Global IT Security Operations Lead – Exposure Management

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Develop and manage a scalable global security operations framework.

• Oversee the daily delivery of security operations services, including ticket management, triage, prioritization, escalation, case quality assurance, and closure.

• Supervise managed security service providers and other external security services.

• Create definitions for severity, establish investigation protocols, escalation procedures, response playbooks, and criteria for executive notifications.

• Report on operational health and risk to the CISO, utilizing metrics such as coverage, detection quality, response effectiveness, backlog status, and remediation efforts.

• Design the operating model and talent roadmap for a robust global security operations function.

• Direct enterprise-wide security operations and incident response activities, which include detection, triage, containment coordination, eradication support, root cause analysis, and post-incident evaluations.

• Manage incident documentation, evidence preservation, lessons learned, corrective measures, and closure validation.

• Facilitate incident tabletop exercises and coordinate security involvement in recovery readiness activities.

• Collaborate with IT, engineering, manufacturing, and business service owners to ensure timely remediation.

• Set the rhythm for transforming vulnerability, asset, identity, cloud, and threat findings into prioritized remediation actions.

• Monitor remediation commitments, address overdue high-risk items, and escalate unresolved risks.

• Ensure that security monitoring and response requirements are integrated into major projects.

• Define telemetry standards, coverage models, automation pipelines, and detection use cases.

• Enhance detection accuracy through tuning, enrichment, automation, and lifecycle management.

• Utilize approved AI capabilities and automation to advance detection, investigation, response, documentation, and the maturity of security operations.

• Establish monitoring and logging requirements while addressing coverage gaps.

• Convert threat intelligence into actionable detections, hunts, response playbooks, and countermeasures.

• Collaborate with vulnerability management, risk, and red teams to minimize attack surfaces.

• Analyze and respond to IOCs, TTPs, ransomware threats, and supply-chain vulnerabilities.

• Report to the CISO and guide the development of internal staff as the function expands.


⛳️ Requirements

• Minimum of 7 years of progressive experience in information security, particularly in security operations, incident response, detection engineering, or exposure management.

• Proven experience in leading a SOC, MDR/MSSP service, incident response team, or similar global security operations capability.

• Strong understanding of applied AI, including the evaluation and utilization of generative AI, security platform AI capabilities, and automation tools.

• Experience in managing and developing analysts and engineers is preferred.

• Proficiency in constructing an operating model and leading through influence.

• Extensive practical experience with SIEM, EDR/XDR, SOAR or case management, vulnerability management workflows, IAM telemetry, cloud logging, and incident response protocols.

• Familiarity with OT/industrial security principles and the constraints of production environments is preferred.

• Experience in supporting defense, aerospace, manufacturing, or similarly complex hybrid environments is preferred.

• Excellent communication skills and the ability to convey technical risks to business stakeholders.

• Preferably hold certifications such as CISSP, CISM, CCSP, OSCP, or related GIAC qualifications.

• Bachelor's degree from a recognized college or university or equivalent experience.

• Must meet U.S. export-control requirements where applicable, including documentation for assessing U.S. Person status or obtaining an export license.


🏝️ Benefits

• Remote work flexibility.

• Equal employment opportunity protections for veterans and individuals with disabilities.

• Reasonable accommodations available for applicants with disabilities.

People also viewed

Capgemini1 day ago

SOC Analyst Internship

FR flagFrance OnlyInternshipSecurity Operations
ApplyView job
Capgemini1 day ago

SOC Analyst – Internship

FR flagFrance OnlyInternshipSecurity Operations
ApplyView job
LEADtech1 day ago

SOC Analyst

ES flagSpain OnlyFull-timeSecurity Operations
ApplyView job
Teamified1 day ago

Security Operations Engineer – PCI DSS

LK flagSri Lanka OnlyFreelanceSecurity Operations
ApplyView job
Teamified1 day ago

Security Operations Engineer – PCI DSS

PH flagPhilippines OnlyFreelanceSecurity Operations
ApplyView job
Live Nation Entertainment1 day ago

Senior Director – Cyber Security Operations

US flagCalifornia, +2 more statesFull-timeSecurity Operations$188k – $235k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers