Hiring.Camp

Security Operations Lead

Asmglobal

·

Yesterday

Location
Legends Global Corporate-8198, United States of America · Frisco, TX
Workplace
Hybrid
Type
Full-time
Department
Operations
Seniority
Lead
Source
Workday

Description

POSITION: Security Operations Lead  

LOCATION: Hybrid (This person can be based out of our Dallas/Frisco, TX or Conshohocken, PA Corporate Headquarters)

DEPARTMENT: Technology

REPORTS TO: VP, Cyber Security

LEGENDS GLOBAL

Legends Global is the premier partner to the world’s greatest live events, venues, and brands. We deliver a fully integrated suite of premium services through a white-label model that keeps our partners front and center — from feasibility and project development to sales, partnerships, hospitality, merchandise, venue management, and world-class content and booking.

With a global network of more than 450 venues, hosting 20,000 events and welcoming 165 million guests annually, Legends Global brings unmatched scale, expertise, and connectivity to help our partners grow. The Legends Global Way guides how we operate: Align, Scale, Connect, Team, Win — shared success, repeatable systems, connected solutions, unstoppable teams, and wins that are earned every day.

Security Operations Lead

The Security Operations Lead is responsible for detection, triage, and response operations across our enterprise. This role blends hands-on incident handling with detection engineering, playbook development, and response automation efforts. This role delivers on alerts and case management, drives resilient detection strategies, and leads hunt efforts that proactively surface threats before they become incidents.

Joining a team of SOC Analysts, the Security Operations Lead sets the standard on how to identify, triage, and resolve cybersecurity incidents, and demonstrates this to the SOC team. This role is a great opportunity for a seasoned analyst to lead by example on how a global Security Operations Center should run.

Key Responsibilities

  • Independently lead complex or high-impact security incidents and identify opportunities to improve SOC processes, tools, and response capabilities.
  • Provide technical guidance and mentorship to SOC Analysts, sharing best practices and establishing standards for documentation, communication, and delivery.  Build and operationalize SOC playbooks and escalation workflows.
  • Lead alert triage, enrichment, prioritization, and false-positive suppression.
  • Author detection requirements and write and tune SIEM rules.
  • Develop threat-hunting hypotheses and lead hunt efforts using advanced telemetry and threat intelligence.
  • Design detection strategies across the kill chain and help advance the enterprise detection strategy.
  • Execute complex incidents end-to-end, including containment, eradication, documentation, and communication.
  • Conduct post-incident reviews and drive remediation and control improvements.
  • Promote industry collaboration and embed resilient detection engineering practices.
  • Advocate for and implement automation-first incident response.
  • Provide technical guidance and mentorship to SOC Analysts, sharing best practices and setting standards for documentation, communication, and delivery.

Education and Experience

  • Proven experience in a SOC or equivalent detection and response function, with a focus on high-fidelity detections, repeatable playbooks, and measurable outcomes.
  • Three to five years of experience in Security Operations, Detection and Response, or Incident Handling; SOC experience is required.
  • Hands-on experience with SIEM platforms, such as Google Security Operations, Microsoft Sentinel, or IBM QRadar; EDR platforms, such as CrowdStrike, Microsoft Defender, or SentinelOne; and SOAR platforms.
  • Proficiency in authoring detections, tuning rules, developing enrichment pipelines, and improving alert routing.
  • Demonstrated experience building and executing incident-response playbooks and containment and eradication plans.
  • Experience conducting post-incident reviews and root-cause analyses and delivering corrective action plans to engineering teams.
  • Scripting skills in Python, PowerShell, or Bash for automation, enrichment, and data analysis.
  • Excellent written communication skills, including case documentation and executive-ready incident summaries
  • Proficient in authoring detections, rule tuning, enrichment pipelines, and alert routing.
  • Demonstrated capability in building and executing IR playbooks and containment/eradication plans.
  • Experience conducting post-incident reviews and RCAs, and delivering corrective action plans to engineering teams.
  • Scripting skills (Python/PowerShell/Bash) for automation, enrichment, and data wrangling.
  • Excellent written communication for case documentation and executive-ready incident summaries.

Desired Skills and Abilities

  • Demonstrates the ability to influence technical direction and cross-functional outcomes through expertise and sound judgment, without formal people-management responsibility.
  • Transforms noisy telemetry into actionable signals.
  • Is detail-oriented and disciplined in organizing information, developing repeatable playbooks, maintaining clear documentation, and closing feedback loops.
  • Is prepared to mentor other analysts and set standards for SOC communication and delivery.
  • Influences technical direction and cross-functional outcomes through expertise and sound judgment.
  • Is comfortable presenting complex technical information to the CISO and other executive leaders.

