Cybersecurity Operations & Incident Response Lead

Coastal

Completely RemoteFull TimeInformation Technology
Posted 4 days ago

Job description

Responsibilities

  • Own SIEM/SOAR strategy and daily operations, including log onboarding and detection engineering
  • Serve as incident response commander for high-severity incidents and coordinate cross-functional responders
  • Manage the vulnerability management lifecycle across servers, endpoints, cloud, and APIs
  • Oversee third-party SOC/MSSP providers to ensure quality, SLAs, and continuous tuning
  • Align SecOps processes to FFIEC/GLBA expectations and industry frameworks like NIST CSF
  • Develop and report on KPIs and KRIs for the Security and Threat Operations function

Requirements

  • 8+ years in Security Operations, Incident Response, Detection Engineering, or Threat Hunting
  • 3+ years of team lead experience
  • Hands-on expertise with SIEM/SOAR, EDR, and detection content development
  • Proven experience as an incident commander for high-impact events
  • Experience operating in hybrid environments (Azure, Okta, M365, Zscaler, etc.)
  • Familiarity with MITRE ATT&CK and threat-led validation
  • Proficiency with scripting or automation tools like Python or TypeScript
  • Bachelor's degree in Information Security, Computer Science, or equivalent practical experience

Preferred Qualifications

  • Prior experience in a regulated environment such as finance or healthcare

Benefits

  • Competitive medical plans and HSA options
  • Dental and vision insurance
  • Life, disability, and supplemental insurance
  • 401(k) retirement plan with company matching
  • Generous paid time off and 11 paid holidays

About the Company

Coastal is at the forefront of modern banking, combining strong financial infrastructure with cutting-edge Banking-as-a-Service (BaaS) and fintech enablement strategies.

Skills & tools

SIEMincident responsePython

What the team is looking for

Use this list as a quick fit check before you apply.

  1. 018+ years in Security Operations
  2. 023+ years team lead experience
  3. 03SIEM/SOAR expertise
  4. 04Incident command experience
  5. 05Hybrid environment experience
  6. 06Scripting skills (Python/TypeScript)
NeverApplyAd

Wake up to a shortlist, not a search results page.

NeverApply scores every new listing against your CV, salary floor and visa. A handful of real matches by morning.

Get your daily matches