3 часа назад
SOC Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
SOC Lead (Cybersecurity) (SIEM/SOAR): Leading security operations center investigations, incident response, threat hunting, and automation for a global enterprise with an accent on blue-team operations, detective controls, and security playbooks. Focus on developing SIEM/SOAR integrations with Python, PowerShell, APIs, and scripting, while supervising SOC analysts and improving incident remediation.
Location: Stamford, Connecticut; remote or onsite. US Person status under EAR Part 772 and ITAR 120.15 is required.
Company
Crane Aerospace & Electronics supports a global enterprise through aerospace and electronics operations and a global information security program.
What you will do
- Lead daily SOC analyst activities, including alert triage, incident assignment, investigation, remediation, and escalation.
- Perform hands-on threat hunting and detailed investigations of security events and incidents.
- Define standard work, processes, response playbooks, and threat-intelligence-informed detections.
- Develop and automate security workflows integrating SIEM, SOAR, incident response platforms, APIs, and other technologies.
- Enhance detective capabilities and tune security solutions, configurations, and processes with global security and IT teams.
- Support vulnerability management, security infrastructure operations, policies, documentation, and incident preparedness.
Requirements
- At least 5 years of professional experience in security operations and incident response management.
- At least 2 years of supervisory experience leading SOC or incident response analysts.
- Experience with incident triage, closed-loop investigations, threat detection, remediation, and enterprise security operations.
- Experience developing automation with Python, PowerShell, other scripting languages, JSON, XML, and REST APIs.
- Knowledge of SIEM, SOAR, EDR, firewalls, proxies, IDS/IPS, DLP, threat intelligence, vulnerability scanning, and related security technologies.
- Must be a US Person as defined under EAR Part 772 and ITAR 120.15.
Nice to have
- Professional certification in incident response, digital forensics, or malware analysis, such as GCIH, GCFA, GNFA, or GCTI.
- Degree in a related field.
Culture & Benefits
- Work with a global information security team supporting distributed enterprise IT environments.
- Collaborate with information security management, SOC teams, incident responders, and IT.
- Contribute to continuous improvement and the development of next-generation security operations capabilities.
- Flexibility to work outside normal business hours when required.
- Ability to travel domestically and internationally with limited notice as required.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Lead Analyst – Cyber Incident Response (AI)
5 дней назад
Principal Cybersecurity Engineer (US Federal)
184 800 - 277 200$
CrowdStrike
6 дней назад
Analyst I, Falcon Complete GovCloud (Hybrid, St Louis)
85 000 - 120 000$
CrowdStrike
7 дней назад
Associate Security Engineer
70 000 - 95 000$
4 дня назад
Principal Security Architect (AWS)
22 часа назад