COMPENSATION

Competitive salary, commensurate with experience, and a generous benefits package that includes medical, dental, vision, life and disability insurance, paid vacation, and 401k plan.

WORKING CONDITIONS

Location: Hybrid (This person can be based out of our Dallas/Frisco, TX or Conshohocken, PA Corporate Headquarters)

NOTE:

The essential responsibilities of this position are described under the headings above. They may be subject to change at any time due to reasonable accommodation or other reasons. Also, this document in no way states or implies that these are the only duties to be performed by the employee occupying this position.

Legends Global is an Equal Opportunity/Affirmative Action employer, and encourages Women, Minorities, Individuals with Disabilities, and protected Veterans to apply. VEVRAA Federal Contractor.

Skills

PythonCybersecuritySIEMSOC

Similar Jobs

30

Security Operations Lead

Lendable · London · Hybrid

1 month ago

Security Operations Lead

Nttlimited · Canberra, Australia · Hybrid

2 months ago

Security Operations Lead

Accenturefederalservices · Washington, DC +1 · Hybrid

4 months ago

Security Operations Lead

AIS Careers · Client Site - Alexandria, VA, United States of America · Hybrid

7 months ago

Security Operations Lead

Replit · Hybrid, Onsite

1+ year ago

Sr Sales Operations Lead, Security Specialists, NAMER Specialist Operations

Amazon

6 days ago

IT Operations & Security Lead

Phoenix Data Corporation · Indianapolis, IN

3 weeks ago

VP, Security Operations Lead

Jefferies · Jersey City, NJ, United States, US

3 weeks ago

Lead Security Operations Center (SOC) Analyst

Livenation · Work From Home - Nevada, United States of America · Remote

1 month ago

Security Operations Lead (GSOC)

Swbc · SWBC Headquarters, United States of America

1 month ago

Corporate Security Operations Lead, VP

Db · Mumbai Nirlon Knowledge Pk B1, India

2 months ago

Security Operations Lead (SecOps)

Sword Health · Porto · Remote

3 months ago

Information Security Operations Lead

Brooksauto · Malaysia - Johor +1 · Onsite

4 months ago

L5 Lead Security Operations Centre Specialist

Deliveroo · Hyderabad - Main Office · Hybrid

4 months ago

Information Security Operations Lead/Manager

Default · Carmel

4 months ago

Personnel Security Operations Lead Specialist - Programma GCAP

Leonardocompany · IT - Roma - Via Montello, Italy

6 months ago

Lead Operations Security Engineer

SCOR · Bucuresti - Ilfov, Romania

6 months ago

Engineering Lead, Security Operations

Anchorage Digital · United States · Remote

7 months ago

Lead Information Security Operations Specialist

TIAA started out over · Charlotte Main 8500 Carnegie Blvd, United States of America +2 · Hybrid

Yesterday

Security Operations & SIEM Lead (SOC)

Professional Kyndryl · Noida India (INNOIGAL) WeWork Galaxy SO

3 days ago

Lead, Cyber Security Operations

Pru · Wash, 213 Washington St., Newark, NJ, United States of America

2 weeks ago

Lead Information Security Operations Analyst

Mastercard · London, England (Angel Lane), United Kingdom

2 weeks ago

Security Operations Team Lead

Aggreko · Sentinel Building, Glasgow, United Kingdom · Remote, Hybrid

3 weeks ago

Security Operations Center Lead

Altera · Penang 15, Penang, Malaysia +1

3 weeks ago

Envista Security Operations & Engineering Lead (Brea, CA)

Envista Careers · USA - Brea - Multiple OpCo, United States of America

1 month ago

Lead, AI Security Operations Engineer

Mastercard · Mexico City, Mexico

1 month ago

Lead, AI Security Operations Engineer

Mastercard · Mexico City, Mexico

1 month ago

Security Operations Center Lead

Fgcu · Main Campus, United States of America

2 months ago

Third Party Security Risk Operations Lead

Gsknch · Bengaluru Campus 31, India

2 months ago

SOC Lead - Cyber Security Operations - VOIS

Vodafone · Bengaluru, KA,IN, IN

3 months ago