Staff Cyber Defense Engineer (SOC Lead) – Automation & AI
CME GroupMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessLog in to see why each signal reads the way it does.
Job Description
Structured overview of role & requirementsAbout This Role
Lead the transition toward an AI-driven Security Operations Center (SOC) by architecting and governing complex automation scripts and automated playbooks.
Direct daily SOC engineering and analyst teams, define the automation roadmap, enforce coding and CI/CD standards (Python/REST API), and optimize SOC workflows to reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Serve as Incident Commander during major breaches, manage threat hunting programs, and integrate LLMs and machine learning into cyber defense strategies and core security stack (SIEM, EDR, etc.) health.
Minimum Requirements
7+ years progressive SOC, Incident Response, or Security Engineering experience with 2+ years in supervisory or technical team lead roles.
BA/BS degree in Engineering, Computer Science, Information Security, or equivalent experience; advanced security/engineering certifications (e.g., GSE, GCIA, CISSP, AWS Security/ML).
Expert knowledge of adversary tactics (MITRE ATT&CK), network architecture, forensic analysis, and hands-on incident response experience.
Strong familiarity with enterprise SOAR platforms (e.g., Cortex XSOAR, Splunk SOAR) and experience managing automation pipelines and CI/CD practices.
Ideal Candidate Profile
Experienced leader with hands-on engineering and coding skills in Python, REST APIs, and Detection as Code for SOC automation and AI integration.
Strategic thinker skilled in translating AI-driven security roadmaps into deployable and scalable autonomous SOC capabilities with measurable KPI ownership.
Proven ability to coordinate high-pressure incident response and integrate machine learning/LLM technologies into enterprise security environments effectively.
