Quick Summary
At StoneX, our Security Operations Center is more than a place where alerts are monitored—it’s where people, technology, intelligence, and increasingly AI come together to protect the business.
3+ years of Security Operations Center or incident response experience, with demonstrated leadership, mentoring, or people management experience. Strong experience triaging security alerts,
Responsibilities
~2 min read- →
Operational Leadership: Lead Security Operations Center activities, ensuring monitoring, triage, investigation, escalation, and response processes are consistent, measurable, and aligned with established procedures and service expectations.
- →
AI & Agentic Security Operations: Help shape, build, and operationalize StoneX’s agentic Security Operations platform, partnering with AI engineers and security teams to apply AI and automation across triage, investigation, enrichment, orchestration, and analyst decision support. Ensure capabilities deliver measurable operational value while maintaining appropriate human oversight, governance, and accountability.
- →
People & Culture: Build a healthy, accountable, and sustainable team environment where analysts can perform at a high level without burnout becoming an accepted cost of operating a security function.
- →
Developing People: Coach and develop analysts, providing regular feedback, clear expectations, growth opportunities, and support that strengthens technical capability, judgment, and confidence.
- →
Incident Coordination: Manage escalations and coordinate response activities during priority cybersecurity events, ensuring the right teams and stakeholders are engaged when needed.
- →
Operational Continuity: Ensure effective documentation, communication, and handoffs across regions and time zones so important context and accountability aren’t lost between teams.
- →
Investigation Quality: Drive consistency and quality across investigations, documentation, and reporting through coaching, review, and clearly defined expectations.
- →
Partnership: Work closely with Threat Intelligence and Engineering teams to validate alerts, test detection use cases, improve processes, and strengthen overall detection and response capabilities.
- →
Continuous Improvement: Use operational metrics, team feedback, AI, and automation to improve alert quality, reduce unnecessary noise and repetitive work, strengthen processes, and continuously improve both security outcomes and the analyst experience.
Spending at least four days in the office engaging directly with analysts, security partners, and other stakeholders.
Meeting with analysts to review investigations, operational priorities, challenges, workload, and development opportunities.
Reviewing escalations and priority incidents while helping the team make sound decisions and coordinate response activities.
Coaching analysts through complex investigations and helping strengthen their technical judgment, documentation, and decision-making.
Reviewing operational handoffs and documentation to ensure continuity across regions and time zones.
Partnering with Threat Intelligence and Engineering teams to validate detections, investigate recurring issues, and identify opportunities to improve alert quality.
Partnering with AI engineers, Detection Engineering, and other security teams to identify, test, and operationalize agentic workflows that reduce manual effort, accelerate investigations, and improve analyst decision-making.
Reviewing alert volumes, workloads, operational trends, and team feedback to identify sources of unnecessary friction or fatigue and opportunities where AI, automation, or process improvements can make the team more effective.
Contributing to Security Operations Center reporting, metrics, and continuous improvement initiatives.
Participating in an on-call rotation and providing after-hours leadership support during major cybersecurity incidents or significant operational events.
Occasionally traveling for team meetings, leadership gatherings, or other business needs.
You’re people-centered – you understand that protecting the business starts with taking care of the people doing the work, and you pay attention to workload, operational pressure, alert fatigue, development, and team wellbeing.
You’re culture-driven – you want to build a team where people feel supported, accountable, comfortable raising concerns, and excited to continue developing their careers.
You’re calm under pressure – when an investigation or incident becomes challenging, people look to you for clarity, direction, and steady leadership.
You’re a coach – you enjoy helping analysts strengthen their technical skills, judgment, confidence, and ability to operate independently.
You’re operationally minded – you value consistency, strong processes, clear handoffs, measurable outcomes, and disciplined execution.
You’re collaborative – you know effective cyber defence depends on strong partnerships between Security Operations, Threat Intelligence, Engineering, and other technology teams, and you’re comfortable working with diverse teams and perspectives across the globe.
You’re excited about what’s next – you want to be at the forefront of how AI and agentic technologies are changing security operations, and you’re energized by turning emerging technology into practical capabilities that make analysts and defenders more effective.
You’re comfortable making decisions – you can assess the information available, make sound decisions quickly, and adjust as circumstances change.
You’re improvement-focused – you challenge unnecessary noise, repetitive work, and inefficient processes rather than accepting burnout and constant firefighting as simply part of security operations.
Requirements
~1 min read3+ years of Security Operations Center or incident response experience, with demonstrated leadership, mentoring, or people management experience.
Strong experience triaging security alerts, investigating incidents, and interpreting detection content.
Strong communication skills with the ability to coach others, lead during high-pressure situations, and document investigations clearly.
Experience monitoring and investigating threats across cloud and on-premises environments.
Familiarity with scripting or security query languages such as SPL, KQL, or similar technologies.
Ability to make sound decisions quickly, manage shifting priorities, and positively influence team performance during critical situations.
Experience with MITRE ATT&CK, threat hunting, or detection engineering concepts and practices.
Experience with security orchestration, automation, and response platforms.
Familiarity with metrics-driven Security Operations Center management and continuous improvement practices.
Experience applying AI, automation, or emerging technologies to security operations, including areas such as alert triage, investigation, enrichment, analyst decision support, or workflow orchestration.
Familiarity with agentic AI concepts, responsible AI practices, and the opportunities and risks associated with introducing autonomous or semi-autonomous capabilities into security operations.
Formal leadership training or experience managing geographically distributed teams.
Associate’s or bachelor’s degree in Cybersecurity, Information Technology, or a related field. Equivalent professional experience and non-traditional paths are welcomed.
Certifications such as GCIH, GCIA, SC-200, or similar practitioner-level credentials.
- 4 days in office per week
Hiring Salary Range $150,000 - $180,000. Salary to be determined by the education, experience, knowledge, skills and abilities of the applicant, internal equity and alignment with market data.) Subject to business performance and recommendations of management, this role may be eligible to participate in an incentive compensation plan. This compensation package, in addition to a full range of medical, financial, and/or other benefits, dependent on the position, is offered.
Location & Eligibility
Listing Details
- Posted
- September 25, 2024
- First seen
- September 25, 2026
- Last seen
- September 26, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 11%
- Scored at
- September 26, 2026
Signal breakdown
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.