Remote job
AI SOC Lead
Job details
About this role
Role overview Lead day-to-day operations for a security operations shift, coordinating analysts and serving as the escalation point for complex incidents. The SOC uses AI agents to enrich alerts and support investigations; you will review their work and ensure automation is applied with appropriate human judgment and safeguards.
Responsibilities - Prioritize the alert queue, assign work, and keep client service commitments on track. - Lead complex incident response from initial triage through containment and handover. - Review AI-assisted triage and investigation findings, correcting inaccurate conclusions. - Tune SIEM and XDR detections, suppression rules, and AI prompts to reduce false positives. - Conduct threat hunts informed by current intelligence and MITRE ATT&CK techniques. - Coach L1 and L2 analysts, manage shift handovers, and review investigation quality. - Maintain playbooks and runbooks, including controls and approval steps for automated actions. - Communicate with client stakeholders during incidents and contribute to post-incident reviews.
Requirements - 6+ years in information security, including at least 3 years in SOC or incident response work. - Hands-on experience with a major SIEM and an EDR or XDR platform. - Strong knowledge of Windows, Linux, TCP/IP, DNS, HTTP, and cloud logs from AWS, Azure, or GCP. - Incident handling experience spanning detection, containment, and root-cause analysis. - Practical familiarity with LLM tools in security workflows and their limitations. - Experience leading or mentoring analysts in a 24×7 environment. - Excellent spoken and written English for client communication.