Назад
Company hidden
3 часа назад

SOC Lead (Cybersecurity)

Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
SOC Lead (Cybersecurity) (SIEM/SOAR): Leading security operations center investigations, incident response, threat hunting, and automation for a global enterprise with an accent on blue-team operations, detective controls, and security playbooks. Focus on developing SIEM/SOAR integrations with Python, PowerShell, APIs, and scripting, while supervising SOC analysts and improving incident remediation.

Location: Stamford, Connecticut; remote or onsite. US Person status under EAR Part 772 and ITAR 120.15 is required.

Company

Crane Aerospace & Electronics supports a global enterprise through aerospace and electronics operations and a global information security program.

What you will do

  • Lead daily SOC analyst activities, including alert triage, incident assignment, investigation, remediation, and escalation.
  • Perform hands-on threat hunting and detailed investigations of security events and incidents.
  • Define standard work, processes, response playbooks, and threat-intelligence-informed detections.
  • Develop and automate security workflows integrating SIEM, SOAR, incident response platforms, APIs, and other technologies.
  • Enhance detective capabilities and tune security solutions, configurations, and processes with global security and IT teams.
  • Support vulnerability management, security infrastructure operations, policies, documentation, and incident preparedness.

Requirements

  • At least 5 years of professional experience in security operations and incident response management.
  • At least 2 years of supervisory experience leading SOC or incident response analysts.
  • Experience with incident triage, closed-loop investigations, threat detection, remediation, and enterprise security operations.
  • Experience developing automation with Python, PowerShell, other scripting languages, JSON, XML, and REST APIs.
  • Knowledge of SIEM, SOAR, EDR, firewalls, proxies, IDS/IPS, DLP, threat intelligence, vulnerability scanning, and related security technologies.
  • Must be a US Person as defined under EAR Part 772 and ITAR 120.15.

Nice to have

  • Professional certification in incident response, digital forensics, or malware analysis, such as GCIH, GCFA, GNFA, or GCTI.
  • Degree in a related field.

Culture & Benefits

  • Work with a global information security team supporting distributed enterprise IT environments.
  • Collaborate with information security management, SOC teams, incident responders, and IT.
  • Contribute to continuous improvement and the development of next-generation security operations capabilities.
  • Flexibility to work outside normal business hours when required.
  • Ability to travel domestically and internationally with limited notice as required.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →