Lead Software Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Job Description: Our client is seeking a Lead Security Analyst to serve as a technical leader within their Security Operations Center, supporting a large enterprise healthcare environment. This role blends hands-on security engineering with incident command responsibilities, requiring someone equally comfortable responding to active threats and advising on long-term security posture improvements. The ideal candidate brings strong judgment, clear communication skills, and the ability to engage directly with end users and stakeholders across the organization.
Day-to-Day Responsibilities:
- Lead cyber incident triage and response, determining scope, urgency, and next steps through resolution or escalation
- Serve as incident commander during major security events, coordinating response efforts and communicating with stakeholders
- Design, tune, and maintain detection logic, correlation rules, dashboards, and alerts within Microsoft Sentinel and the broader Microsoft security stack
- Lead and participate in proactive threat hunting activities to identify indicators of compromise before incidents occur
- Develop and maintain security automation playbooks and SOAR workflows to improve response speed and consistency
- Support onboarding, parsing, and normalization of log sources into the SIEM
- Write and maintain incident response playbooks, runbooks, and SOPs
- Mentor and support SOC analysts, promoting a culture of continuous improvement
- Participate in after-hours on-call rotation on a monthly basis
- Partner with Infrastructure, Compliance, and Operations teams on security initiatives
Requirements
- Senior-level Security Analyst experience with a blend of security operations and security engineering
- Hands-on experience deploying and administering Microsoft Sentinel
- Experience leading incident investigations and coordinating response efforts at enterprise scale
- Proven track record creating security automation playbooks and response workflows
- Strong background tuning detections, alerts, and correlation rules
- Experience supporting environments with 35,000 users or similarly large organizations
- Deep expertise in the Microsoft security ecosystem, including Azure, Microsoft Defender Suite, and related services
- Experience leveraging AI-enabled security tools, including Microsoft Copilot for Security
- Strong communication skills with the ability to engage directly with end users and non-technical stakeholders
- Familiarity with HIPAA and regulated/healthcare environments
Preferred Qualifications:
- Experience with CrowdStrike or other enterprise EDR platforms
- Background assessing security programs and providing strategic improvement recommendations
- Experience with security operations automation, orchestration, and response best practices, * Senior-level Security Analyst experience with a blend of security operations and security engineering
- Hands-on experience deploying and administering Microsoft Sentinel
- Experience leading incident investigations and coordinating response efforts at enterprise scale
- Proven track record creating security automation playbooks and response workflows
- Strong background tuning detections, alerts, and correlation rules
- Experience supporting environments with 35,000 users or similarly large organizations
- Deep expertise in the Microsoft security ecosystem, including Azure, Microsoft Defender Suite, and related services
- Experience leveraging AI-enabled security tools, including Microsoft Copilot for Security
- Strong communication skills with the ability to engage directly with end users and non-technical stakeholders
- Familiarity with HIPAA and regulated/healthcare environments, * Experience with CrowdStrike or other enterprise EDR platforms
- Background assessing security programs and providing strategic improvement recommendations
- Experience with security operations automation, orchestration, and response best practices
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
The 12 Best Jobs for Software Engineers
Fully Remote Software Engineer Jobs