Security Operations Lead

Remote Foster City, CA FullTime

Posted 21d ago

Job Location

Foster City, CA

Tech Stack

Remote Work Policy

Fully remote

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Replit is seeking a Security Operations Lead (SOC Lead) to establish, enhance, and manage a 24/7 detection and response capability within a modern, cloud-native, and AI-driven environment. This leadership role will oversee global SOC functions including monitoring, SIEM management, detection engineering, alert triage, and operational readiness. A key aspect of this position involves evaluating and integrating emerging AI-based SOC products and autonomous response platforms. The role requires monitoring across multi-cloud environments (primarily GCP, with AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads. Collaboration with Cloud Security, Compliance/GRC, SRE, Platform Engineering, IT/Endpoint teams, and AI Infrastructure is essential to ensure the detection strategy scales effectively against evolving threats. This is a hands-on leadership opportunity to shape the future of SOC operations while addressing complex challenges in a high-scale AI setting.

Responsibilities

  • Lead, mentor, and scale a global SOC team for 24/7 monitoring, alert intake, triage, correlation, and escalation.
  • Establish operational rigor including processes, runbooks, SLAs, metrics, and quality standards for high-scale environments.
  • Oversee monitoring across cloud infrastructure (GCP, AWS, Azure), Kubernetes clusters, SaaS platforms, endpoints, developer platforms, CI/CD pipelines, and AI/ML systems.
  • Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation.
  • Identify opportunities to automate triage, investigations, enrichment, and reporting.
  • Serve as the internal expert on AI-based SOC tooling capabilities and limitations.
  • Own the SIEM ecosystem, including ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics.
  • Expand telemetry sources to include cloud logs, API logs, system events, SaaS audit logs, identity provider logs, and endpoint EDR/XDR event streams.
  • Standardize data schemas and improve detection signal quality across all sources.
  • Develop high-fidelity detections for cloud-native attacks, identity threats, lateral movement, SaaS misconfigurations, endpoint anomalies, insider threats, and account takeover patterns.
  • Utilize MITRE ATT&CK, MITRE Cloud Matrix, and threat intelligence to guide detection coverage.
  • Collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases.
  • Lead day-to-day triage and threat analysis, ensuring accurate categorization and prioritization.
  • Drive complex investigations involving correlated events across various platforms.
  • Guide root cause analysis and collaborate on remediation and architectural improvements.
  • Continuously refine detection logic, reduce false positives, and improve signal quality.
  • Partner with Cloud Security on cloud posture and preventative controls.
  • Work with Compliance/GRC to support SOC 2, ISO 27001, and audit readiness.
  • Collaborate with SRE and Engineering to instrument new services with structured logs and detection hooks.
  • Coordinate with IT/Endpoint teams for full endpoint telemetry and EDR response readiness.
  • Communicate threats, gaps, and trends to leadership and engineering stakeholders.

Requirements

  • 7+ years of experience in Security Operations, with at least 3 years in a senior or lead capacity.
  • Experience leading or collaborating with 24/7 SOC environments.
  • Strong experience with SIEM platforms (e.g., Chronicle, Splunk, Elastic, Sentinel, Panther).
  • Deep understanding of cloud security monitoring (GCP required; AWS/Azure preferred).
  • Deep understanding of SaaS security monitoring (e.g., Okta, Google Workspace, GitHub, Slack).
  • Deep understanding of endpoint security telemetry (e.g., CrowdStrike, SentinelOne, Defender).
  • Deep understanding of Kubernetes and container detection.
  • Hands-on detection engineering skills, event correlation, threat hunting, and log analysis.
  • Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools.
  • Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns.
  • Experience with SOAR and scripting languages (Python, Go, Bash).
  • Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management.

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.