Security Operations Lead — Remote-First & Flexible Hours

Phoenix Court Group

United States

On-site

USD 134,000 - 211,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Remote-first company
Comprehensive health benefits
Equity and PTO

Job summary

Sword Health is seeking a Security Operations Lead to guide Sword’s Security Operations Center, architect its SIEM, drive detection engineering, and coordinate incident response across a multi-continent footprint. You will mentor engineers, implement AI- and automation-first security workflows, and partner with engineering, IT, and legal teams to reduce risk while scaling defenses for 700,000+ members.

As the hands-on technical lead, you’ll set the direction for MITRE-aligned detections and

Qualifications

  • Bachelor’s degree in CS/Cybersecurity or equivalent experience.
  • 7+ years in Security Operations.
  • Experience scaling a SOC through automation and AI with measurable MTTR impact.
  • Hands-on SOC structuring: SIEM selection, detection engineering, runbooks.
  • Strong incident response, forensics, and post-incident reviews.
  • Cloud security experience in AWS and/or GCP.
  • Fluency with NIST 800-61, CIS Controls, MITRE ATT&CK, ISO 27001; risk-based alert tuning.
  • Excellent communicator with executives and cross-functional teams.

Responsibilities

  • Lead the hands-on technical SOC lead for Sword’s SOC, architect SIEM, develop detection content, and guide incident response.
  • Own end-to-end SIEM: data sources, normalization, retention, cost, tuning; align to threat model.
  • Mentor detection engineers, manage on-call rotations, and act as incident commander for major events.
  • Define the operating model and roadmap to scale SOC capabilities across the company.
  • Drive AI- and automation-first security transformations (SOAR, LLM-assisted triage, ML-driven detections).
  • Lead high-severity investigations, root-cause analysis, and post-incident reviews.
  • Lead threat intelligence and hunting programs; translate findings into detections and mitigations.
  • Report SOC performance metrics to drive continuous improvement.
  • Influence security architecture across products and infrastructure; embed security into development.

Skills

Public Trust Clearance
SIEM Architecture
Incident Response
Automation & AI
Python/Go scripting
Threat Hunting
Cloud Security
Leadership

Education

BSc in Computer Science / Cybersecurity

Tools

Splunk
Sentinel
Chronicle
Elastic
AWS
GCP

Job description

Sword Health is seeking a Security Operations Lead to guide Sword’s Security Operations Center, architect its SIEM, drive detection engineering, and coordinate incident response across a multi-continent footprint. You will mentor engineers, implement AI- and automation-first security workflows, and partner with engineering, IT, and legal teams to reduce risk while scaling defenses for 700,000+ members.

As the hands-on technical lead, you’ll set the direction for MITRE-aligned detections and

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations Lead - AI-Driven SOC, Remote-First
Security Operations Lead - AI-Driven SOC, Remote-First

Neura Market • Northern (KY)

Hybrid
USD 150,000 - 190,000
Health insurance
401(k) plan
Paid holidays
+2
Security Operations Lead - AI-Driven SOC, Remote-First
Security Operations Lead - AI-Driven SOC, Remote-First

Sword Health, Inc. • United States

On-site
USD 134,000 - 211,000
Health insurance
Dental insurance
Vision insurance
+10
Senior SecOps Lead — AI Security & Incident (Remote)
Senior SecOps Lead — AI Security & Incident (Remote)

Sword Health • United States

On-site
USD 180,000 - 240,000
Comprehensive health, dental andvision
Life and AD&D Insurance
Equity shares
+6
Security Operations Leader: AI-Driven Threat Detection
Security Operations Leader: AI-Driven Threat Detection

Swordhealth • United States

On-site
USD 180,000 - 240,000
Senior Security Operations Engineer — Remote, AI‑Driven SOC
Senior Security Operations Engineer — Remote, AI‑Driven SOC

Sword Health • United States

On-site
USD 140,000 - 210,000
Health insurance
Equity shares
Remote-friendly environment
+2
AI-Driven Cloud SOC Lead (Remote)
AI-Driven Cloud SOC Lead (Remote)

Swordhealth • United States

Remote
USD 100,000 - 130,000
Comprehensive health, dental, and vision insurance
Life and AD&D insurance
Financial advisory services
+9
Security Operations Lead — Remote
Security Operations Lead — Remote

United States Digital Space LLC • United States

Remote
USD 185,000 - 296,000
Equity
Health, dental, vision
Retirement benefits
+6
Remote Security Operations Lead - NGSIEM & Threat Detection
Remote Security Operations Lead - NGSIEM & Threat Detection

Cognizant • Dallas (TX)

On-site
USD 115,000 - 130,000
Medical/Dental/Vision/Life Insurance
401(k) plan and contributions
Paid holidays/Paid Time Off
+1
Security Operations Lead — AI & Incident Response
Security Operations Lead — AI & Incident Response

Forward Financing • United States

On-site
USD 172,000 - 237,000
Remote-first company
Total rewards package
Office locations
+1
Senior Security Engineer: Remote Red Team & Detection
Senior Security Engineer: Remote Red Team & Detection

Mgsecureops • United States

On-site
USD 150,000 - 230,000
Remote work
Equity package
Health, dental, and vision insurance
+2