via Remote Rocketship
$90K - 150K a year
Lead and manage global security operations, incident response, and exposure management functions while building scalable teams and processes.
7+ years in security operations leadership with hands-on incident response and detection engineering experience, strong AI and automation skills, and ability to lead global teams.
Job Description: • Build and run a scalable global security operations capability • Own daily security operations service delivery, including ticket intake, triage, prioritization, escalation, case quality, and closure • Manage managed security service providers and other third-party security services • Establish severity definitions, investigation standards, escalation paths, response playbooks, and executive notification criteria • Report operational health and risk to the CISO using coverage, detection quality, response, backlog, and remediation measures • Build the operating model and talent roadmap for a scalable global security operations function • Lead enterprise-wide security operations and incident response, including detection, triage, containment coordination, eradication support, root-cause analysis, and post-incident review • Own incident documentation, evidence preservation, lessons learned, corrective actions, and closure validation • Lead incident tabletop exercises and coordinate security participation in recovery readiness • Partner with IT, engineering, manufacturing, and business service owners on timely remediation • Establish the cadence for converting vulnerability, asset, identity, cloud, and threat findings into prioritized remediation actions • Track remediation commitments, challenge overdue high-risk items, and escalate unresolved exposure • Ensure security monitoring and response requirements are incorporated into major initiatives • Define telemetry standards, coverage models, automation pipelines, and detection use cases • Improve detection fidelity through tuning, enrichment, automation, and lifecycle management • Leverage approved AI capabilities and automation to improve detection, investigation, response, documentation, and security operations maturity • Define monitoring and logging requirements and close coverage gaps • Translate threat intelligence into detections, hunts, response playbooks, and countermeasures • Collaborate with vulnerability management, risk, and red teams to reduce attack surface • Understand and respond to IOCs, TTPs, ransomware, and supply-chain threats • Report to the CISO and lead and develop internal staff as the function grows Requirements: • 7+ years of progressive information security experience, including substantial hands-on experience in security operations, incident response, detection engineering, or exposure management • Demonstrated experience leading a SOC, MDR/MSSP service, incident response function, or comparable global security operations capability • Strong applied AI acumen, including evaluating and leveraging generative AI, security platform AI capabilities, and automation • Experience managing and developing analysts/engineers is preferred • Ability to build an operating model and lead through influence • Strong practical experience with SIEM, EDR/XDR, SOAR or case management, vulnerability management workflows, IAM telemetry, cloud logging, and incident response processes • Familiarity with OT/industrial security concepts and production-environment constraints is preferred • Experience supporting defense, aerospace, manufacturing, or similar complex hybrid environments is preferred • Exceptional communication skills and ability to translate technical risk to the business • CISSP, CISM, CCSP, OSCP, or related GIAC certification is preferred • Bachelor's degree from an accredited college/university or equivalent experience • If applicable, must satisfy U.S. export-control requirements, including documentation needed to assess U.S. Person status or obtain an export license Benefits: • Remote work arrangement • Equal employment opportunity protections for protected veterans and individuals with disabilities • Reasonable accommodation for applicants with disabilities
This job posting was last updated on 9/23/2026