Cybersecurity Operations – Incident Response Lead

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $141.5k - $169.8k / year

⏰ Full Time

🟠 Senior

🛡️ Security Operations

🦅 H1B Visa Sponsor

info
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Coastal

Coastal

201 - 500 employees

🏦 Banking

💳 Fintech

🤝 B2B

Banking • Fintech • B2B

Coastal is a community bank (Coastal Community Bank) serving the North Puget Sound region that provides personal and business banking products and services. It operates local branches and ATMs while offering checking and savings accounts, home and business loans, treasury management, credit card processing, and online/mobile banking features (including mobile deposit, Zelle, and a mobile app). Coastal also supports embedded finance and fintech partnerships through technology offerings like ZSuite and a CCBX division, emphasizes fraud/security, compliance, and FDIC-insured deposit services (including IntraFi), and markets both consumer and B2B financial solutions.

📋 Description

• Own SIEM/SOAR strategy and daily operations; drive log onboarding, normalization, and high-fidelity detections across the entire technology landscape, including but not limited to: Core technology infrastructure: Active Directory Domain Services, Entra ID, Okta, Azure control plane, Zscaler, Windows and macOS endpoints, hybrid network, Productivity/G&A systems: M365, SaaS, Business-specific systems: Azure IaaS/PaaS services, custom-developed API services, banking core, financial ledger and reporting systems. • Coordinate with Engineering and IT to build detection engineering into system development lifecycle. • Develop, test, and maintain detection content (e.g., KQL/Sigma), alert routing, and enrichment pipelines that reduce noise and increase true-positive rates. • Integrate threat intelligence (strategic, operational, and technical) into detections and response workflows. • Serve as incident response commander for high-severity incidents; coordinate cross-functional responders in Infrastructure, IT, Engineering, Legal, and Compliance. • Build, maintain, and continuously improve standard operating procedures (SOPs), runbooks, and playbooks. • Maintain and exercise incident response plans through tabletop and similar activities. • Mature evidence handling, forensics workflows, and case management; ensure accurate timelines and regulator-ready documentation. • Drive post-incident reviews with measurable corrective actions (people/process/technology) and executive readouts. • Own the vulnerability management lifecycle, ensuring coverage of vulnerability discovery, triage, and management across servers, endpoints, network, cloud subscriptions, containers/images, and custom APIs. • Prioritize remediation using risk-based scoring and exploit intelligence. • Track configuration and identity hygiene (e.g., privileged accounts, conditional access, MFA coverage, device compliance) and partner with owners to close gaps. • Building and maturing a threat hunting and purple team function as part of the overall Security & Threat Operations maturation roadmap. • Lead day-to-day oversight of the third-party SOC: queue hygiene, case quality, SLAs, runbook adherence, and continuous tuning to our environment. • Ensure vendor tooling integrations, data retention, and access are compliant with Coastal policies and regulatory expectations. • Establish operating rhythms (standups, metrics reviews, post-incident retrospectives) and standard operating procedures for response, containment, eradication, and recovery. • Build and maintain a Security and Threat Operations strategy in coordination with the Director of Security Engineering and Operations, CISO, and other stakeholders, including software engineering, data engineering, and IT. • Develop and report on KPIs and KRIs for the Security and Threat Operations function. • Align SecOps processes to FFIEC/GLBA expectations and industry frameworks (NIST CSF and Cyber Risk Institute Profile). • Prepare evidence for audits/exams; provide clear, actionable metrics and board-level reporting on SOC performance, incident trends, control coverage, and risk reduction. • Partner with Legal, Compliance, Privacy, and Third-Party Risk on obligations and notifications. • Coach analysts on analytical rigor, bias reduction, and structured investigations. • Promote a blameless, learning-oriented culture that prizes speed, accuracy, and craftsmanship.

🎯 Requirements

• Demonstrated success operating in hybrid environments spanning on-prem AD, Entra ID (Azure AD), Okta, Azure, Microsoft 365, Zscaler, and containerized workloads/APIs. • Hands-on expertise with SIEM/SOAR, EDR, log pipelines, and detection content development including tuning and QA. • Proven incident commander for high-impact events; adept with forensics, scoping, containment, and executive communication. • Strong vulnerability management leadership across technology areas, including risk-based prioritization and remediation orchestration. • Familiarity with MITRE ATT&CK, cyber kill chain, and threat-led validation (purple teaming). • Experience managing outsourced SOC/MSSP providers with measurable improvements to signal quality and response times. • Excellent communication skills—able to translate technical risks into business terms and influence across stakeholders. • Familiarity with scripting or automation tools (e.g., Python, TypeScript) to streamline operations processes. • 8+ years in Security Operations, Incident Response, Detection Engineering, or Threat Hunting. • 3+ years team lead experience. • Bachelor’s degree in Information Security, Computer Science, or related field, or equivalent practical experience. • Prior experience in a regulated environment (finance, healthcare, etc.) is strongly preferred.

🏖️ Benefits

• Medical Coverage: Choose from three competitive medical plans to find the coverage that best fits your needs and lifestyle. • Health Savings Account (HSA): Available with eligible medical plans, offering tax advantages and employer contributions. • Flexible Spending Accounts (FSA): Options for healthcare and dependent care expenses to help you save on out-of-pocket costs. • Dental and Vision Insurance: Plans to keep you and your family smiling and seeing clearly. • Life Insurance: Company-paid basic life insurance with options to purchase additional coverage for yourself and your dependents. • Long-Term /Short-Term Disability (LTD): Income protection in the event of a long-term illness or injury. • Supplemental Benefits: Including Hospital Indemnity, Accident Insurance, and Critical Illness coverage to provide extra financial support when you need it most. • 401(k) Retirement Plan: A competitive retirement savings plan with company matching to help you plan for the future. • Paid Time Off: Generous vacation and sick leave policies to support your time away from work. • Holidays: Enjoy 11 paid holidays throughout the year.

Apply Now

Similar Jobs

🔥 18 hours ago

Nielsen

10,000+ employees

📱 Media

Cyber Security Analyst investigating and responding to threats while enhancing overall security capabilities at Nielsen. Collaborating with teams to manage incidents and uphold privacy and security of data.

🕒 2 days ago

Fastly

501 - 1000

🔒 Cybersecurity

☁️ SaaS

📡 Telecommunications

CSOC Engineer focused on threat detection and customer support at Fastly, enhancing security solutions for a scalable edge cloud platform. Collaborate globally to mitigate internet-scale threats and improve product capabilities.

🕒 3 days ago

NuHarbor Security

51 - 200

🔒 Cybersecurity

Senior Security Operations Analyst at NuHarbor Security responsible for security investigations and mentorship of junior analysts while ensuring high-quality client documentation.

🕒 3 days ago

RapDev

51 - 200

🤝 B2B

🏢 Enterprise

🔒 Cybersecurity

Senior Security Operations Center Analyst monitoring security events and threats with Datadog. Provide incident response and support for cloud security solutions in a fast-paced environment.

🕒 6 days ago

IDEX Corporation

5001 - 10000

🔬 Science

⚕️ Healthcare Insurance

🚗 Transport

Senior Manager overseeing cybersecurity incident response and security operations at IDEX. Leading enterprise-wide incident detection and response capabilities with a focus on high-impact incidents.