Modern Data Workspace ✨ | A Leader in The Forrester Wave™️ | Follow for resources, blogs, and more from the data world.
SOC Lead - Detection & Response
Location
Worldwide
Posted
18 days ago
Salary
0
Seniority
Lead
Job Description
SOC Lead - Detection & Response
Atlan
Role Description We're looking for a SOC Lead who will own Atlan's security operations end-to-end. You lead the function, not a team. You own detection and response outcomes, manage our external SOC vendor, and build the AI-native operations layer that defines what security ops looks like at Atlan. You'll report to the Senior Security Manager and work across Application Security, Platform Security, GRC, and Corporate Security. We expect this person to contribute beyond SOC — whether that's supporting compliance audits, or security automation. What You'll Do - Own SOC operations - Manage the managed SOC vendor - Build detection and response capability - Build and operate AI agents for SOC - Lead incident response - Drive automation - Build toward in-house SOC - Contribute across security domains - Report to leadership Qualifications - 6+ years in security operations, with demonstrated experience building or leading core SOC functions, particularly across detection engineering and incident response. - Hands-on experience with SIEM platforms — alert triage, detection rule development, correlation logic (Splunk preferred) - Experience managing or working closely with a managed SOC or MDR vendor - Strong incident response fundamentals — you've run incidents, written post-mortems, and improved controls as a result - Comfortable with cloud-native environments (AWS/GCP/Azure) and the threat landscape specific to SaaS B2B companies - Experience with EDR platforms (SentinelOne, CrowdStrike, or similar) - Ability to write clearly — incident reports, runbooks, leadership briefings - Hands-on experience building automation — scripts, workflows, or integrations that reduced manual analyst work Requirements - Working knowledge of LLMs and how they can be applied to security operations — triage, summarization, investigation assistance - Experience building or using AI-assisted security workflows (prompt engineering, agent frameworks, or SOAR + AI integrations) - Ability to evaluate and deploy AI SOC agent tooling — you can tell the difference between a demo and something production-ready Nice to Have - Experience building or scaling an in-house SOC from scratch - Familiarity with automation tooling (n8n, Tines, Palo Alto XSOAR, or similar) - Prior work building agentic security workflows — multi-step AI pipelines that take actions, not just generate text - Working knowledge of compliance frameworks (SOC 2, ISO 27001, HIPAA) and how SOC feeds compliance evidence - Threat hunting experience - Relevant certifications: GCIA, GCIH, GCFA, or equivalent Benefits - Competitive Compensation: Strong base salary, performance-based variable pay, and impact-driven equity. - AI Native Culture: AI is woven into how we build, think, and work every day. - Health & Wellness: Comprehensive health, dental, vision, and mental health benefits. - Flexible Time Off & Leave Policies: Trust to own your energy with flexible time off and modern leave. - Accelerated Growth & Learning: Develop at an uncommon velocity through cutting-edge tech. - Global, Remote-First, High-Trust: Work from anywhere with a diverse team across 15+ countries.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
IT Security Analyst
Quad GraphicsQuad Graphics is a leading, multi-channel provider of marketing services for companies around the world. The company started as a small print shop in 1971, work
Conduct audits to evaluate IT security controls, assist in developing risk matrices, and coordinate third-party assessments while collaborating with departments to enhance compliance and mitigate organizational risks.
• Support implementation and maintenance of cybersecurity controls aligned with DoD/DoN guidelines, NIST frameworks, and organizational policies. • Contribute to the development and execution of Zero Trust security strategies. • Manage ATO compliance activities, including documentation, evidence gathering, and coordination with authorizing officials. • Perform vulnerability management, leveraging tools such as AWS Security Hub, container scanning solutions, and other enterprise security platforms. • Provide security expertise for containerized deployments and cloud environments to ensure secure architectures and operational practices. • Lead or support FISMA-related audits and compliance efforts, ensuring timely remediation of findings and continuous monitoring. • Collaborate across teams to assess risks, recommend mitigations, and drive continuous security improvements.
Security Analyst
TaxwellFounded in 2022 through the merger of Drake Software and TaxAct, Taxwell is a leading tax technology company that serves over 90,000 tax professionals and 3 mil
Role Description Serves as a consultant for Taxwell. At Taxwell, we believe our work benefits from the diverse perspectives of our employees. As such, Taxwell welcomes and celebrates diversity and inclusion and is committed to equal opportunity employment. At Taxwell, you can expect a supportive, open, and inclusive atmosphere and a team that values your contributions. Qualifications - Commitment to diversity and inclusion - Ability to work in a supportive and open atmosphere Requirements - Equal employment opportunities available to all applicants - Confidential handling of information gathered in the hiring process Benefits - Supportive and inclusive work environment Company Description Taxwell helps everyday Americans get every tax advantage they deserve by finding credits and deductions they never even knew existed. Our tax preparation software offers easy guidance and ensures your maximum tax refund. We strive to build a team of like-minded experts in both tax and technology who align with our brand purpose, are advocates for our customers and have a fresh, non-traditional approach to the tax industry.
Threat Intelligence Analyst
TRM LabsTRM Labs specializes in blockchain investigations and risk management, empowering organizations to detect, investigate, and prevent crypto-related fraud and financial crime. Founde
Role Description TRM's Blockchain Intelligence team is the world's leading source of actionable crypto crime intelligence — and scams are the fastest-growing threat category we track. As a Threat Intelligence Analyst specializing in scams, you will own TRM's intelligence production on: - Pig butchering syndicates - Romance fraud networks - Investment scam operations Your responsibilities will include: - Mapping the infrastructure behind global scam syndicates, tracing victim funds through complex laundering chains. - Producing Snap Leads, Timely Insights, and contributing to published reports reaching law enforcement agencies, financial institutions, and crypto businesses worldwide. - Using AI tools — including Claude, Perplexity, and AI-assisted OSINT workflows — as core components of your research process. - Monitoring global scam channels, forums, and social media platforms to surface proactive collection not visible through on-chain analysis alone. - Collaborating with TRM's GTM, Product, and Data teams to ensure your intelligence is embedded in the platform. Qualifications - 3+ years of experience in threat intelligence, fraud investigation, or crypto crime analysis. - Demonstrated knowledge of scam ecosystems (pig butchering, romance fraud, investment fraud, or equivalent). - Working proficiency in blockchain analysis. - A track record of producing actionable intelligence outputs. - Strong AI fluency. - Excellent written communication skills. - A self-starter mindset. Requirements - Ability to trace funds, identify clusters, and use tools like TRM Investigator or Chainalysis Reactor. - Experience writing leads, reports, or briefs that influenced operational decisions. - Proficiency in using AI tools as core parts of your research workflow. - Ability to write a BLUF-style intelligence report for immediate action. - Capability to generate your own collection priorities and pursue investigative threads independently. Benefits - High velocity and high ownership team environment. - Opportunities for rapid iteration and experimentation. - Collaboration across teams and functions. - Focus on meaningful problems and ambitious goals.



