Security Operations Lead
Listed on 2026-09-28
-
IT/Tech
Cybersecurity, Security Management & Operations
Position
Security Operations Lead
LocationHybrid (This person can be based out of our Dallas/Frisco, TX or Conshohocken, PA Corporate Headquarters)
DepartmentTechnology
Reports ToVP, Cyber Security
Company OverviewLEGENDS GLOBAL Legends Global is the premier partner to the world’s greatest live events, venues, and brands. We deliver a fully integrated suite of premium services through a white-label model that keeps our partners front and center - from feasibility and project development to sales, partnerships, hospitality, merchandise, venue management, and world-class content and booking. With a global network of more than 450 venues, hosting 20,000 events and welcoming 165 million guests annually, Legends Global brings unmatched scale, expertise, and connectivity to help our partners grow.
The Legends Global Way guides how we operate:
Align, Scale, Connect, Team, Win - shared success, repeatable systems, connected solutions, unstoppable teams, and wins that are earned every day.
- Independently lead complex or high-impact security incidents and identify opportunities to improve SOC processes, tools, and response capabilities.
- Provide technical guidance and mentorship to SOC Analysts, sharing best practices and establishing standards for documentation, communication, and delivery.
- Build and operationalize SOC playbooks and escalation workflows.
- Lead alert triage, enrichment, prioritization, and false-positive suppression.
- Author detection requirements and write and tune SIEM rules.
- Develop threat-hunting hypotheses and lead hunt efforts using advanced telemetry and threat intelligence.
- Design detection strategies across the kill chain and help advance the enterprise detection strategy.
- Execute complex incidents end-to-end, including containment, eradication, documentation, and communication.
- Conduct post-incident reviews and drive remediation and control improvements.
- Promote industry collaboration and embed resilient detection engineering practices.
- Advocate for and implement automation-first incident response.
- Provide technical guidance and mentorship to SOC Analysts, sharing best practices and setting standards for documentation, communication, and delivery.
Proven experience in a SOC or equivalent detection and response function, with a focus on high-fidelity detections, repeatable playbooks, and measurable outcomes. Three to five years of experience in Security Operations, Detection and Response, or Incident Handling; SOC experience is required. Hands-on experience with SIEM platforms, such as Google Security Operations, Microsoft Sentinel, or IBM QRadar; EDR platforms, such as Crowd Strike, Microsoft Defender, or Sentinel One;
and SOAR platforms. Proficiency in authoring detections, tuning rules, developing enrichment pipelines, and improving alert routing. Demonstrated experience building and executing incident-response playbooks and containment and eradication plans. Experience conducting post-incident reviews and root-cause analyses and delivering corrective action plans to engineering teams. Scripting skills in Python, Power Shell, or Bash for automation, enrichment, and data analysis. Excellent written communication skills, including case documentation and executive-ready incident summaries.
Proficient in authoring detections, rule tuning, enrichment pipelines, and alert routing. Demonstrated capability in building and executing IR playbooks and containment/eradication plans. Experience conducting post-incident reviews and RCAs, and delivering corrective action plans to engineering teams. Scripting skills (Python/Power Shell/Bash) for automation, enrichment, and data wrangling. Excellent written communication for case documentation and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).