Lead Cybersecurity Engineer
Free to start · No card · 5 credits the moment you sign up
Job description
About the Role:
We are seeking a Lead, Cybersecurity Operations to play a critical role in advancing our global Cybersecurity Operations (CSOC) capabilities.
This individual will serve as a senior technical leader responsible for overseeing threat detection, incident response, and continuous improvement of security operations across the organization. As part of the Cybersecurity Operations Team, the Lead will drive operational excellence by enhancing detection strategies, improving incident response processes, and ensuring effective use of security technologies. This role acts as the primary technical escalation point for analysts and a key liaison between leadership and the SOC team—translating strategic direction into actionable work and ensuring meaningful outcomes.
This position requires a hands-on leader with deep technical expertise, strong operational awareness, and a passion for elevating both team performance and cybersecurity capabilities in a fast-paced, evolving threat landscape.
Responsibilities:
-
Lead Cybersecurity Operations Execution & Quality
Oversee day-to-day security monitoring, detection, and response activities, ensuring high-quality investigations and timely remediation of security events and incidents. -
Serve as Primary Technical Escalation Point
Act as the go-to escalation resource for analysts, providing hands-on guidance for complex investigations and ensuring consistency and depth in investigative outcomes. -
Own Incident Response Lifecycle & Stakeholder Coordination
Lead and coordinate complex security incidents end-to-end, while acting as a liaison between leadership and the SOC—translating strategic direction into actionable tasks and delivering clear, meaningful updates. -
Drive Detection & Response Maturity (SIEM & Tooling)
Lead SIEM-driven operations and continuously improve detection capabilities through use-case development, tuning, telemetry optimization, and enhanced coverage across security domains. -
Coordinate SME Programs & Operational Initiatives
Break down strategic cybersecurity objectives into actionable workstreams, track progress, remove blockers, and ensure successful execution of team initiatives. -
Develop & Optimize Playbooks, Processes, and Automation
Create and refine incident response playbooks, SOPs, and automation opportunities to improve consistency, efficiency, and scalability of operations. -
Leverage Metrics & Threat Insights to Drive Improvement
Track key operational metrics (MTTD, MTTR, alert fidelity) and conduct advanced threat analysis to inform decisions, strengthen defenses, and continuously improve security posture.
Requirements:
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent practical experience).
- Security+, GCIH, GCIA, GCED, or equivalent certifications.
- 5–8+ years of experience in cybersecurity operations or SOC environments
- Proven experience leading or coordinating incident response activities
- Hands-on experience with SIEM platforms and building detection-driven operations
- Strong familiarity with security technologies such as EDR, NDR, email security, WAF, and identity/security monitoring tools
Originally posted on Himalayas
Prepare your application
Use the description above to assess your fit for RBGlobal. This checklist is guidance from Resumize, rather than additional requirements from the employer. Imported listings can be shortened or change after collection, so confirm the complete description and current availability before sending an application.
Match requirements to evidence
Identify the responsibilities and skills the employer explicitly names. For each important requirement, choose one example from your work, education, training, or projects. Explain what you did, how you did it, and what changed as a result. Include a measurable outcome when you can support it. If you lack a requirement, describe related experience accurately instead of adding an unfamiliar skill to your resume.
Put the most relevant examples near the top of your resume. Keep job titles, dates, qualifications, and contact details consistent across your application materials. Use the employer’s terminology when it describes your experience accurately; a copied list of keywords does not explain your contribution. A short, specific bullet is easier to review than a paragraph that mixes several unrelated duties.
Check the working arrangement
Confirm the location, schedule, employment type, and any eligibility requirements on the employer’s site. A remote label does not establish worldwide eligibility or flexible hours. If compensation, benefits, equipment, travel, or contract duration are missing from this listing, write down your questions for the recruiter. Do not assume details from another opening at the same company apply to this role.
Review before submitting
Follow the employer’s requested file format and application instructions. Open your exported resume and check that its text is selectable, its sections read in order, and its links work. Proofread names, dates, and contact information. Share confidential work samples only when you have permission, and use an anonymized example when necessary.
Submit through a trusted employer or recruiting destination. If the original listing has disappeared, search the employer’s careers page for the title rather than assuming the vacancy remains open. Save the application date, job reference, and the version of your resume you sent. Those details help you prepare for a later conversation and avoid submitting conflicting information through several job boards.
Review your resume for writing and readability feedback, or browse other openings if this opportunity is unavailable.