About the Role
As the Cyber Security Operations Team Lead, you will provide leadership and technical expertise to a team of cyber threat analysts and engineers. You will act as a critical point of contact for managing and responding to security events, ensuring compliance with service level agreements (SLAs), and continuously improving security processes. Your leadership will be instrumental in achieving customer satisfaction and the overall success of our managed services. In addition to mentoring and leading your team, you will play a key role in developing new service offerings and integrating new technologies into our services portfolio.
Responsibilities
- Lead and mentor a team of cyber threat analysts and engineers, providing guidance and technical expertise to ensure efficient threat detection and response.
- Act as both a team and thought leader to junior threat team members within the region and interact with peer leads and management across regions.
- Utilize strong operating system, TCP/IP networking, and application skills to analyze and understand detected threats.
- Analyze and respond to security events from various sources, including firewalls, EDR, IDS, IPS, SIEM (Qradar, Splunk, ArcSight, LogRhythm), Web Application Firewall (WAF), and other security data sources, within documented SLAs.
- Tune security devices for proactive blocking and detection based on customer business requirements.
- Configure, manage, and upgrade protection policies for Intrusion Detection Systems (IDS), Intrusion Protection Systems (IPS), Security Information and Event Monitoring (SIEM) platforms, and Endpoint Detection & Response Platforms.
- Create, enhance, and document processes for the management and monitoring of security solutions.
- Demonstrate leadership in all aspects of customer service, responding to customer needs and inquiries in a polite, positive, and professional manner.
- Act as a mentor and escalation point for analysts and engineers within GTO, developing training plans to elevate their performance.
- Lead projects to develop new service offerings and integrate new technology into our services portfolio.
- Collaborate with internal engineering teams to facilitate the implementation of new features and functions.
- Collect and report on data trending across multiple products and customers, providing input and guidance on new product development.
- Understand the broader security and threat landscape, concerns, and motivations.
- Collaborate with management on process enhancement, documentation, and definition for threat analysis and classification.
- Foster a culture of growth and development within the teams, actively recognizing and rewarding team members for exceptional contributions.
- Be available to provide oversight or work any shift within your direct reports' 24/7/365 operations, including nights, weekends, and holidays.
Requirements
- 7 or more years of information security or networking experience.
- Previous operational experience as an analyst, engineer, or team lead.
- Excellent customer service skills.
- Strong analytical thinking and problem-solving skills.
- Strong oral and written communication skills.
- Self-managed and team-oriented, with the ability to coach and teach.
- Responsive, collaborative, and highly motivated.
- Leadership and management experience.
- A high school diploma or equivalent is required.
Skills
- Project and Queue Management
- SOC Operations/Management
- Endpoint Detection & Response
- Security Information and Event Management (SIEM)
- Unix/Linux and Windows system administration
- Information security best practices and network security architecture
- Signature-based security products
- Current exploit and remediation techniques
- TCP/IP networking
- Vulnerability Scanning technologies
- Log collection and analysis tools
- Threat Intelligence
- Incident Response/Forensics
- English: Demonstrated Fluency
Location
- Australia
Work Type
- Flexible work
- In-person for key moments
Experience Level
- 7 or more years of information security or networking experience
- At least 7 years of experience in Information Security or Networking
Education Level
- Bachelor's/Master's Degree in Information Technology or a similar area of study
- Certification in a security-related industry, vendor, or professional certification
- A college or university degree is a plus
About the Company
- LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence.
- As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity.
- LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services.
Equal Opportunity
- LevelBlue is committed to a culture of respect, inclusion, and equal opportunity.
- All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other status protected under applicable law.
