Cyber Operations Strategist, Critical Harm Operations
Senior individual contributor responsible for improving cyber operations, resolving complex dual-use safety decisions, and building scalable reviewer, quality, vendor, and automation systems. Requires 8+ years of hands-on cybersecurity experience and strong operational judgment.
About the job
Responsibilities
- Drive the Cyber Operations operating model across domain priorities, SOPs, escalation paths, quality health, vendor capability, roadmap inputs, and trusted access strategies.
- Serve as the senior cyber expert for complex or high-risk decisions across ChatGPT, API, Codex, agents, and emerging product surfaces.
- Translate policy ambiguity, quality misses, appeals, and reviewer disagreement into decision rules, calibration examples, training, and tooling requirements.
- Build operating systems and quality loops, including golden sets, holdouts, double-labeling, adjudication, error taxonomies, reviewer calibration, and automation evaluations.
- Improve FTE and BPO capability through onboarding, certification, coaching, recurring calibration, and vendor-performance partnership.
- Use quality, appeals, SLA, backlog, and disagreement signals to diagnose root causes and prioritize high-leverage fixes.
- Build SQL analyses, scripts, dashboards, LLM evaluation workflows, evidence enrichment, routing logic, and lightweight automations.
- Partner with Policy, Integrity, Safety Systems, Security, Legal, Product, Engineering, and Investigations to operationalize changes and drive launch readiness.
Requirements
- 8+ years of hands-on cybersecurity experience in offensive security, threat intelligence, incident response, security research, red teaming, application security, DFIR, malware analysis, or a related field.
- Deep understanding of attacker tradecraft, vulnerability exploitation, credential abuse, malware, persistence, evasion, exfiltration, cloud abuse, identity abuse, and ambiguous dual-use activity.
- Experience building or improving high-stakes operations, reviewer programs, QA systems, escalation workflows, or vendor/BPO programs.
- Ability to turn complex cyber and policy judgment into reviewer-usable SOPs, decision trees, training, and concise recommendations.
- Proficiency or comfort with SQL, Python, C/C++, JavaScript, PowerShell, Bash, APIs, LLM tooling, or automation.
- Understanding of human-in-the-loop automation, evaluations, monitoring, holdouts, and fallback paths for sensitive workflows.
- Ability to operate independently in ambiguity, communicate across technical and non-technical audiences, and exercise sound judgment with sensitive material.
Nice to Have
- Experience with trust and safety, platform abuse, cyber misuse of AI systems, or LLM safety.
- Experience with golden sets, classifier or prompt evaluations, and reviewer-quality programs.
- Experience enabling global vendor reviewer operations.
Skills
Cybersecurity, SQL, Python, C/C++, JavaScript, PowerShell, Bash, APIs, Llm Tooling, Automation, Threat Intelligence, Incident Response, Red Teaming, Malware Analysis, Cloud Security
Similar jobs
Security Engineering jobsLeads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
Analyzes insureds’ cybersecurity posture, investigates incidents and claims, and recommends prioritized risk-reduction measures. The role requires 2–4 years of security experience, strong network and threat knowledge, familiarity with assessment tools and security frameworks, and a bachelor’s degree or equivalent experience.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Investigates cyber incidents and insurance claims, assesses security controls, and advises customers and security leaders on prioritized risk improvements. The role requires 2–4 years of security experience, strong network threat knowledge, and familiarity with major security and compliance frameworks.
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.