Talent Apply
Log in
All jobs
H

Security Operations Lead

HiringCafe
Foster City, California, United States
HybridUSD 220,000 - 325,000 / year

About this role

Job title: Security Operations Lead

About the Role Replit is seeking a Security Operations Lead to build, mature, and operate our 24/7 detection and response capabilities across a modern cloud-native and AI-driven environment. You will lead the global SOC function—monitoring, SIEM ownership, detection engineering, alert triage, and operational readiness—while evaluating and integrating emerging AI-based SOC products and autonomous response platforms.

This role oversees monitoring across multi-cloud environments (GCP primary, AWS/Azure secondary), Kubernetes, SaaS services, endpoints, developer tools, and AI workloads. You’ll collaborate closely with Cloud Security, Compliance/GRC, SRE, Platform Engineering, IT/Endpoint teams, and AI Infrastructure to ensure our detection strategy scales and stays ahead of evolving threats.

This is a hands-on leadership role ideal for someone who wants to shape the SOC of the future in a high-scale AI setting.

What You'll Do

  • Lead, mentor, and scale a global SOC team responsible for 24/7 monitoring, alert intake, triage, correlation, and escalation.
  • Build operational rigor: processes, runbooks, SLAs, metrics, and quality standards for high-scale environments.
  • Cover monitoring across Cloud infrastructure (GCP, AWS, Azure); Kubernetes/GKE/EKS/AKS clusters; SaaS platforms (Google Workspace, GitHub, Slack, Okta, etc.); Endpoints (macOS, Linux, Windows) including EDR/XDR telemetry; Developer platforms + CI/CD pipelines; AI/ML systems and model-serving workflows.
  • Evaluate, adopt, and integrate AI-native SOC technologies for triaging, detection, and correlation; identify opportunities to automate triage, investigations, enrichment, and reporting.
  • Own the SIEM ecosystem—ingestion, normalization, correlation, enrichment, tuning, dashboards, and metrics; expand telemetry across cloud logs, API logs, system events, SaaS audit logs and admin events, identity providers, and endpoint telemetry.
  • Develop high-fidelity detections for cloud-native attacks, identity threats and lateral movement, SaaS misconfigurations and privilege abuse, endpoint malware/behavior anomalies, insider threats and account takeover patterns.
  • Use MITRE ATT&CK, MITRE Cloud Matrix, and threat intel to drive detection coverage; collaborate with Engineering, Cloud Security, and SRE to ensure telemetry supports detection use cases.
  • Lead day-to-day triage and threat analysis activities, guiding root cause analysis and remediation; drive complex investigations across cloud, SaaS, endpoints, and developer platforms; continuously refine logic to reduce false positives.
  • Partner with Cloud Security on cloud posture and preventative controls; work with Compliance/GRC to support SOC 2, ISO 27001; collaborate with SRE and Engineering to instrument new services with structured logs and detection hooks; coordinate with IT/Endpoint teams to ensure full endpoint telemetry and EDR readiness; communicate threats and trends to leadership.

What We're Looking For

  • 7+ years of experience in Security Operations, with 3+ years in a senior or lead capacity.
  • Experience leading or collaborating with 24/7 SOC environments (internal, hybrid, or MSSP).
  • Strong experience with SIEM platforms (Chronicle, Splunk, Elastic, Sentinel, Panther, etc.).
  • Deep understanding of Cloud security monitoring (GCP required; AWS/Azure preferred).
  • SaaS security monitoring (Okta, Google Workspace, GitHub, Slack, etc.).
  • Endpoint security telemetry (EDR/XDR tools such as CrowdStrike, SentinelOne, or Defender).
  • Kubernetes and container detection; hands-on detection engineering, event correlation, threat hunting, and log analysis.
  • Familiarity with AI-based SOC platforms and LLM-driven detection/triage tools.
  • Strong understanding of identity security, OAuth/OIDC, and API telemetry patterns.
  • Experience with SOAR and scripting (Python, Go, Bash).
  • Knowledge of MITRE ATT&CK, cloud kill chains, behavioral detections, and detection lifecycle management.

Nice to Have

  • Experience integrating AI-based SOC products and autonomous response platforms across multi-cloud environments.
  • Track record of scaling SOC functions in high-scale AI settings.

Compensation & Benefits

  • Salary: $220,000-$325,000 per year.
  • Hybrid, Full-Time role.
  • Benefits not explicitly listed in posting.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →