Job Requirements
Los Angeles, CA
Top Secret/SCI Polygraph not specified
Mid Level Career (5+ yrs experience)
$160,000 - $200,000
Job Description
The Cybersecurity Lead role at Apex is a critical leadership role responsible for overseeing the daily operations of the Security Operations Center (SOC), ensuring proactive threat detection, incident response, and team performance. This position requires a blend of technical expertise, strategic oversight, and strong leadership skills to safeguard the organization's information assets against cyber threats. The SOC Lead reports to the Director of IT & Cybersecurity and collaborates with IT and compliance to align security operations with business objectives.
Key Responsibilities
• Team Leadership and Development: Manage a team of SOC analyst(s) & engineer(s), including hiring, training, performance evaluations, and professional development to build a high-performing security operations unit.
• Incident Detection and Response: Oversee monitoring of security events using SIEM tools and other technologies; coordinate incident response efforts, including triage, escalation, containment, eradication, and post-incident analysis to minimize impact and ensure rapid resolution.
• Threat Intelligence and Hunting: Conduct proactive threat hunting, malware analysis, and deep-dive investigations into escalated incidents; integrate threat intelligence to enhance detection capabilities and stay ahead of emerging cyber risks.
• Process and Tool Optimization: Manage, tune, and optimize SOC tools such as SIEM (Elastic), IDS/IPS, endpoint security, and vulnerability management systems; develop and refine security policies, procedures, playbooks, and automation to improve efficiency and reduce false positives.
• Metrics and Reporting: Develop, track, and report on key performance indicators (KPIs) and metrics for SOC operations via dashboards and reports; prepare executive summaries on threats, incidents, and defensive posture to inform decision-making.
• Strategic Planning and Compliance: Contribute to SOC strategy, including resource allocation, technology evaluations, and integration of new tools; ensure compliance with security standards, conduct tabletop exercises, and collaborate on risk assessments and audits.
• Stakeholder Communication and Escalation: Serve as the primary point of escalation for complex incidents; coordinate with internal teams and external partners during active threats; foster cross-functional relationships to support organizational security goals.
• Operational Oversight: Ensure 24/7 SOC coverage, including staffing and surge support; perform hands-on analysis as needed and drive continuous improvement in processes to enhance overall cybersecurity resilience.
• Assessment & Compliance Support: Assist with achieving CMMC, ISO 27001, and other accreditations needed for the organization. Maintain the accreditations with continuous monitoring and changes.
• Assist with other duties: Assist with daily IT tickets and projects when needed.
Qualifications
• 7+ years of experience in cybersecurity operations, with at least 2-3 years in a leadership role
• TS/SCI security clearance required
• Relevant certifications such as CISSP, CISM, GIAC GCIH, or CompTIA Security+.
• Proficiency in security tools (SIEM, EDR/XDR, IDP/IDS, CASB/SASE, NESSUS, BURP SUITE, firewalls) and scripting languages (e.g., Python, PowerShell)
• Strong technical skills with a strong understanding of networking protocols and operating systems (Windows/MacOS/Linux)
• Strong analytical, problem-solving, and communication skills; proven ability to lead teams in high-pressure environments
#LI-JC1
Key Responsibilities
• Team Leadership and Development: Manage a team of SOC analyst(s) & engineer(s), including hiring, training, performance evaluations, and professional development to build a high-performing security operations unit.
• Incident Detection and Response: Oversee monitoring of security events using SIEM tools and other technologies; coordinate incident response efforts, including triage, escalation, containment, eradication, and post-incident analysis to minimize impact and ensure rapid resolution.
• Threat Intelligence and Hunting: Conduct proactive threat hunting, malware analysis, and deep-dive investigations into escalated incidents; integrate threat intelligence to enhance detection capabilities and stay ahead of emerging cyber risks.
• Process and Tool Optimization: Manage, tune, and optimize SOC tools such as SIEM (Elastic), IDS/IPS, endpoint security, and vulnerability management systems; develop and refine security policies, procedures, playbooks, and automation to improve efficiency and reduce false positives.
• Metrics and Reporting: Develop, track, and report on key performance indicators (KPIs) and metrics for SOC operations via dashboards and reports; prepare executive summaries on threats, incidents, and defensive posture to inform decision-making.
• Strategic Planning and Compliance: Contribute to SOC strategy, including resource allocation, technology evaluations, and integration of new tools; ensure compliance with security standards, conduct tabletop exercises, and collaborate on risk assessments and audits.
• Stakeholder Communication and Escalation: Serve as the primary point of escalation for complex incidents; coordinate with internal teams and external partners during active threats; foster cross-functional relationships to support organizational security goals.
• Operational Oversight: Ensure 24/7 SOC coverage, including staffing and surge support; perform hands-on analysis as needed and drive continuous improvement in processes to enhance overall cybersecurity resilience.
• Assessment & Compliance Support: Assist with achieving CMMC, ISO 27001, and other accreditations needed for the organization. Maintain the accreditations with continuous monitoring and changes.
• Assist with other duties: Assist with daily IT tickets and projects when needed.
Qualifications
• 7+ years of experience in cybersecurity operations, with at least 2-3 years in a leadership role
• TS/SCI security clearance required
• Relevant certifications such as CISSP, CISM, GIAC GCIH, or CompTIA Security+.
• Proficiency in security tools (SIEM, EDR/XDR, IDP/IDS, CASB/SASE, NESSUS, BURP SUITE, firewalls) and scripting languages (e.g., Python, PowerShell)
• Strong technical skills with a strong understanding of networking protocols and operating systems (Windows/MacOS/Linux)
• Strong analytical, problem-solving, and communication skills; proven ability to lead teams in high-pressure environments
#LI-JC1
group id: 91136884