SECURITY OPERATIONS CENTER (SOC) LEAD (TIER III)
Jobgether
Full-timelead
Job description
Accountabilities:
• Lead, mentor, and develop junior and mid-level SOC analysts, fostering technical growth, knowledge sharing, and operational excellence.
• Act as the primary escalation point for high-priority and critical security incidents, driving investigations through to resolution.
• Oversee and enhance proactive threat hunting initiatives and detection engineering programs across enterprise environments.
• Monitor, triage, and investigate security alerts originating from SIEM, EDR, and other security monitoring platforms.
• Design, implement, and optimize advanced detection rules and threat monitoring strategies across Mac, Linux, and Windows environments.
• Conduct in-depth investigations related to malware, phishing campaigns, advanced persistent threats (APTs), and other sophisticated attack vectors.
• Perform proactive threat intelligence analysis and leverage OSINT sources to improve organizational security posture.
• Collaborate closely with Incident Response teams to escalate confirmed threats and coordinate remediation efforts.
• Develop clear documentation, incident reports, and actionable recommendations to strengthen security controls and operational processes.
• Partner with cross-functional IT and infrastructure teams to identify vulnerabilities, improve security frameworks, and support enterprise security initiatives.
• Participate in on-call rotations and ensure continuous SOC coverage in a 24x7 operational environment.
• Contribute to the development of security roadmaps, operational playbooks, and automation initiatives to improve efficiency and response capabilities.
Requirements
• 6–8+ years of experience within Security Operations Centers (SOC), including significant exposure to advanced incident response and technical leadership responsibilities.
• Proven experience leading and mentoring security teams in high-volume and fast-paced operational environments.
• Strong hands-on expertise with Endpoint Detection and Response (EDR) platforms, particularly CrowdStrike or equivalent technologies.
• Demonstrated experience developing and optimizing threat detection logic using CrowdStrike Query Language (CQL) or similar query languages.
• Extensive experience triaging security alerts and managing complex incidents across enterprise environments.
• Strong understanding of cybersecurity principles, threat landscapes, attack methodologies, and incident response frameworks.
• Proficiency in analyzing logs, network traffic, endpoint telemetry, and forensic artifacts across Mac, Linux, and Windows systems.
• Experience utilizing threat intelligence platforms, OSINT tools, and forensic methodologies to support investigations and threat hunting activities.
• Strong analytical, problem-solving, and decision-making skills, with the ability to remain effective under pressure.
• Excellent communication and documentation skills, with the ability to clearly articulate technical findings and remediation recommendations.
• Self-driven and proactive mindset with a demonstrated commitment to continuous learning and professional development.
Nice to Have
• Experience leading large-scale security transformation projects and contributing to strategic cybersecurity roadmaps.
• Knowledge of scripting languages such as Python for automation and workflow optimization.
• Experience developing automation workflows and playbooks using SOAR platforms, including CrowdStrike Fusion SOAR or similar technologies.
• Familiarity with cloud security concepts and environments, including AWS, Microsoft Azure, and Google Cloud Platform (GCP).
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline, or equivalent professional experience.
• Relevant cybersecurity certifications are considered advantageous.
Benefits
• Opportunity to lead advanced cybersecurity initiatives within a globally distributed and highly technical environment.
• Exposure to cutting-edge security technologies, threat intelligence capabilities, and enterprise-scale infrastructures.
• Collaborative and engineering-driven culture that values innovation, technical excellence, and continuous improvement.
• Significant ownership and influence over security operations strategies and detection engineering initiatives.
• Career development opportunities through mentorship, cross-functional collaboration, and exposure to complex cybersecurity challenges.
• Flexible remote work environment with global team interaction and knowledge-sharing opportunities.
• Supportive and inclusive workplace culture that encourages professional growth and continuous learning.
• Competitive compensation package aligned with experience and technical expertise.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1