Security Operations Leader: Detection & Incident Response

Envista

Brea (CA)

On-site

USD 156,000 - 191,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Health & Wellbeing
Retirement & Financial Benefits
Life & Disability Insurance
Paid Time Off
Learning & Career Development

Job summary

Envista seeks a strategic Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, and incident response. This onsite role manages the SOC, IAM, and security tooling, coordinating with MSSP/MDR partners and cross-functional teams.

The position requires guiding a threat-informed security program, building scalable detections, and leading incidents from containment to lessons learned. Relocation to Irvine/Brea area anticipated, 4 days onsite.

Qualifications

  • 7+ years of experience in cybersecurity, security operations, detection engineering, or incident response.
  • 5+ years leading security operations, engineering, SOC, or incident response teams.
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.
  • Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Chronicle).
  • Experience in Azure, AWS, or GCP environments.
  • Ability to communicate technical risks to executive leadership and business stakeholders.

Responsibilities

  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response.
  • Oversee SOC and MSSP/MDR partnerships with SLAs, alert quality, escalation paths, and metrics.
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, and detection coverage.
  • Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity, and cloud platforms.
  • Coordinate major incidents through containment, eradication, and recovery with post-incident reviews.
  • Build detection engineering lifecycle: hypothesis testing, tuning, deployment, and retirement.
  • Partner with Legal, Privacy, HR, IT, and Communications for incident handling and governance.
  • Drive automation across triage, enrichment, containment, and reporting workflows.

Skills

Security leadership
Security operations management
Incident response coordination
Threat detection engineering
MITRE ATT&CK approach
Cloud security

Education

Bachelor's degree in Information Security, Cybersecurity, CS, IS, Business, Engineering, or related field

Tools

Microsoft Sentinel
Splunk
QRadar
Chronicle
EDR/XDR tooling

Job description

Envista seeks a strategic Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, and incident response. This onsite role manages the SOC, IAM, and security tooling, coordinating with MSSP/MDR partners and cross-functional teams.

The position requires guiding a threat-informed security program, building scalable detections, and leading incidents from containment to lessons learned. Relocation to Irvine/Brea area anticipated, 4 days onsite.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Leader: Detection, IR & Platform Engineering
Security Operations Leader: Detection, IR & Platform Engineering

Envista Holdings Corporation • Brea (CA)

On-site
USD 156,000 - 191,000
Annual bonus
Medical benefits
401K match
+1
Security Operations Lead — Incident Response & Detection
Security Operations Lead — Incident Response & Detection

enVista • Carmel (IN)

Hybrid
USD 120,000 - 150,000
Competitive pay bonuses
Comprehensive health coverage
PTO and sabbatical programme
+3
Security Ops Leader: Detection Eng. & Incident Response
Security Ops Leader: Detection Eng. & Incident Response

Pure Storage, Inc. • Santa Clara (CA)

On-site
USD 225,000 - 281,000
Equity
Incentive pay
Flexible time off
+1
Security Operations Engineer: Incident Response & Detection
Security Operations Engineer: Incident Response & Detection

Vertex Inc. • Northern (KY)

Hybrid
USD 91,000 - 119,000
Senior SecOps Leader: Detection & Incident Response
Senior SecOps Leader: Detection & Incident Response

Everpure • Santa Clara (CA)

On-site
USD 225,000 - 281,000
Equity
Flexible PTO
Career development
Security Operations Engineer – Incident Response & Detection
Security Operations Engineer – Incident Response & Detection

Vertex, Inc. • King of Prussia (PA)

On-site
USD 91,000 - 119,000
Detection & Response Lead - Cloud & IR
Detection & Response Lead - Cloud & IR

Isccareers • United States

On-site
USD 160,000 - 200,000
Employee Ownership Program
Professional development opportunities
Work from home reimbursement forremote
+3
Detection and Response Lead
Detection and Response Lead

Integrated Specialty Coverages, LLC • United States

On-site
USD 120,000 - 180,000
SOC Lead: 24/7 Incident Detection & Response
SOC Lead: 24/7 Incident Detection & Response

Optimalsemi • United States

On-site
USD 140,000 - 190,000
Security Operations Lead — Automation & Team Leadership
Security Operations Lead — Automation & Team Leadership

EnVista • Carmel (IN)

On-site
USD 120,000 - 180,000
Competitive compensation
Bonuses
Medical Insurance