More jobs:
Security Operations Lead
Job in
Peoria, Peoria County, Illinois, 61639, USA
Listed on 2026-03-01
Listing for:
New York Technology Partners
Full Time
position Listed on 2026-03-01
Job specializations:
-
IT/Tech
Cybersecurity, IT Support, Systems Engineer
Job Description & How to Apply Below
Responsibilities
- Work with the Director of Information Security to build and execute a SOC modernization roadmap
- Standardize SOC workflows: intake, triage, investigation, escalation/handoff, closure
- Establish operational rhythms: queue health checks, weekly ops review, monthly metrics and outcomes, tabletop exercises & reviews
- Implement AI-assisted SOC capabilities that support analysts, including:
- Alert clustering/deduplication and prioritization support
- Automated enrichment (asset/user context, baselines, threat intel, cloud context)
- Investigation copilots (timeline generation, query suggestions, correlation summaries)
- Draft case notes and executive-ready incident summaries with links back to source evidence
- Assist with defining guardrails for AI usage: human approval gates, scoped permissions, audit trails, redaction/data handling, and “no unsupported claims” standards
- Evaluate vendors and/or internal approaches; run pilots, measure results, and lead production rollouts
- Coordinate integrations across SIEM, EDR, SOAR, cloud telemetry, ticketing, and collaboration/on-call tooling
- Partner with Platform Engineering to improve telemetry pipelines (parsing, normalization, enrichment, retention)
- Define operational acceptance criteria for changes (signal quality, latency, reliability, access controls)
- Partner with the Director of Information Security to drive SOC operational KPIs (e.g., time-to-triage, case aging, escalation completeness, automation coverage)
- Drive continuous improvement via regular reviews, quality sampling, and post-case learnings
- Identify recurring pain points and implement targeted fixes (playbooks, automation, training, data improvements)
- Train and mentor analysts on standard workflows and effective use of AI-assisted tooling
- Improve cross-functional handoffs between SOC, Engineering, IT, and Platform teams
- Provide concise operational updates to the Director of Information Security and leadership stakeholders
- 5+ years in security operations / SOC engineering / incident response operations (or equivalent)
- Strong understanding of SOC workflows, incident lifecycle, and escalation/handoff patterns
- Experience with SIEM/EDR ecosystems and integrating security tooling via APIs/webhooks
- Demonstrated ability to drive operational change: playbooks, metrics, quality, training, adoption
- Strong written communication and stakeholder management
- Experience deploying AI-assisted SOC tooling (copilots/agents) with governance
- SOAR/automation experience with approval-gated actions and safe defaults
- Familiarity with WQL (Wazuh), SPL (Splunk) and/or KQL (Microsoft Sentinel) and light scripting (Python/Bash)
- Cloud and identity familiarity (AWS/Azure/GCP, SSO/MFA/IAM)
- SOC workflows are consistent and measurable across analysts/shifts
- Alert noise is reduced, and investigations start with better context and faster handoffs
- AI-assisted tooling improves analyst throughput and documentation quality with strong guardrails
- Integrations and telemetry quality improvements materially reduce friction and case aging
- Leadership has clear metrics that show SOC operational uplift over time
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×