Overview
In this hands-on leadership role, you own Security Operations end to end, including the SOC, incident response, detection engineering, and threat intelligence. You will lead a global team, shape the operating model, and set the standard for incident handling. You will drive detections as code, advance threat intel, and ensure effective collaboration with engineering and product security. This role offers the chance to build a next-generation security function and influence a fast-growing digital-sports environment.
Pay / Benefits
- flexible working model
- office-first hybrid (four days in office)
- career and personal development plan
- diverse, collaborative global team
- impactful work shaping products and security posture
Responsibilities
- Own incident response lifecycle end to end (preparation, triage, containment, eradication, post-incident reviews)
- Lead the global SOC and related functions (IR, detection engineering, threat intelligence)
- Design and evolve the security operating model, on-call structure, tooling, and automation
- Develop detections as code, map detections to real threats, and drive coverage across cloud and applications
- Build and lead a genuine intel capability to inform hunts, detections, and leadership briefings
- Represent operational reality at leadership levels and collaborate with engineering and product security
- Define and improve metrics for detection coverage, investigation quality, and time to detect/contain
- Lead major incidents personally and establish standards for incident handling
- Create a scalable SOC build (either from scratch or major rebuild)
- Drive alignment between security outputs and business objectives
Key requirements
- Deep incident response experience with hands-on leadership of major incidents
- Built or rebuilt a SOC with strong operating model, tooling, and metrics
- Strong cloud security grounding (AWS, GCP, Azure) including identity, logging, lateral movement, containment, IR in cloud
- Detection engineering experience (rule development, coverage mapping, tuning, automation)
- Threat intelligence experience with operationalized intel feeding hunts and detections
- Track record leading globally distributed technical teams across time zones
- Hands-on experience with SIEM/Data Lakes, implementing and supporting
- Experience with DDoS mitigation
- Experience with threat hunting and purple teaming
- Strategic thinking
- Cross-functional collaboration
- Effective communication with leadership
- SIEM/Data Lakes
- Cloud security (AWS, GCP, Azure)
- Detection engineering and automation
…
