Response & Threat Hunting

ASM Global LLC. • Legends (SC)

Hybrid
USD 120,000 - 180,000
Medical insurance
Dental insurance
Vision insurance
+4
SOC Lead
SOC Lead

Soni • Philadelphia

On-site
USD 140,000 - 180,000
Lead SOC Analyst
Lead SOC Analyst

UFP Industries, Inc. • Grand Rapids (MI)

On-site
USD 90,000 - 120,000
Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
Safety & Security Lead
Safety & Security Lead

Legends • Tucson (AZ), Northern (KY)

Hybrid
USD 70,000 - 90,000
Senior Cybersecurity Consultant, Blue Team Lead
Senior Cybersecurity Consultant, Blue Team Lead

Layer8security • Northern (KY)

Hybrid
USD 120,000 - 190,000
Medical insurance
Life insurance
Unlimited vacation
+2