SOC Lead
Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
About the job
Responsibilities
- Lead cybersecurity incident response for cloud-native infrastructure, including compromised containers, Kubernetes clusters, and CI/CD pipelines.
- Coordinate isolation, remediation, root-cause analysis, containment, eradication, recovery, and post-incident reviews across cloud workloads.
- Lead host- and network-based forensic collection and analysis.
- Oversee detection, analysis, and mitigation of insider threats and complex security incidents using DLP, SIEM, IDS/IPS, EDR, and firewalls.
- Conduct proactive threat hunting for indicators of compromise and APT tactics, techniques, and procedures, including cloud- and container-specific attack patterns.
- Lead security monitoring, incident response, and SOC process-improvement initiatives.
- Mentor junior SOC analysts and provide technical guidance.
- Collaborate with Tier 2/3 staff and cross-functional teams on incident detection, classification, reporting, and SOP improvements.
- Maintain hands-on expertise in GCP, Kubernetes, CI/CD pipelines, and cloud-native detection and response.
- Use AI/ML tools and automation to accelerate triage and streamline security operations.
- Evaluate emerging cybersecurity tools and methodologies.
Required Qualifications
- 8+ years of experience in information security, including extensive hands-on incident response, threat hunting, and forensic analysis.
- 2+ years in a lead SOC role responding to sophisticated threats.
- 2+ years performing cloud incident response, preferably in GCP, involving Kubernetes/container workloads and CI/CD pipelines.
- 4+ years detecting, analyzing, and mitigating complex threats using DLP, SIEM, IDS/IPS, EDR, and firewalls.
- Working knowledge of container security, including image scanning, runtime protection, and container escape scenarios.
- Working knowledge of CI/CD pipeline security, including secrets exposure, build/deploy compromise, and software supply-chain risks.
Preferred Qualifications
- Strong experience with GCP, Kubernetes, CI/CD pipelines, and DevOps principles.
- Expertise in container security, runtime protection, image scanning, and service mesh security policies.
- Experience securing Infrastructure as Code and GitOps deployment workflows.
- Experience using AI/ML for incident response, threat detection, and SOC automation.
- Familiarity with securing LLM deployments and AI pipelines against adversarial attacks.
- Understanding of email security, network monitoring, DLP, OS forensics, and related security domains.
- Advanced SIEM expertise, particularly Chronicle and Splunk.
- Experience developing insider-threat detection strategies, writing detection signatures, and improving SOC processes.
- Strong threat-intelligence skills and the ability to translate adversary techniques into detection and mitigation strategies.
- Forensic investigation experience across Linux, macOS, and Windows.
- Scripting and automation proficiency with Python, Bash, and Go.
- Advanced certifications such as GCIA, GCIH, GCFA, CISSP, CKS, or GCP Professional Cloud Security Engineer, or equivalent.
- Experience developing SOC SOPs and contributing to SOC maturity assessments.
- Strong collaboration, communication, teamwork, adaptability, problem-solving, and leadership skills.
Compensation
- Annual salary range: $96,086–$111,683.
Skills
Incident Response, Threat Hunting, Digital Forensics, GCP, Kubernetes, CI/CD, Container Security, SIEM, Chronicle, Splunk, Dlp, Edr, Python, Bash, Go
Similar jobs
Security Engineering jobsInvestigates cyber incidents and insurance claims, assesses security controls, and advises customers and security leaders on prioritized risk improvements. The role requires 2–4 years of security experience, strong network threat knowledge, and familiarity with major security and compliance frameworks.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.
The Senior Information Security Engineer will lead threat hunting, detection engineering, incident response, vulnerability management, and security-platform ownership across cloud and enterprise environments. The role requires 5+ years of security experience, strong attacker-TTP knowledge, and hands-on expertise with enterprise security technologies and automation.
Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.