Security Operations Lead: AI-Driven SOC & Response

Sword Health

United States

On-site

USD 134,000 - 211,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Sword Health seeks a Security Operations Lead to helm the SOC, architect SIEM and detection content (MITRE-aligned), and drive AI- and automation-first security initiatives across a global footprint. You will mentor engineers, manage incident response, and partner with engineering, IT, and legal to elevate security posture.

You will define operating models, build scalable processes, and report on MTTD/MTTR metrics while ensuring investigations and post-incident reviews translate into durable

Qualifications

  • Public Trust Clearance required: must be able to obtain/maintain a US public trust clearance.
  • Bachelor's degree in Computer Science, Cybersecurity, or equivalent professional experience.
  • 7+ years experience in Security Operations.
  • Proven experience scaling a SOC through automation and AI with measurable impact on MTTR, coverage, or analyst leverage.
  • Hands-on experience structuring a SOC and operating metrics.
  • Deep SIEM expertise (Splunk, Sentinel, Chronicle, Elastic) and detection engineering.
  • Experience leading SOC/CSIRT teams including on-call/incident commander duties.
  • Cloud security experience (AWS/GCP).
  • Strong scripting/development skills for automation and tooling.
  • Excellent communicator with executives and cross-functional collaboration.
  • Forensics experience.

Responsibilities

  • Serve as hands-on technical lead for Sword's Security Operations Center and set the technical direction.
  • Own the SIEM end-to-end architecture and detection-content OKR aligned to MITRE ATT&CK.
  • Lead the SOC/CSIRT team technically and mentor engineers.
  • Define operating model and roadmaps for SIEM and detection architecture.
  • Drive AI- and automation-first transformation of security operations with SOAR and ML-driven detection.
  • Lead high-severity incident response and post-incident reviews with cross-functional partners.
  • Run threat intelligence and threat hunting programs; translate TTPs into detections.
  • Define SOC performance metrics and drive continuous improvement.
  • Influence security architecture across products and infrastructure from day one.
  • Develop and maintain YARA-L detection rules and SOAR playbooks.

Skills

Public Trust Clearance
Experience in Security Operations
Automation/AI for SOC
SOC structure/leadership
Incident response leadership
Cloud security (AWS/GCP)
Scripting/Development (Python/Go/Bash)
Communication with executives
Forensics experience

Education

Bachelor's degree in Computer Science, Cybersecurity, or equivalent

Tools

Splunk
Microsoft Sentinel
Google SecOps/Chronicle
Elastic

Job description

Sword Health seeks a Security Operations Lead to helm the SOC, architect SIEM and detection content (MITRE-aligned), and drive AI- and automation-first security initiatives across a global footprint. You will mentor engineers, manage incident response, and partner with engineering, IT, and legal to elevate security posture.

You will define operating models, build scalable processes, and report on MTTD/MTTR metrics while ensuring investigations and post-incident reviews translate into durable

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Leader: AI-Driven Threat Detection
Security Operations Leader: AI-Driven Threat Detection

Swordhealth • United States

On-site
USD 180,000 - 240,000
Senior SOC Analyst — AI-Driven Incident Response
Senior SOC Analyst — AI-Driven Incident Response

BeyondTrust • United States

On-site
USD 90,000 - 130,000
Security Operations Lead: 24/7 AI-Driven SOC
Security Operations Lead: 24/7 AI-Driven SOC

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
Global Security Operations Lead – AI-Driven SOC
Global Security Operations Lead – AI-Driven SOC

Replit • Foster City (CA)

On-site
USD 295,000 - 385,000
401(k) match
Health insurance
Dental & Vision
+4
Senior SOC Lead: Incident Response & Threat Detection
Senior SOC Lead: Incident Response & Threat Detection

5195 EKC Advanced Electronics USA, LLC • Delaware

On-site
USD 120,000 - 180,000
Security Operations Lead
Security Operations Lead

New York Technology Partners • Chicago (IL)

On-site
USD 120,000 - 190,000
AI Security Operations Lead: Threat-Driven Response
AI Security Operations Lead: Threat-Driven Response

Veriipro • Center Square (PA)

On-site
USD 140,000 - 190,000
Security Operations Center Manager
Security Operations Center Manager

AGS • Boulder (CO)

On-site
USD 140,000 - 200,000
AI-Driven SOC Lead: Detection & 24/7 Response
AI-Driven SOC Lead: Detection & 24/7 Response

Gomotive • Northern (KY)

Remote
USD 140,000 - 200,000
Health benefits
Paid time off
401k plan
AI-Enabled SOC Architect & Incident Response Lead
AI-Enabled SOC Architect & Incident Response Lead

Quantum Software • Redmond (WA)

On-site
USD 150,000 - 210,000