Назад
Company hidden
22 часа назад

Security Operations Lead (Cybersecurity)

Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Operations Lead (Cybersecurity): Building and owning a SOC function for hybrid on-premises and cloud infrastructure with an accent on SIEM engineering, incident response, detection engineering, and threat hunting. Focus on developing MITRE ATT&CK-aligned detections, conducting digital forensics and malware analysis, automating response workflows, and leading a growing security operations team.

Location: Torrance, California, United States. U.S. citizenship or lawful permanent resident status is required to comply with ITAR export regulations, and the role requires obtaining and maintaining a Top Secret security clearance.

Company

hirify.global builds space infrastructure and a global network of phased-array ground stations for reliable satellite communications supporting national security, connectivity, and disaster response.

What you will do

  • Build and operate the security operations center across AWS GovCloud, Microsoft GCC, on-premises facilities, and endpoint environments.
  • Own alert triage, investigation, escalation, and end-to-end incident response processes.
  • Develop SIEM detections, behavioral analytics, UEBA rules, threat-hunting queries, and MITRE ATT&CK coverage.
  • Conduct digital forensics and malware analysis across Linux and Windows using tools such as Volatility and YARA.
  • Develop security automation, SOAR playbooks, and automated response actions using Python, PowerShell, or Bash.
  • Hire, mentor, and lead security analysts and engineers while defining SOC procedures, metrics, and on-call coverage.

Requirements

  • 5+ years of hands-on SOC operations, incident response, or threat-hunting experience, including technical leadership.
  • Experience building SIEM platforms, custom detection rules, log-source integrations, advanced queries, and EDR workflows.
  • Proficiency in digital forensics, malware analysis, Linux log analysis, and Python, PowerShell, or Bash automation.
  • Experience with UEBA, MITRE ATT&CK, the Diamond Model, and threat intelligence workflows.
  • Knowledge of NIST 800-171, CMMC, DFARS incident reporting, and other government compliance requirements.
  • Ability to obtain and maintain a Top Secret or TS/SCI security clearance; U.S. citizenship or lawful permanent resident status required.

Nice to have

  • Active TS clearance or higher and experience in aerospace, defense, critical infrastructure, or other regulated environments.
  • Experience with FortiGate, Cloudflare Zero Trust, Okta, CrowdStrike, SentinelOne, Proofpoint, or Sublime Security.
  • Experience with AWS GovCloud, Microsoft GCC, SOAR platforms, air-gapped environments, or ITAR compliance.
  • Certifications such as GCIH, GCFA, or GNFA.

Culture & Benefits

  • Work on mission-critical space communications infrastructure with real-world national security and disaster-response applications.
  • Collaborate with security engineering, network engineering, infrastructure, and compliance functions.
  • Reasonable accommodations are available during the application and interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →