Security Operations Lead @Sword
All Others
Salary $133,978 - $210..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Security Operations Lead @Sword

1wk ago - Sword is hiring a remote Security Operations Lead. πŸ’Έ Salary: $133,978 - $210,537 per year πŸ“Location: USA

Role Description

As Security Operations Lead, you'll lead our SecOps squad and own how Sword detects, investigates, and responds to threats. You'll help structure how this function operates β€” setting the direction on SIEM architecture, detection engineering, and incident response β€” and use automation and AI to scale a focused team across a fast-growing, multi-continent footprint. You'll be a core voice in our security strategy, and the systems, processes, and culture you build will set the bar for how Sword protects 700,000+ members.

What you’ll be doing:

  • Serve as the hands-on technical lead for Sword’s Security Operations Center.
  • Setting the technical direction β€” architecting the SIEM, engineering detection logic, executing incident response, and building the technical roadmap to scale our defenses as the company grows.
  • Own the SIEM end-to-end (architecture, data sources, normalization, retention, cost, and tuning) and evolve detection-as-code content aligned to MITRE ATT&CK and Sword’s threat model.
  • Lead the SOC/CSIRT team technically β€” mentoring detection and response engineers, raising the bar on investigations, running on-call and escalation models, and acting as commander for major incidents.
  • Set the strategy and technical direction for Sword’s Security Operations Center β€” defining the operating model, SIEM and detection architecture, incident response capability, and the roadmap to scale them as the company grows.
  • Drive an AI- and automation-first transformation of security operations: design SOAR playbooks, agentic and LLM-assisted triage workflows, and ML-driven detection to reduce MTTD/MTTR, expand coverage, and let a lean team operate at enterprise scale.
  • Lead high-severity incident response from detection through containment, eradication, recovery, and post-incident review, partnering with engineering, IT, legal, and executive stakeholders during critical events.
  • Run the threat intelligence and threat hunting programs, converting emerging TTPs into new detections, proactive hardening, and informed risk decisions.
  • Advanced Incident Response & Threat Hunting: Lead end-to-end incident investigations in Google SecOps, leveraging complex telemetry correlation to proactively hunt for threats, contain active incidents, and drive root-cause remediation.
  • Define and report on SOC performance β€” MTTD, MTTR, coverage, automation rate, false-positive rate, on-call health β€” and use those metrics to drive measurable, continuous improvement.
  • Influence security architecture and engineering decisions across the company, ensuring detection, response, and recovery are built into new products, platforms, and infrastructure from day one.
  • Detection & Automation Leadership: Architect, refine, and maintain custom YARA-L detection rules and SOAR playbooks in Google SecOps to automate triage, alert enrichment, and initial incident response.

Qualifications

  • Public Trust Clearance - Candidates must be able to obtain and maintain a US public trust clearance.
  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
  • 7+ years experience in Security Operations.
  • Proven experience scaling a SOC through automation and AI β€” SOAR, hyperautomation, LLM-assisted triage, agentic workflows, or ML-driven detection β€” with measurable impact on MTTR, coverage, or analyst leverage.
  • Hands-on experience structuring a SOC, either building one from the ground up or maturing one through significant transformation β€” SIEM selection, implementation or migration, detection engineering practice, runbook libraries, on-call rotations, and operating metrics.
  • Deep SIEM expertise (Splunk, Sentinel, Google SecOps/Chronicle, Elastic, or similar) β€” ingestion architecture, detection-as-code, query optimization, and coverage-versus-cost tradeoffs.
  • Highly preferred: Google SecOps/Chronicle.
  • Prior experience as the technical lead of a SOC or CSIRT team β€” owning the full incident response lifecycle, mentoring analysts and engineers, and acting as on-call/incident commander during major incidents.
  • Strong incident response track record β€” leading high-severity investigations, root cause analysis, digital forensics, and post-incident reviews that produced durable improvements.
  • Solid experience in cloud environments (AWS and/or GCP), with strong understanding of cloud-native threats and controls.
  • Strong scripting and development skills (Python, Go, Bash, or similar) for building automation, integrations, and internal tooling.
  • Working knowledge of EDR/XDR, identity, and network detection telemetry, and how to combine signals into high-fidelity detections.
  • Fluency with security frameworks and standards (NIST 800-61, CIS Controls, MITRE ATT&CK, ISO 27001) and the judgment to apply them pragmatically.
  • Background in threat modeling, adversary emulation, and risk-based alert tuning.
  • Excellent communicator β€” able to brief executives during a Sev1, write a clear post-mortem, and translate technical risk into business language for non-technical audiences.
  • Proven track record of leading cross-functional efforts in high-pressure situations and fostering collaboration across InfoSec, IT, and engineering.
  • Forensics experience, investigating incidents and preserving digital evidence.

Requirements

  • Public Trust Clearance - Candidates must be able to obtain and maintain a US public trust clearance.
  • US citizenship is required to obtain and maintain a government security clearance.

Benefits

  • Total Compensation Range: $133,978 β€” $210,537 USD.
  • Country-specific benefits may vary and will be detailed separately.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Security Operations Lead @Sword
All Others
Salary $133,978 - $210..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,098+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later