Overview:
The SOC Team Lead leads an engineering-driven Security Operations function covering detection, threat hunting, investigation, incident response, forensics, automation, and security platforms.
This role develops a team of SOC Engineers and modernizes SOC capabilities through improved telemetry, integrated security tools, engineering practices, and AI-enabled workflows.
Responsibilities:
- Define and execute the SOC strategy, architecture, operating model, and modernization roadmap.
- Lead and develop SOC Engineers across detection, hunting, investigation, response, forensics, automation, and platform operations.
- Lead complex incidents and coordinate investigation, containment, remediation, forensic analysis, and post-incident improvements.
- Develop and continuously validate detection rules, hunting content, playbooks, and response workflows.
- Improve security visibility across endpoints, networks, identities, applications, cloud environments, and infrastructure.
- Own and integrate SIEM, SOAR, EDR/XDR, NDR, DLP, PAM, vulnerability management, and security platforms.
- Automate enrichment, triage, investigation, hunting, response, and reporting using scripts, APIs, SOAR, and specialized AI agents with appropriate human oversight.
- Define and track detection coverage, investigation quality, response time, automation effectiveness, and security-tool health.
- Collaborate with OffSec, IT, infrastructure, cloud, DevOps, risk and compliance teams.
- Communicate incidents, capability gaps, risks, and improvement priorities to senior management.
Requirements:
- 7+ years of experience in security operations, detection engineering, incident response, threat hunting, forensics, or security engineering.
- Proven experience leading multidisciplinary security engineers and technical initiatives.
- Deep hands-on experience with SIEM platforms, particularly Splunk Enterprise Security.
- Strong knowledge of security telemetry, detection engineering, investigation, threat hunting, incident response, and digital forensics.
- Practical experience with major SOC technologies, including EDR/XDR, NDR, SOAR, DLP, PAM, IAM, vulnerability management, and cloud security tools.
- Experience integrating and automating security platforms using APIs and scripting, preferably Python or PowerShell.
- Strong knowledge of MITRE ATT&CK, network security, identity threats, and cloud security.
- Strong leadership, systems thinking, technical decision-making, and stakeholder communication skills.
Preferred Certifications:
CISSP, CISM, GCFA, GCIH, GCIA, Splunk Enterprise Certified Architect, or equivalent practical qualifications.