×
Register Here to Apply for Jobs or Post Jobs. X

Envista Security Operations & Engineering Lead; Brea​/Irvine, CA)

Job in Brea, Orange County, California, 92631, USA
Listing for: Envista Holdings Corporation
Full Time position
Listed on 2026-09-25
Job specializations:
  • IT/Tech
    Cybersecurity, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 156000 - 191000 USD Yearly USD 156000.00 191000.00 YEAR
Job Description & How to Apply Below
Position: Envista Security Operations & Engineering Lead (Brea/Irvine, CA)

Job Description:

JOB SUMMARY

Candidates must reside within a commutable distance to both Brea, CA and Irvine, CA, as the office location will be relocated from Brea to Irvine in approximately Q1 2028. This is not a hybrid or remote opportunity and requires onsite presence 4 days per week. We are seeking a strategic and hands‑on Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities.

This leader owns the SOC, incident response program, detection lifecycle, and security tooling ecosystem, and is responsible for building scalable, threat‑informed, and measurable security operations.

PRIMARY DUTIES AND RESPONSIBILITIES
  • Security Operations Leadership Lead enterprise security operations including monitoring, triage, investigation, escalation, and response
  • Oversee SOC and MSSP/MDR partnerships including SLAs, alert quality, escalation paths, and performance metrics
  • Establish 24x7 monitoring aligned to enterprise risk
  • Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness
  • Security Engineering & Platform Management Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms
  • Drive automation across triage, enrichment, containment, and reporting workflows
  • Define enterprise logging and telemetry strategy including onboarding, parsing, normalization, retention, and coverage standards
  • Ensure tools are integrated, cost‑effective, and aligned to risk priorities
  • Incident Response & Threat Management Own incident response program including playbooks, exercises, breach workflows, and communications
  • Lead major incidents through containment, eradication, recovery, and root cause analysis
  • Ensure post‑incident reviews drive durable control improvements
  • Coordinate with Legal, Privacy, HR, IT, and Communications
  • Detection Engineering & Monitoring Build detection engineering lifecycle: hypothesis >> development >> testing >> tuning >> deployment >> validation >> retirement
  • Develop behavior‑based and threat‑informed detections aligned to MITRE ATT&CK
  • Expand monitoring across endpoint, identity, cloud, SaaS, network, and critical applications
  • Identify and close detection gaps via red team, pentest, and vulnerability insights
  • Exposure & Control Operations Support exposure management, asset inventory visibility, and attack surface monitoring
  • Drive continuous control monitoring and validation of key security controls
  • Improve vulnerability remediation workflows and risk reduction outcomes
  • Leadership & Stakeholder Management Build and lead high‑performing security operations and engineering teams
  • Establish clear roles, operating model, and accountability
  • Provide executive reporting on threats, incidents, control gaps, and maturity
  • Partner with GRC, Audit, IT, Architecture, and business leadership
Job Requirements
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or a related fields OR equivalent industry experience, military service, professional certifications, and demonstrated leadership experience are valued equally.
  • 7+ years of experience in cybersecurity, security operations, detection engineering, incident response, or security engineering.
  • 5+ years leading security operations, engineering, SOC, or incident response teams.
  • Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.
  • Experience managing MSSP, MDR, SOC-as-a-Service, or strategic security service providers.
  • Hands‑on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Chronicle, etc.)
  • Experience in Azure, AWS, or GCP environments.
  • Understand in…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary