> Markdown version of [/jobs/ext/472621-information-security-lead-cyber-security-and-operations](https://www.wearedevelopers.com/jobs/ext/472621-information-security-lead-cyber-security-and-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Lead - Cyber Security and Operations - **Company:** Sidley Austin LLP - **Location:** Chicago, IL, United States - **Experience:** Expert - **Salary:** $140,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Information Leak Prevention, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Network Security, Reverse Engineering, Security Information and Event Management, Software Vulnerability Management, Malware, Firewalls (Computer Science), Information Technology - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c35a93ece50a3dfc ## About the Role Do you have experience in Triage?, Do you have a Bachelor's degree?, * Bachelor's degree or equivalent combination of education and/or experience * Minimum of 7 years of experience in an Information Security role with at least two years in an incident response, threat analysis, or a security operation center role. * Relevant knowledge and experience in two or more of the following areas: incident response, threat analysis, malware response , security operations, Network Security/next generation firewall, proxy configuration and management * Demonstrated experience in threat detection technologies including two or more of the following: network or host intrusion prevention/detection systems (IPS/IDS), Endpoint Protection, Security Incident Event Management (SIEM), data loss prevention (DLP), Cloud Access Security * Broker (CASB), Next-Gen Firewall (NGFW), or Multifactor-Authentication platforms (MFA) * Demonstrated ability to analyze security events, perform initial triage, and determine appropriate next steps * Demonstrated experience in security projects development, security vendor or services management, and request for proposal processes and procedures Preferred: * Bachelor's degree * Certified Information Systems Security Professional (CISSP) or equivalent is preferred * One or more of the following technical certifications is preferred: GIAC Certified Incident Handler (GCIH), GIAC Certified Forensics Analyst (GCFA), or GIAC Reverse Engineering Malware (GREM), EC-Council Certified Security Analyst Other Skills and Abilities: The following will also be required of the successful candidate: * Strong organizational skills * Strong attention to detail * Good judgment * Strong interpersonal communication skills * Strong analytical and problem solving skills * Able to work harmoniously and effectively with others * Able to preserve confidentiality and exercise discretion * Able to work under pressure * Able to manage multiple projects with competing deadlines and priorities #LI-OE1 ## Description The Information Security Lead for the Cyber Security & Operations function is responsible for providing continuous threat monitoring and incident response services. This individual is responsible for monitoring, developing, and maintaining the tools, technologies, and processes that enable the organization to detect and prevent computer security threats. The Senior Information Security Lead acts as a subject matter expert and works with cross-functional teams as required to perform incident investigations and response activities. This individual participates in the Information Security Operations Center which provides timely investigation and response to potential IT incidents through the continuous monitoring and tracking of security events., * Provide primary support for the network security solutions, including next generation firewalls, web proxies, Cloud Access Security Broker (CASB) technologies and other network security technologies * Participate in and lead troubleshooting and resolution efforts for wide range of security and network related issues * Review and triage information security alerts, provide analysis, determine and track remediation, and escalate as appropriate * Proactively identify and assess security risks and works in advisory capacity for technical teams on mitigation strategies * Participate as a member of the Information Security Operations Team (SecOps) by responding to information security incidents according to the Incident Response Plan * Help build skillset of less experienced security personnel through knowledge transfer and mentoring * Perform review of scheduled information security reports to identify abnormal or potentially suspicious activity within the environment * Maintain the operational integrity of the Security Operations Center (SOC) through monitoring and periodic testing of critical tools and processes * Develop working relationships with cross-functional teams from Information Technology, Physical Security, Human Resources, Marketing, Privacy, Legal, and third-party vendors to effectively respond to security incidents * Document information security incident reports to capture relevant details including approach, root cause, lessons learned, and process improvements * Contribute to the advancement of the security monitoring program through thought leadership and guidance on tools, technologies, and processes that provide automated and proactive detection and prevention * Develop and improve process/procedure manuals and documentation related to incident response, threat intelligence, threat detection, and analysis of vulnerabilities * Propose and generate metrics with emphasis on Security Operation Center (SOC) Key Performance Indicators (KPI). Provide secondary support for the log management and Security Information and Event Monitoring (SIEM) solutions, Multifactor Authentication platform (MFA), Privilege Access Management platform (PAM), and vulnerability management tools ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland)