Replit07/10/2026

Руководитель службы безопасности (SOC)

Salary not specified
MARKET
14,300median for this role
Tech Lead / Team Lead · 102 jobs with disclosed pay
5,250half of the offers: 10,542–19,3541.2 млн
The employer didn't disclose pay — compare with the market yourself.
Полная занятостьУдалёнка

Responsibilities

  • 01Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation
  • 02Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments
  • 03Monitor cloud infrastructure (GCP, AWS, Azure), Kubernetes/GKE/EKS/AKS clusters, SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.), endpoints (macOS, Linux, Windows) including EDR/XDR telemetry, developer platforms and CI/CD pipelines, AI/ML systems and model-serving workflows
  • 04Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation
  • 05Identify opportunities to automate triage, investigations, enrichment, and reporting
  • 06Own the entire SIEM ecosystem—ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics
  • 07Expand telemetry across cloud logs, API logs, system events, SaaS audit logs, admin events, identity providers (Okta, Google, Azure AD), and endpoint EDR/XDR event streams
  • 08Develop high-fidelity detections for cloud-native attacks, identity threats, SaaS misconfigurations, endpoint malware/behavior anomalies, insider threats, and account takeover patterns
  • 09Lead day-to-day triage and threat analysis activities, ensuring accurate categorization and prioritization
  • 10Drive complex investigations involving correlated events across cloud, SaaS, endpoints, and developer platforms
  • 11Guide root cause analysis and work with owners to drive remediation and architectural improvements
  • 12Partner with Cloud Security on cloud posture and preventative controls
  • 13Work with Compliance/GRC to support SOC 2, ISO 27001, and audit readiness
  • 14Collaborate with SRE and Engineering to instrument new services with structured logs and detection hooks
  • 15Coordinate with IT / Endpoint teams to ensure full endpoint telemetry and EDR response readiness
  • 16Communicate threats, gaps, and trends to leadership and engineering stakeholders

Requirements

  • 017+ years of experience in Security Operations, with 3+ years in a senior or lead capacity
  • 02Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP)
  • 03Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.)
  • 04Deep understanding of cloud security monitoring (GCP required; AWS/Azure preferred)
  • 05Deep understanding of SaaS security monitoring (Okta, Google Workspace, GitHub, Slack, etc.)
  • 06Deep understanding of endpoint security telemetry (EDR/XDR tools such as CrowdStrike, SentinelOne, or Defender)
  • 07Deep understanding of Kubernetes and container detection
  • 08Hands-on detection engineering skills, event correlation, threat hunting, and log analysis
  • 09Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools
  • 10Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns
  • 11Experience with SOAR and scripting (Python, Go, Bash)
  • 12Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management
  • 13Experience with UBA/UEBA, ML-driven anomaly detection, or autonomous remediation systems (preferred)
  • 14Previous experience at a high-growth tech company (preferred)
  • 15Security certifications (GCIH, GCIA, GCTI, GCDA, GCFA, etc.) (preferred)