Security Operations Lead

Jobtailor

Pennsylvania

On-site

USD 120,000 - 160,000

Full time

42 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a Security Operations expert to lead detection, triage, and response across the enterprise. You will independently manage complex security incidents and mentor SOC Analysts.

You will develop playbooks, write SIEM rules, and drive automation-first incident response, communicating findings to the CISO and executives.

Qualifications

  • Experience in Security Operations, Detection and Response.
  • 3–5 years in SOC, Detection, & Incident Handling.
  • Hands-on with SIEM and EDR platforms.
  • Proficiency in building incident response playbooks.
  • Strong written communication and executive summaries.

Responsibilities

  • Lead detection, triage, and response operations across the enterprise.
  • Independently lead complex or high-impact security incidents.
  • Identify opportunities to improve SOC processes, tools, and response capabilities.
  • Provide technical guidance and mentorship to SOC Analysts.
  • Build and operationalize SOC playbooks and escalation workflows.
  • Lead alert triage, enrichment, prioritization, and false-positive suppression.
  • Author detection requirements and tune SIEM rules.
  • Develop threat-hunting hypotheses and lead hunt efforts using advanced telemetry.
  • Design detection strategies across the kill chain and advance enterprise detection.
  • Execute complex incidents end-to-end, including containment, eradication, documentation, and communication.
  • Conduct post-incident reviews and drive remediation and control improvements.
  • Promote industry collaboration and embed resilient detection engineering practices.
  • Advocate for and implement automation-first incident response.
  • Establish standards for SOC documentation, communication, and delivery.
  • Influence technical direction and cross-functional outcomes.
  • Present complex technical information to the CISO and other executive leaders.

Skills

Security Operations
Threat Detection
Incident Response
SIEM Rule Authoring
Automation Scripting
Executive Communication

Tools

Google Security Operations
Microsoft Sentinel
IBM QRadar
CrowdStrike
Microsoft Defender
SentinelOne
SOAR Platforms

Job description

  • Lead detection, triage, and response operations across the enterprise
  • Independently lead complex or high-impact security incidents
  • Identify opportunities to improve SOC processes, tools, and response capabilities
  • Provide technical guidance and mentorship to SOC Analysts
  • Build and operationalize SOC playbooks and escalation workflows
  • Lead alert triage, enrichment, prioritization, and false-positive suppression
  • Author detection requirements and write and tune SIEM rules
  • Develop threat-hunting hypotheses and lead hunt efforts using advanced telemetry and threat intelligence
  • Design detection strategies across the kill chain and advance the enterprise detection strategy
  • Execute complex incidents end-to-end, including containment, eradication, documentation, and communication
  • Conduct post-incident reviews and drive remediation and control improvements
  • Promote industry collaboration and embed resilient detection engineering practices
  • Advocate for and implement automation-first incident response
  • Establish standards for SOC documentation, communication, and delivery
  • Influence technical direction and cross-functional outcomes
  • Present complex technical information to the CISO and other executive leaders
Requirements
  • Proven experience in a SOC or equivalent detection and response function, with a focus on high-fidelity detections, repeatable playbooks, and measurable outcomes
  • Three to five years of experience in Security Operations, Detection and Response, or Incident Handling; SOC experience is required
  • Hands-on experience with SIEM platforms such as Google Security Operations, Microsoft Sentinel, or IBM QRadar
  • Hands-on experience with EDR platforms such as CrowdStrike, Microsoft Defender, or SentinelOne
  • Hands-on experience with SOAR platforms
  • Proficiency in authoring detections, tuning rules, developing enrichment pipelines, and improving alert routing
  • Demonstrated experience building and executing incident-response playbooks and containment and eradication plans
  • Experience conducting post-incident reviews and root-cause analyses and delivering corrective action plans to engineering teams
  • Scripting skills in Python, PowerShell, or Bash for automation, enrichment, and data analysis
  • Excellent written communication skills, including case documentation and executive-ready incident summaries
  • Ability to influence technical direction and cross-functional outcomes through expertise and sound judgment, without formal people-management responsibility
  • Ability to transform noisy telemetry into actionable signals
  • Detail-oriented and disciplined in organizing information, developing repeatable playbooks, maintaining clear documentation, and closing feedback loops
  • Prepared to mentor other analysts and set standards for SOC communication and delivery
  • Comfortable presenting complex technical information to the CISO and other executive leaders
Core Competencies

Demonstrates expertise in leading security operations, incident response, and threat detection strategies, with a strong focus on developing and executing SOC playbooks and automation practices. Proficient in utilizing SIEM and EDR platforms to enhance detection capabilities and improve incident handling processes.

Highest-signal resume keywords
  • Security Operations Experience
  • SIEM Platform Proficiency
  • Incident Response Playbook Development
  • Scripting Skills in Python
  • Technical Communication Skills
Hard Skills
  • Incident Handling
  • Threat Detection
  • SIEM Rule Authoring
  • Alert Triage
  • Post-Incident Review
  • Root-Cause Analysis
  • Automation Scripting
  • Data Analysis
  • Enrichment Pipeline Development
  • Containment and Eradication Plans
Soft Skills
  • Mentorship
  • Detail-Oriented
  • Influencing Technical Direction
  • Organizational Skills
  • Communication Skills
Industry Keywords
  • SOC
  • Detection and Response
  • High-Fidelity Detections
  • Automation-First Incident Response
  • Threat Intelligence
Tools & Technologies
  • Google Security Operations
  • Microsoft Sentinel
  • IBM QRadar
  • CrowdStrike
  • Microsoft Defender
  • SentinelOne
  • SOAR Platforms
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Detection and platform engineer
Detection and platform engineer

Tixy Services LLC • Town of Texas (WI), Fort Worth (TX)

Hybrid
USD 120,000 - 180,000
SOC Engineer
SOC Engineer

No Limit Staffing, Inc. • United States

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

Jobtailor • Town of Montana (WI)

On-site
USD 85,000 - 125,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
SOC Engineer
SOC Engineer

Tenex • Sarasota (FL), Scottsdale (AZ), Kansas City (MO)

On-site
USD 90,000 - 140,000
SOC Engineer
SOC Engineer

TENEX.AI • United States

On-site
USD 100,000 - 130,000
Senior SOC Analyst
Senior SOC Analyst

Soni • Philadelphia

On-site
USD 90,000 - 120,000
Tier 2 Security Operations Center (SOC) Analyst
Tier 2 Security Operations Center (SOC) Analyst

Jobtailor • California (MO)

On-site
USD 95,000 - 125,000
SOC Lead
SOC Lead

Soni • Philadelphia

On-site
USD 140,000 - 180,000
Security Operations Lead
Security Operations Lead

New York Technology Partners • Chicago (IL)

On-site
USD 120,000 - 190,000