9 дней назад
Cybersecurity Lead (Cybersecurity)
140 000 - 185 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity Lead (SIEM, EDR/XDR, SOAR): Leading offensive and defensive security operations to improve detection, incident response, and recovery across cloud, endpoint, network, and production environments with an accent on threat emulation, security telemetry, and detection engineering. Focus on designing adversary simulations, tuning detection pipelines, coordinating major incident response, and converting Red Team findings into measurable defensive improvements.
Location: San Jose, California; hybrid
Targeted compensation: $140,000–$185,000 annually
Company
develops networking and cybersecurity solutions for enterprise and production-scale environments.
What you will do
- Lead Blue Team operations, including the management, integration, configuration, and tuning of SIEM, EDR/XDR, SOAR, IDS/IPS, NDR, and threat intelligence platforms.
- Improve security telemetry, log collection, correlation, detection rules, and use cases across endpoints, cloud environments, CI/CD pipelines, and production systems.
- Coordinate threat hunting, alert triage, incident response playbooks, major incident containment, investigation, and recovery.
- Design and conduct Red Team and purple team adversary-emulation exercises using real-world tactics, techniques, and procedures.
- Develop adversary scripts and payloads, report exercise findings, and operationalize defensive improvements with Blue Team engineers.
- Build the roadmap for detection coverage, response automation, control validation, resilience, and continuous improvement.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- 8+ years of cybersecurity experience with leadership across Blue, Red, or Purple Team operations.
- Enterprise ownership of SIEM, EDR/XDR, SOAR, and threat intelligence platforms.
- Strong knowledge of MITRE ATT&CK, the Cyber Kill Chain, threat emulation, incident response, and purple team exercises.
- Deep expertise in endpoint or network forensics, cloud security monitoring, scripting and automation with Python, PowerShell, or Bash, or security engineering in hybrid and production environments.
- Strong communication and leadership skills for working with executives and technical teams.
Nice to have
- OSCP, GCFA, GCIH, GPEN, GXPN, or GCTI certification.
- Experience with enterprise, SaaS, networking, or hybrid cloud infrastructures.
- DevSecOps, CI/CD pipeline security, and cloud-native monitoring experience.
- Experience mentoring Blue Team analysts and managing security tool lifecycles and vendor relationships.
- Familiarity with AttackIQ, Caldera, Scythe, or other purple team automation frameworks.
Culture & Benefits
- Work at the intersection of offensive and defensive cybersecurity.
- Use adversarial exercises and incident learnings to strengthen real-world organizational resilience.
- The position is hybrid and supports collaboration with both executive stakeholders and technical teams.
- is an equal opportunity employer and a VEVRAA federal subcontractor.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Product Champion (Cybersecurity)
144 501 - 190 000$
3 дня назад
Principal Cybersecurity Engineer (AI)
184 800 - 277 200$
7 дней назад
Security Analyst (AI)
120 000 - 140 000$
9 дней назад
Cybersecurity Engineer
80 000 - 100 000$
9 дней назад
SOC Lead (Cybersecurity)
9 дней назад
Cybersecurity Lead Engineer/Architect (AI)
175 000 - 225 000$