Senior Security Operations & Engineering Leader

Envista Holdings Corporation

Brea (CA)

On-site

USD 156,000 - 191,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Envista is seeking an on‑site Security Operations and Engineering Lead in California to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities. The role owns the SOC, incident response program, detection lifecycle, and tooling ecosystem to deliver scalable, threat‑informed security operations.

The candidate will lead enterprise security operations, manage SOC/MSSP partnerships, and define metrics for MTTD/MTTR.

Qualifications

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or related fields OR equivalent industry experience.
  • 7+ years of cybersecurity experience in security operations, detection engineering, incident response, or security engineering.
  • 5+ years leading security operations, engineering, SOC, or incident response teams.
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.
  • Experience managing MSSP, MDR, SOC-as-a-Service, or strategic security service providers.
  • Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Chronicle, etc.).
  • Experience in Azure, AWS, or GCP environments.
  • Understanding of Zero Trust security principles and modern detection strategies.
  • Ability to communicate technical risks to executive leadership and business stakeholders.
  • Experience coordinating investigations across security, IT, legal, privacy, HR, and executive stakeholders.

Responsibilities

  • Lead enterprise security operations including monitoring, triage, investigation, escalation, and response.
  • Oversee SOC and MSSP/MDR partnerships including SLAs, alert quality, escalation paths, and performance metrics.
  • Establish 24x7 monitoring aligned to enterprise risk.
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness.
  • Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms.
  • Drive automation across triage, enrichment, containment, and reporting workflows.
  • Define enterprise logging and telemetry strategy including onboarding, parsing, normalization, retention, and coverage standards.
  • Ensure tools are integrated, cost‑effective, and aligned to risk priorities.
  • Own incident response program including playbooks, exercises, breach workflows, and communications.
  • Lead major incidents through containment, eradication, recovery, and root cause analysis.
  • Ensure post‑incident reviews drive durable control improvements.
  • Coordinate with Legal, Privacy, HR, IT, and Communications.
  • Build detection engineering lifecycle: hypothesis → development → testing → tuning → deployment → validation → retirement.
  • Develop behavior‑based and threat‑informed detections aligned to MITRE ATT&CK.
  • Expand monitoring across endpoint, identity, cloud, SaaS, network, and critical applications.
  • Identify and close detection gaps via red team, pentest, and vulnerability insights.
  • Support exposure management, asset inventory visibility, and attack surface monitoring.
  • Drive continuous control monitoring and validation of key security controls.
  • Improve vulnerability remediation workflows and risk reduction outcomes.
  • Build and lead high‑performing security operations and engineering teams.
  • Establish clear roles, operating model, and accountability.
  • Provide executive reporting on threats, incidents, control gaps, and maturity.
  • Partner with GRC, Audit, IT, Architecture, and business leadership.

Skills

SOC leadership
Security engineering
Incident response
Threat management
Detection engineering
Automation
Cloud security
MITRE ATT&CK

Education

Bachelor’s degree or equivalent experience

Tools

Microsoft Sentinel
Splunk
QRadar
Chronicle

Job description

Envista is seeking an on‑site Security Operations and Engineering Lead in California to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities. The role owns the SOC, incident response program, detection lifecycle, and tooling ecosystem to deliver scalable, threat‑informed security operations.

The candidate will lead enterprise security operations, manage SOC/MSSP partnerships, and define metrics for MTTD/MTTR.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Ops Lead for Mission-Critical Space & GovSec
Security Ops Lead for Mission-Critical Space & GovSec

Industrious Ventures • Torrance (CA)

On-site
USD 120,000 - 150,000
Security Operations Lead — Incident Response & Detection
Security Operations Lead — Incident Response & Detection

enVista • Carmel (IN)

Hybrid
USD 120,000 - 150,000
Competitive pay bonuses
Comprehensive health coverage
PTO and sabbatical programme
+3
Senior Security Operations Lead — SIEM/IR, Hybrid
Senior Security Operations Lead — SIEM/IR, Hybrid

enVista Corp. • Carmel (IN)

Hybrid
USD 140,000 - 190,000
Life Insurance
Short/Long Term Disability
401k with Company Matching
+2
Lead Security Engineer
Lead Security Engineer

Compunnel, Inc. • Washington, Northern (KY)

Hybrid
USD 140,000 - 210,000
Senior Cybersecurity Engineer: SOC & Threat Intel Lead
Senior Cybersecurity Engineer: SOC & Threat Intel Lead

DIVERGENT • Torrance (CA)

On-site
USD 157,000 - 236,000
Equity
Paid time off
Parental leave
+5
Security Ops Lead for Mission-Critical Space & GovSec
Security Ops Lead for Mission-Critical Space & GovSec

Northwood Space • Torrance (CA)

On-site
USD 120,000 - 160,000
Senior Director of Security Operations
Senior Director of Security Operations

Code Red Partners • United States

On-site
USD 180,000 - 280,000
Remote Security Operations & Threat Hunting Lead
Remote Security Operations & Threat Hunting Lead

Apex Systems • Mountain View (CA)

Remote
ESPP
401K program
HSA (HDHP plan)
+1
Senior SOC Engineer - EDR & Detection Platform Lead
Senior SOC Engineer - EDR & Detection Platform Lead

Sandisk • Milpitas (CA)

On-site
USD 140,000 - 210,000
Security Operations Engineer: Incident Response & Threat Detection
Security Operations Engineer: Incident Response & Threat Detection

Vertex Inc. • United States

On-site
USD 91,000 - 119,000