Security Operations Lead (SecOps)
Sword HealthPortugalhá mais de um mês
- Presencial
- Tempo inteiro
- Líder
Descrição
Sword Health is seeking a Security Operations Lead to establish and lead the company's Security Operations Center. In this role, you'll own the detection, investigation, and response to threats across Sword's infrastructure protecting 700,000+ members. You'll set the technical direction for SIEM architecture, detection engineering, and incident response, while building a culture of automation and AI-driven security operations at enterprise scale across a fast-growing, multi-continent footprint.
You'll drive an AI- and automation-first transformation of security operations by designing SOAR playbooks, agentic and LLM-assisted triage workflows, and ML-driven detection to reduce mean time to detection and response. As the technical leader of the SOC/CSIRT team, you'll mentor detection and response engineers, establish on-call and escalation models, act as commander for major incidents, and own the full SIEM end-to-end including architecture, data sources, normalization, retention, and tuning aligned to MITRE ATT&CK and Sword's threat model.
This is a strategic role where you'll influence security architecture decisions across the company, establish and improve incident response playbooks and runbooks, run threat intelligence and threat hunting programs, and define SOC performance metrics to drive continuous improvement. You'll partner closely with engineering, IT, legal, and executive stakeholders during critical security events.
Competências
- SIEM (Splunk, Sentinel, Chronicle, Elastic)
- Security Operations Center (SOC) management
- Incident Response
- Detection Engineering
- SOAR (Security Orchestration, Automation and Response)
- Cloud Security (AWS, GCP)
- EDR/XDR
- Threat Intelligence
- Threat Hunting
- Threat Modeling
- Digital Forensics
- Python
- Go
- Bash
- Scripting
- MITRE ATT&CK
- NIST 800-61
- CIS Controls
- ISO 27001
- Identity and Access Management
- Network Detection
- Machine Learning for Security
- LLM-assisted automation
- AI for security operations
Responsabilidades
- Set the strategy and technical direction for Sword's Security Operations Center, defining the operating model, SIEM and detection architecture, incident response capability, and the roadmap to scale as the company grows
- Drive an AI- and automation-first transformation of security operations by designing SOAR playbooks, agentic and LLM-assisted triage workflows, and ML-driven detection to reduce MTTD/MTTR
- Lead the SOC/CSIRT team technically, mentoring detection and response engineers, raising the bar on investigations, running on-call and escalation models, and acting as commander for major incidents
- Own the SIEM end-to-end including architecture, data sources, normalization, retention, cost, and tuning
- Evolve detection-as-code content aligned to MITRE ATT&CK and Sword's threat model
- Lead high-severity incident response from detection through containment, eradication, recovery, and post-incident review
- Partner with engineering, IT, legal, and executive stakeholders during critical security events
- Run the threat intelligence and threat hunting programs, converting emerging TTPs into new detections
- Define and report on SOC performance metrics including MTTD, MTTR, coverage, automation rate, and false-positive rate
- Influence security architecture and engineering decisions across the company to ensure detection, response, and recovery are built into new products and infrastructure
- Establish and continuously improve incident response playbooks, runbooks, and tabletop exercises
Benefícios
- Portugal-based benefits and perks package
Conhece alguém para esta vaga?