More jobs:
Security Operations Lead
Job in
Pittsburgh, Allegheny County, Pennsylvania, 15289, USA
Listed on 2026-09-06
Listing for:
Jobtailor
Full Time
position Listed on 2026-09-06
Job specializations:
-
IT/Tech
Security Management & Operations, Cybersecurity
Job Description & How to Apply Below
- Lead detection, triage, and response operations across the enterprise
- Independently lead complex or high-impact security incidents
- Identify opportunities to improve SOC processes, tools, and response capabilities
- Provide technical guidance and mentorship to SOC Analysts
- Build and operationalize SOC playbooks and escalation workflows
- Lead alert triage, enrichment, prioritization, and false-positive suppression
- Author detection requirements and write and tune SIEM rules
- Develop threat-hunting hypotheses and lead hunt efforts using advanced telemetry and threat intelligence
- Design detection strategies across the kill chain and advance the enterprise detection strategy
- Execute complex incidents end-to-end, including containment, eradication, documentation, and communication
- Conduct post-incident reviews and drive remediation and control improvements
- Promote industry collaboration and embed resilient detection engineering practices
- Advocate for and implement automation-first incident response
- Establish standards for SOC documentation, communication, and delivery
- Influence technical direction and cross-functional outcomes
- Present complex technical information to the CISO and other executive leaders
- Proven experience in a SOC or equivalent detection and response function, with a focus on high-fidelity detections, repeatable playbooks, and measurable outcomes
- Three to five years of experience in Security Operations, Detection and Response, or Incident Handling; SOC experience is required
- Hands-on experience with SIEM platforms such as Google Security Operations, Microsoft Sentinel, or IBM QRadar
- Hands-on experience with EDR platforms such as Crowd Strike, Microsoft Defender, or Sentinel One
- Hands-on experience with SOAR platforms
- Proficiency in authoring detections, tuning rules, developing enrichment pipelines, and improving alert routing
- Demonstrated experience building and executing incident-response playbooks and containment and eradication plans
- Experience conducting post-incident reviews and root-cause analyses and delivering corrective action plans to engineering teams
- Scripting skills in Python, Power Shell, or Bash for automation, enrichment, and data analysis
- Excellent written communication skills, including case documentation and executive-ready incident summaries
- Ability to influence technical direction and cross-functional outcomes through expertise and sound judgment, without formal people-management responsibility
- Ability to transform noisy telemetry into actionable signals
- Detail-oriented and disciplined in organizing information, developing repeatable playbooks, maintaining clear documentation, and closing feedback loops
- Prepared to mentor other analysts and set standards for SOC communication and delivery
- Comfortable presenting complex technical information to the CISO and other executive leaders
Demonstrates expertise in leading security operations, incident response, and threat detection strategies, with a strong focus on developing and executing SOC playbooks and automation practices. Proficient in utilizing SIEM and EDR platforms to enhance detection capabilities and improve incident handling processes.
Highest-signal resume keywords- Security Operations Experience
- SIEM Platform Proficiency
- Incident Response Playbook Development
- Scripting Skills in Python
- Technical Communication Skills
- Incident Handling
- Threat Detection
- SIEM Rule Authoring
- Alert Triage
- Post-Incident Review
- Root-Cause Analysis
- Automation Scripting
- Data Analysis
- Enrichment Pipeline Development
- Containment and Eradication Plans
- Mentorship
- Detail-Oriented
- Influencing Technical Direction
- Organizational Skills
- Communication Skills
- SOC
- Detection and Response
- High-Fidelity Detections
- Automation-First Incident Response
- Threat Intelligence
- Google Security Operations
- Microsoft Sentinel
- IBM QRadar
- Crowd Strike
- Microsoft Defender
- Sentinel One
- SOAR Platforms
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×