Security Operations Lead (SecOps)
New
S
SwordHealthcare AI
Location: Remote - Portugal; Remote - USFull-TimeLead
Salary$50,400 — $79,200 USD
Apply NowOpens the employer's application page
Job Details
- Experience
- 7+ years
- Required Skills
- Python
Requirements
- 7+ years experience in Security Operations.
- Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
- Experience scaling a SOC through automation, SOAR, LLM-assisted triage, or ML-driven detection.
- Hands-on experience structuring a SOC through SIEM implementation, detection engineering, and on-call rotations.
- Deep SIEM expertise (e.g., Splunk, Sentinel, Chronicle, Elastic) in architecture and detection-as-code.
- Proven experience as a technical lead for a SOC or CSIRT team.
- Strong incident response track record, including forensics and root cause analysis.
- Solid experience in cloud environments (AWS/GCP) with knowledge of cloud-native threats.
- Strong scripting and development skills (Python, Go, or Bash) for automation.
- Fluency with security frameworks (NIST 800-61, CIS Controls, MITRE ATT&CK, ISO 27001).
- Demonstrated ability to use AI tools in daily workflows (Level 1 AI proficiency).
Responsibilities
- Serve as the hands-on technical lead for Sword’s Security Operations Center, architecting the SIEM and engineering detection logic.
- Lead the SOC/CSIRT team technically, including mentoring engineers and acting as incident commander.
- Drive an AI- and automation-first transformation of security operations using SOAR and LLM-assisted workflows.
- Lead high-severity incident response, including investigation, containment, recovery, and post-incident reviews.
- Run threat intelligence and threat hunting programs to convert TTPs into new detections.
- Define and report on SOC performance metrics to drive continuous improvement.
View Full Description & ApplyYou'll be redirected to the employer's site