Threat Operations Lead & Incident Response

Wedbush

Pasadena (CA)

Hybrid

USD 154,000 - 184,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) match
Tuition reimbursement
Paid time off
Parental leave

Job summary

Wedbush Securities in Pasadena, CA seeks an Assistant Vice President of Threat Operations to lead the security operations function, oversee threat monitoring, detection, incident response, and forensics across the enterprise. This hybrid role reports to the CISO and requires strong leadership of security engineers and analysts.

The candidate will manage detection coverage, coordinate major incident responses, and align policies with FINRA/SEC obligations, while driving automation and process

Qualifications

  • Bachelor's Degree from an accredited university.
  • CISSP (Certified Information Systems Security Professional) required.
  • 7+ years of relevant work experience required, with 5+ years of previous managerial experience.
  • GCIH (GIAC Certified Incident Handler), GCFA (GIAC Certified Forensic Analyst), GCFE (GIAC Certified Forensic Examiner), GCIA (GIAC Certified Intrusion Analyst), or CISM (Certified Information Security Manager) preferred.
  • Demonstrated ability to lead, develop, and retain technical security teams, including performance management and coaching.
  • Expertise in incident response, digital forensics, evidence collection and preservation, and threat intelligence.
  • Working command of security operations tooling, including SIEM, endpoint detection and response, and security orchestration and automation platforms.
  • Experience defining repeatable operational processes and documenting remediation to an auditable standard.
  • Strong analytical and problem solving ability, with sound judgment under time pressure during active incidents.
  • Ability to communicate complex technical concepts clearly, verbally and in writing, to technical and non-technical audiences including senior leadership.
  • Ability to collaborate effectively with cross-functional teams and stakeholders across Technology, Compliance, and Legal.
  • Working knowledge of the regulatory environment applicable to a broker-dealer, including data protection and incident notification obligations.
  • Demonstrated commitment to staying current with security threats, trends, and technologies.

Responsibilities

  • Oversee day-to-day security operations, including threat monitoring, detection, alert triage, and escalation across the enterprise
  • Lead incident response end to end (contain, mitigate, eradicate, recover), driving post-incident review and remediation to closure
  • Direct digital forensic investigations to establish root cause, scope, and impact, ensuring defensible evidence collection; serve as senior escalation point and coordinate the Firm's technical response to major incidents
  • Mature detection coverage through detection engineering, tuning, and false-positive reduction, integrating threat intelligence into monitoring and hunting; unify monitoring, detection, and response into a single view across threat operations
  • Own the operational execution of the Firm's data protection and incident escalation obligations as a FINRA- and SEC-registered broker-dealer.
  • Improve operations processes and workflows, tracking metrics such as MTTD/MTTR to drive measurable gains; champion automation and playbook development to standardize response
  • Develop and execute the security operations strategy, policies, and playbooks aligned to Firm goals, risk appetite, and regulatory obligations; partner with Technology, Compliance, Legal, and leadership to communicate risk and priorities, elevate per broker-dealer obligations, support regulatory exams/audits/client notifications, and translate technical issues for technical and executive audiences
  • Own workload allocation, staffing coverage, and on-call rotation; identify capability gaps and build the business case for tooling, training, or headcount
  • Hire, manage, coach, and set pay for security engineers, responders, and forensic analysts
  • Set goals, run performance reviews, and build development plans to strengthen team capability across monitoring, response, and forensics
  • Perform other duties as required and assigned

Skills

Bachelor's degree
CISSP
Security leadership
Incident response
Digital forensics
Threat intelligence
Security tooling
Communication
Regulatory awareness
Team coaching

Education

Bachelor's Degree

Tools

SIEM
EDR (Endpoint Detection & Response)
SOAR platforms

Job description

Wedbush Securities in Pasadena, CA seeks an Assistant Vice President of Threat Operations to lead the security operations function, oversee threat monitoring, detection, incident response, and forensics across the enterprise. This hybrid role reports to the CISO and requires strong leadership of security engineers and analysts.

The candidate will manage detection coverage, coordinate major incident responses, and align policies with FINRA/SEC obligations, while driving automation and process

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assistant Vice President, Threat Operations
Assistant Vice President, Threat Operations

Wedbush • Pasadena (CA)

Hybrid
USD 154,000 - 184,000
Medical, dental, vision
401(k) match
Tuition reimbursement
+2
Cybersecurity Incident Response Team Lead – Vice President
Cybersecurity Incident Response Team Lead – Vice President

Crédit Agricole Group • New York (NY)

On-site
USD 150,000 - 185,000
Senior Security Operations Lead - Threat Hunting & IR
Senior Security Operations Lead - Threat Hunting & IR

DLA Piper • Baltimore (MD)

Hybrid
USD 94,000 - 131,000
Security Ops Lead for Mission-Critical Space & GovSec
Security Ops Lead for Mission-Critical Space & GovSec

Industrious Ventures • Torrance (CA)

On-site
USD 120,000 - 150,000
Senior InfoSec Analyst - Threat Hunting & IR Lead (Hybrid)
Senior InfoSec Analyst - Threat Hunting & IR Lead (Hybrid)

DLA Piper • Austin (TX)

Hybrid
USD 94,000 - 131,000
Medical Insurance
Dental Insurance
401(k) Plan
+1
SOC Operations Analyst: Threat Monitoring & Incident Response
SOC Operations Analyst: Threat Monitoring & Incident Response

Inter-Con Security • Pasadena (CA)

On-site
USD 65,000 - 95,000
Senior Cyber Threat & Incident Response Lead
Senior Cyber Threat & Incident Response Lead

Raymond James Financial, Inc. • Town of Florida (NY), Northern (KY)

Hybrid
USD 120,000 - 180,000
Security Operations Manager, 24x7 SOC Lead
Security Operations Manager, 24x7 SOC Lead

Talanto • Los Angeles (CA), Northern (KY)

Hybrid
USD 203,000 - 285,000
Stunning offices in CA & TX
Competitive compensation
Premium health coverage
+2
Associate SOC Engineer: Threat Detection & Response
Associate SOC Engineer: Threat Detection & Response

Conference of State Bank Supervisors (CSBS) • Washington

Hybrid
USD 70,000 - 110,000
Comprehensive benefits
Hybrid work environment
Cyber Threat Detection and Response Analyst
Cyber Threat Detection and Response Analyst

PTY TECH, LLC • Jacksonville (FL)

On-site
USD 85,000 - 130,000