Skip to content
← Back to job listings

Security Operations Lead

Replit · United States

External listingfull-time25 days ago

About The Role

Join our team as a Security Operations Lead (SOC Lead) to build, mature, and operate our 24/7 detection and response capabilities in a modern cloud-native and AI-driven environment. You will lead the global SOC function, oversee monitoring across multi-cloud environments, and collaborate closely with various teams to ensure our detection strategy scales and stays ahead of evolving threats. This is a hands-on leadership role perfect for someone who wants to shape the SOC of the future while solving complex challenges in a high-scale AI setting.

  • Lead and mentor a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation.
  • Own the entire SIEM ecosystem—ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics.
  • Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation.
  • Kubernetes and container detection
  • Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.)
  • 7+ years of experience in Security Operations, with 3+ years in a senior or lead capacity
  • Deep understanding of:
  • Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP)
  • Experience with SOAR and scripting (Python, Go, Bash)
  • SaaS security monitoring (Okta, Google Workspace, GitHub, Slack, etc.)
  • Endpoint security telemetry (EDR/XDR tools such as CrowdStrike, SentinelOne, or Defender)
  • Hands-on detection engineering skills, event correlation, threat hunting, and log analysis
  • Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools
  • Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns
  • Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management
  • Cloud security monitoring (GCP required; AWS/Azure preferred)
  • Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems
  • Previous experience at a high-growth tech company
  • Security certifications (GCIH, GCIA, GCTI, GCDA, GCFA, etc.)
  • Automation mindset: Focused on reducing manual toil via SOAR, scripting, and AI augmentation
  • Curiosity: Passion for learning, experimenting, and staying ahead of evolving threats—especially those targeting cloud-native and AI systems
  • Adaptability: Comfortable evaluating and integrating next-gen AI-based SOC tools
  • Leadership: Mentorship and guidance of analysts and engineers
  • Operational excellence: Building reliable, scalable SOC systems
  • Analytical rigor: Capable of making sense of large, complex, multi-source telemetry
  • Clear communication: Able to articulate risk, incidents, and recommendations to both technical and executive audiences

This is an external listing. JobSpring does not represent or verify the employer. Report this listing