Overview
In this hands-on, executive role, you lead Sportradar’s Security Operations end-to-end, owning the global SOC, incident response, detection engineering, and threat intelligence. You’ll shape the operating model, on-call structure, tooling, and automation, and personally lead major incidents to set the standard. You’ll work closely with engineering, product security, and the wider InfoSec leadership to ensure defensible systems and clear risk communication. This is a high-impact opportunity to influence security across a world-spanning sports tech ecosystem.
Pay / Benefits
- flexible working model
- office-first hybrid culture
- career and personal development plans
- global, diverse team
- opportunity to work with senior leadership
- collaborative, fast-growing environment
Responsibilities
- Own incident response end-to-end: preparation, triage, containment, eradication, post-incident reviews
- Build and evolve the SOC, including operating model, on-call structure, tooling, and automation
- Treat detection engineering as an engineering discipline: detections as code, versioned and tuned to real threats
- Develop and operationalize threat intelligence to drive hunts, detections, and leadership briefings
- Be the voice of operational reality at the leadership table, aligning security with engineering and product roadmaps
- Define and improve metrics: detection coverage, investigation quality, time to detect/contain, and lessons learned
- Lead globally distributed technical teams across multiple time zones
- Hands-on experience with SIEM/Data Lakes implementation and support
- Experience with DDoS mitigation and threat hunting/purple teaming
Key requirements
- Deep, current incident response experience with hands-on leadership of serious incidents
- Proven track record building or rebuilding a SOC with operating model, hiring, tooling, and metrics
- Strong cloud security expertise across AWS, GCP, Azure including identity, logging, lateral movement, containment
- Detection engineering experience: rule development, coverage mapping, tuning, automation
- Threat intelligence experience: building/running an intel function that informs hunts and detections
- Experience leading globally distributed technical teams
- Hands-on experience with SIEM/Data Lakes
- Experience with DDoS mitigation
- Threat hunting and purple teaming experience
- leadership
- strong communication at executive level
- cross-functional collaboration
- SIEM
- Data Lakes
- Cloud security (AWS, GCP, Azure)
…
