Security Operations and Incident Response Lead
Listed on 2026-09-25
-
IT/Tech
Cybersecurity
We are Splashtop. We deliver next-generation remote access and remote support software and services across the Americas, Europe, Asia, Middle East, and Africa. Splashtop’s cloud-based, secure, and easily managed solutions serve customers that include everyone from multinational enterprises and academic institutions to small businesses, MSPs, and individuals.
Headquartered in Cupertino, California (USA) and founded in 2006, Splashtop has offices in Hangzhou (China), Tokyo (Japan), Taipei (Taiwan), Singapore, Amsterdam (Netherlands). From our offices, 210 Splashtoppers serve more than 200,000 corporate customers
We always deliver what we promise and scaling hard, with a stunning Net Promoter Score of +93 and 85% of the Fortune 500 companies who enjoy Splashtop products globally. We recently achieved the aspirational Unicorn status of $1B valuation thanks to our 30+ million happy users. Each Splashtop employee will be a real team member, no matter what position you are in.
We are a young, fast-growing company, we respect and are transparent to one another. In this role you can have a real impact into the next steps of the company’s growth. We all work hard to exceed customer expectations, we are collaborative, positive thinkers and always improve our solutions and services. Besides hitting it hard we also enjoy and celebrate our success with our team.
This is a new role based in Cupertino. You will run security operations, own incident response, and close a specific gap we have identified: the security risk created by integrations between our business systems, including the AI tools and agents now connected to them. You will work alongside our existing IT, security, and GRC teams in San Jose, Taipei, and Hangzhou.
You will not take over those teams. Your results will depend on working well with them. This role reports to the VP of Security and Compliance.
Security operations
- Run day to day security monitoring across endpoints, identity, cloud, and SaaS applications. Triage alerts, investigate, and elevate.
- Improve detection quality. Tune alerts so that real problems surface and noise is removed.
- Build monitoring coverage that works across Cupertino and Taipei time zones.
- Define and report security operations metrics: time to detect, time to triage, time to remediate, escalation accuracy, and coverage gaps.
- Work with our endpoint security and identity security engineers in Taipei, who own those platforms, so that detection reflects how the systems are actually configured.
- Own the incident response program. Keep the plan current and track corrective actions until they are closed.
- Own tabletop exercise program. Run exercises on a regular schedule and choose scenarios from current threat activity rather than from a generic list. Cover supply chain, 3rd/4th party compromise, ransomware, and business system or integration compromise.
- Bring the right people into each exercise, technical responders for operational exercises, and executives, Legal and communications for decision level exercises.
- Track every finding an exercise produces until it closed.
- Lead active incidents: coordinate containment, recovery, evidence handling, and the written timeline.
- Keep external incident support ready to use. Security leadership owns the relationships with outside counsel, forensics, insurance, and law enforcement. You make sure escalation paths have been tested and evidence handling is prepared before those partners are engaged.
- Write the post incident report and drive the corrective actions it produces to completion.
- Turn intelligence into action. Every item that matters should produce something concrete – a new detection rule, a hunt through…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).