Security Operations Lead
Remote • Foster City, CA • FullTime
Posted 21d ago
About the job
Replit is seeking a Security Operations Lead (SOC Lead) to establish, enhance, and manage a 24/7 detection and response capability within a modern, cloud-native, and AI-driven environment. This leadership role will oversee global SOC functions including monitoring, SIEM management, detection engineering, alert triage, and operational readiness. A key aspect of this position involves evaluating and integrating emerging AI-based SOC products and autonomous response platforms. The role requires monitoring across multi-cloud environments (primarily GCP, with AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads. Collaboration with Cloud Security, Compliance/GRC, SRE, Platform Engineering, IT/Endpoint teams, and AI Infrastructure is essential to ensure the detection strategy scales effectively against evolving threats. This is a hands-on leadership opportunity to shape the future of SOC operations while addressing complex challenges in a high-scale AI setting.
Responsibilities
- Lead, mentor, and scale a global SOC team for 24/7 monitoring, alert intake, triage, correlation, and escalation.
- Establish operational rigor including processes, runbooks, SLAs, metrics, and quality standards for high-scale environments.
- Oversee monitoring across cloud infrastructure (GCP, AWS, Azure), Kubernetes clusters, SaaS platforms, endpoints, developer platforms, CI/CD pipelines, and AI/ML systems.
- Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation.
- Identify opportunities to automate triage, investigations, enrichment, and reporting.
- Serve as the internal expert on AI-based SOC tooling capabilities and limitations.
- Own the SIEM ecosystem, including ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics.
- Expand telemetry sources to include cloud logs, API logs, system events, SaaS audit logs, identity provider logs, and endpoint EDR/XDR event streams.
- Standardize data schemas and improve detection signal quality across all sources.
- Develop high-fidelity detections for cloud-native attacks, identity threats, lateral movement, SaaS misconfigurations, endpoint anomalies, insider threats, and account takeover patterns.
- Utilize MITRE ATT&CK, MITRE Cloud Matrix, and threat intelligence to guide detection coverage.
- Collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases.
- Lead day-to-day triage and threat analysis, ensuring accurate categorization and prioritization.
- Drive complex investigations involving correlated events across various platforms.
- Guide root cause analysis and collaborate on remediation and architectural improvements.
- Continuously refine detection logic, reduce false positives, and improve signal quality.
- Partner with Cloud Security on cloud posture and preventative controls.
- Work with Compliance/GRC to support SOC 2, ISO 27001, and audit readiness.
- Collaborate with SRE and Engineering to instrument new services with structured logs and detection hooks.
- Coordinate with IT/Endpoint teams for full endpoint telemetry and EDR response readiness.
- Communicate threats, gaps, and trends to leadership and engineering stakeholders.
Requirements
- 7+ years of experience in Security Operations, with at least 3 years in a senior or lead capacity.
- Experience leading or collaborating with 24/7 SOC environments.
- Strong experience with SIEM platforms (e.g., Chronicle, Splunk, Elastic, Sentinel, Panther).
- Deep understanding of cloud security monitoring (GCP required; AWS/Azure preferred).
- Deep understanding of SaaS security monitoring (e.g., Okta, Google Workspace, GitHub, Slack).
- Deep understanding of endpoint security telemetry (e.g., CrowdStrike, SentinelOne, Defender).
- Deep understanding of Kubernetes and container detection.
- Hands-on detection engineering skills, event correlation, threat hunting, and log analysis.
- Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools.
- Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns.
- Experience with SOAR and scripting languages (Python, Go, Bash).
- Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management.