We are looking for a Lead SecOps Engineer to help protect our systems, applications, and data from evolving threats. You'll work at the intersection of security monitoring, incident response, and automation — building the detection and response capabilities that keep our environment secure.
Responsibilities
- Monitor security alerts and logs across endpoints, network, cloud, and applications (SIEM/SOAR platforms)
- Investigate and respond to security incidents, performing triage, containment, and root-cause analysis
- Develop and tune detection rules, correlation logic, and alerting to reduce false positives and close coverage gaps
- Build and maintain automation/playbooks for incident response (SOAR)
- Conduct vulnerability management, including scanning, prioritization, and coordinating remediation with engineering teams
- Perform threat hunting to proactively identify malicious activity
- Support security tooling deployment and integration (EDR, SIEM, cloud security posture tools, IAM)
- Participate in on-call rotation for security incidents
- Contribute to post-incident reviews and documentation (runbooks, RCAs)
- Collaborate with IT, DevOps, and engineering to harden infrastructure and enforce security best practices
- Assist with compliance/audit activities (SOC 2, ISO 27001, etc.) as needed
Requirements
- 5+ years of experience in security operations, incident response, or a related field
- At least 1 year of relevant leadership experience
- Hands-on expertise in SIEM (Splunk, Sentinel, Elastic, QRadar) and EDR tools
- Solid understanding of networking, operating systems (Linux/Windows), and cloud environments (AWS, Azure, GCP)
- Familiarity with common attack techniques and frameworks (MITRE ATT&CK, NIST Cybersecurity Framework)
- Scripting proficiency in Python, Bash, or PowerShell for automation and tooling
- Background in vulnerability management and remediation workflows
- Strong analytical and problem-solving skills; calm under pressure during incidents
- Clear written and verbal communication for documentation and cross-team collaboration (B2 English proficiency)
Nice to have
- Experience with SOAR platforms (Palo Alto XSOAR, Tines)
- Security certifications (Security+, GCIH, GCIA, CISSP, OSCP)
- Background in threat intelligence or purple/red team collaboration
- Familiarity with container/Kubernetes security
- Experience in a regulated industry (finance)