• Architect the SOC strategy and roadmap, defining threat intelligence operations, detection frameworks, and defensive maturity metrics.
• Build and tune detection logic across cloud stacks, identity layers, and endpoints, rejecting noise to accelerate incident response velocity.
• Own incident command, leading containment and recovery operations while driving engineering change through rigorous post-mortems.
• Govern the defensive stack—SIEM, EDR, and automated playbooks—ensuring engineering delivers lean, high-fidelity operations at scale.
• Establish proactive threat hunting programs, synthesizing external intelligence to intercept emerging threats before they reach mission-critical systems.
• Synchronize security controls with engineering and product squads, embedding rigorous automated defenses into platform architecture.
• Mentor and scale a high-performing security operations squad, anchoring a culture built on accountability and technical craft.
• Optimize vendor and MDR relationships, ensuring third-party partnerships deliver the technical execution the mission demands.