Skip to content
ReplitReplit

Security Operations Lead

Lead and scale Replit's 24/7 global SOC, owning SIEM, detection engineering, AI-powered triage/automation, and threat response across multi-cloud, Kubernetes, SaaS, endpoints, and AI workloads. Requires 7+ years in security operations with 3+ years leading SOC functions, deep cloud/SIEM expertise, and hands-on detection engineering.

About the job

What You’ll Do

SOC Leadership & 24/7 Monitoring

  • Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation.
  • Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments.
  • Cover monitoring across:
    • Cloud infrastructure (GCP, AWS, Azure)
    • Kubernetes/GKE/EKS/AKS clusters
    • SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.)
    • Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry
    • Developer platforms + CI/CD pipelines
    • AI/ML systems and model-serving workflows

AI-Based SOC Integration & Innovation

  • Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation.
  • Identify opportunities to automate triage, investigations, enrichment, and reporting.
  • Serve as the internal expert on the capabilities and limitations of AI-based SOC tooling.

SIEM & Telemetry Ownership

  • Own the entire SIEM ecosystem—ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics.
  • Expand telemetry across:
    • Cloud logs, API logs, system events
    • SaaS audit logs and admin events
    • Identity providers (Okta, Google, Azure AD)
    • Endpoint EDR/XDR event streams
  • Standardize data schemas and improve detection signal quality across sources.

Detection Engineering

  • Develop high-fidelity detections for:
    • Cloud-native attacks
    • Identity threats and lateral movement
    • SaaS misconfigurations and privilege abuse
    • Endpoint malware/behavior anomalies
    • Insider threats and account takeover patterns
  • Use MITRE ATT&CK, MITRE Cloud Matrix, and threat intel to drive detection coverage.
  • Collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases.

Triage, Threat Analysis & Escalation

  • Lead day-to-day triage and threat analysis activities, ensuring accurate categorization and prioritization.
  • Drive complex investigations involving correlated events across cloud, SaaS, endpoints, and developer platforms.
  • Guide root cause analysis and work with owners to drive remediation and architectural improvements.
  • Continuously refine logic, reduce false positives, and improve signal quality.

Cross-Functional Collaboration

  • Partner with Cloud Security on cloud posture and preventative controls.
  • Work with Compliance/GRC to support SOC 2, ISO 27001, and audit readiness.
  • Collaborate with SRE and Engineering to instrument new services with structured logs and detection hooks.
  • Coordinate with IT / Endpoint teams to ensure full endpoint telemetry and EDR response readiness.
  • Communicate threats, gaps, and trends to leadership and engineering stakeholders.

Required Skills & Experience

  • 7+ years of experience in Security Operations, with 3+ years in a senior or lead capacity.
  • Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP).
  • Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.).
  • Deep understanding of:
    • Cloud security monitoring (GCP required; AWS/Azure preferred)
    • SaaS security monitoring (Okta, Google Workspace, GitHub, Slack, etc.)
    • Endpoint security telemetry (EDR/XDR tools such as CrowdStrike, SentinelOne, or Defender)
    • Kubernetes and container detection
  • Hands-on detection engineering skills, event correlation, threat hunting, and log analysis.
  • Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools.
  • Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns.
  • Experience with SOAR and scripting (Python, Go, Bash).
  • Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management.

Preferred Qualifications

  • Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems.
  • Previous experience at a high-growth tech company.
  • Security certifications (GCIH, GCIA, GCTI, GCDA, GCFA, etc.).

What We Value

  • Operational excellence: Building reliable, scalable SOC systems.
  • Analytical rigor: Capable of making sense of large, complex, multi-source telemetry.
  • Leadership: Mentorship and guidance of analysts and engineers.
  • Adaptability: Comfortable evaluating and integrating next-gen AI-based SOC tools.
  • Clear communication: Able to articulate risk, incidents, and recommendations to both technical and executive audiences.
  • Automation mindset: Focused on reducing manual toil via SOAR, scripting, and AI augmentation.
  • Curiosity: Passion for learning, experimenting, and staying ahead of evolving threats—especially those targeting cloud-native and AI systems.

Skills

SIEM, Chronicle, Splunk, Elastic, Sentinel, Panther, GCP, AWS, Azure, Kubernetes, Edr, Xdr, Crowdstrike, Sentinelone, Microsoft Defender

Anthropic

Anthropic

Washington, DC
Safeguards Enforcement Lead, Cyber Harms
$285k+/yrHybridSecurity Engineering

Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.

Anthropic

Anthropic

San Francisco, CA
Platform Security Engineer, DRTM / Secure Launch
$320k+/yrHybrid8+ YOESecurity Engineering

Owns DRTM adoption, attestation, and platform hardening across x86 and ARM infrastructure, working across firmware, bootloaders, kernels, hardware, and silicon security. The role requires deep systems-security experience, upstream Linux or firmware contributions, and strong vendor and OEM leadership.

OpenAI

OpenAI

San Francisco, CA

Software Security Architect, Operating Systems | Consumer Devices
$268k+/yrOn-site7+ YOESecurity Engineering

Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.

OpenAI

OpenAI

San Francisco, CA

Cyber Operations Lead, Critical Harm Operations
$252k+/yrHybrid8+ YOESecurity Engineering

Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.