SonicJobs Logo
Left arrow iconBack to search

Lead, Cybersecurity Engineer Operations

RBGlobal
Posted a month ago, valid for 23 days
Location

Westchester, IL 60154, US

Salary

$123,950 - $154,880 per year

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • We are looking for a Lead, Cybersecurity Operations to enhance our global CSOC capabilities as a senior technical leader.
  • The ideal candidate should have 5-8+ years of experience in cybersecurity operations or SOC environments and relevant certifications such as Security+, GCIH, or GCIA.
  • This role involves overseeing threat detection, incident response, and operational excellence, acting as the primary technical escalation point for analysts.
  • The position offers a competitive salary and benefits, including medical, dental, vision insurance, a 401k plan with matching, and 15 days of PTO annually.
  • The candidate must possess a strong technical background and a passion for improving cybersecurity capabilities in a dynamic threat landscape.

About the Role: 

We are seeking a Lead, Cybersecurity Operations to play a critical role in advancing our global Cybersecurity Operations (CSOC) capabilities. 

This individual will serve as a senior technical leader responsible for overseeing threat detection, incident response, and continuous improvement of security operations across the organization. As part of the Cybersecurity Operations Team, the Lead will drive operational excellence by enhancing detection strategies, improving incident response processes, and ensuring effective use of security technologies. This role acts as the primary technical escalation point for analysts and a key liaison between leadership and the SOC team—translating strategic direction into actionable work and ensuring meaningful outcomes.

This position requires a hands-on leader with deep technical expertise, strong operational awareness, and a passion for elevating both team performance and cybersecurity capabilities in a fast-paced, evolving threat landscape.

Responsibilities: 

  • Lead Cybersecurity Operations Execution & Quality
    Oversee day-to-day security monitoring, detection, and response activities, ensuring high-quality investigations and timely remediation of security events and incidents.
  • Serve as Primary Technical Escalation Point
    Act as the go-to escalation resource for analysts, providing hands-on guidance for complex investigations and ensuring consistency and depth in investigative outcomes.
  • Own Incident Response Lifecycle & Stakeholder Coordination
    Lead and coordinate complex security incidents end-to-end, while acting as a liaison between leadership and the SOC—translating strategic direction into actionable tasks and delivering clear, meaningful updates.
  • Drive Detection & Response Maturity (SIEM & Tooling)
    Lead SIEM-driven operations and continuously improve detection capabilities through use-case development, tuning, telemetry optimization, and enhanced coverage across security domains.
  • Coordinate SME Programs & Operational Initiatives
    Break down strategic cybersecurity objectives into actionable workstreams, track progress, remove blockers, and ensure successful execution of team initiatives.
  • Develop & Optimize Playbooks, Processes, and Automation
    Create and refine incident response playbooks, SOPs, and automation opportunities to improve consistency, efficiency, and scalability of operations.
  • Leverage Metrics & