Security Operations Lead (SecOps)

3 months, 2 weeks ago
Full-time
Lead
DevOps and Infrastructure
SWORD Health

SWORD Health

SWORD Health provides AI-powered digital physical therapy solutions designed to prevent pain, support recovery, and enhance overall health, while also aiming to transform the rehabilitation industry through innovative technology and clinical oversight.

Health Care Providers & Services
251-1K
Founded 2015
$324M raised

Description

  • Set the strategy and technical direction for the Security Operations Center, including operating model, SIEM and detection architecture, and incident response capability.
  • Drive an AI- and automation-first transformation of security operations through SOAR playbooks, agentic and LLM-assisted triage workflows, and ML-driven detection.
  • Lead the SOC/CSIRT team technically by mentoring detection and response engineers, managing on-call and escalation models, and serving as incident commander for major events.
  • Own the SIEM end to end, including architecture, data sources, normalization, retention, cost management, tuning, and detection-as-code content.
  • Lead high-severity incident response from detection through containment, eradication, recovery, and post-incident review.
  • Run threat intelligence and threat hunting programs and turn emerging TTPs into new detections and proactive hardening measures.
  • Define, track, and report SOC performance metrics such as MTTD, MTTR, coverage, automation rate, false-positive rate, and on-call health.
  • Influence security architecture and engineering decisions so detection, response, and recovery are built into products, platforms, and infrastructure from the start.
  • Establish and continuously improve incident response playbooks, runbooks, and tabletop exercises to improve readiness.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
  • Proven experience scaling a SOC through automation and AI, such as SOAR, hyperautomation, LLM-assisted triage, agentic workflows, or ML-driven detection.
  • Hands-on experience building or maturing a SOC, including SIEM selection, implementation or migration, detection engineering, runbook libraries, on-call rotations, and operating metrics.
  • Deep SIEM expertise with tools such as Splunk, Sentinel, Chronicle, Elastic, or similar.
  • Prior experience as the technical lead of a SOC or CSIRT team, owning the full incident response lifecycle and acting as incident commander during major incidents.
  • Strong incident response experience, including high-severity investigations, root cause analysis, digital forensics, and post-incident reviews.
  • Solid experience in cloud environments, especially AWS and/or GCP, with understanding of cloud-native threats and controls.
  • Strong scripting and development skills in Python, Go, Bash, or similar for automation, integrations, and internal tooling.
  • Working knowledge of EDR/XDR, identity, and network detection telemetry and how to combine signals into high-fidelity detections.
  • Fluency with security frameworks and standards such as NIST 800-61, CIS Controls, MITRE ATT&CK, and ISO 27001.
  • Background in threat modeling, adversary emulation, and risk-based alert tuning.
  • Excellent communication skills for executive briefings, post-mortems, and translating technical risk into business language.
  • Proven ability to lead cross-functional efforts in high-pressure situations across InfoSec, IT, and engineering.
  • Forensics experience, including investigating incidents and preserving digital evidence.
  • Valid EU visa and based in Portugal.
  • Preferred AI fluency at Sword Health, with at least Level 1 demonstrated through real examples of using AI in work.

Benefits

  • €50,400 - €79,200 annual compensation, including base pay, variable pay, and equity.
  • Equity shares / stock options as part of total compensation.
  • Health, dental, and vision insurance.
  • Meal allowance.
  • Remote work allowance plus work-from-home flexibility.
  • Flexible working hours.
  • Discretionary vacation.
  • Snacks and beverages.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Incident Responder

Dragos 251-1K Professional Services

Dragos is hiring a Senior Incident Responder in Singapore to support APAC customers by investigating and coordinating responses to high-impact incidents across complex OT environments.

21 hours, 1 minute ago

Senior SOC Analyst | MDR

UltraViolet Cyber 501-1000 Computer and Network Security

UltraViolet Cyber is seeking a Senior Security Analyst to join its 24/7 shared-services Cyber Defense team, investigating security incidents and strengthening protection for client infrastructure and data.

Cybersecurity Linux Network Security
22 hours, 1 minute ago

Security GRC Specialist

SAP Fioneer 1K-5K Internet Software & Services

SAP Fioneer is seeking a Security GRC Specialist to strengthen and scale security governance, risk, and compliance practices across its financial services software products and operations.

1 day, 22 hours ago

CyberSecurity Analyst

Avertium 251-1K IT Services

Avertium is seeking a Cybersecurity Analyst to support clients through proactive security monitoring, incident response, security administration, and alignment of business and IT security objectives.

Active Directory Cybersecurity HIPAA Juniper Linux Network Security Penetration Testing SQL Unix Windows Server
2 days, 22 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers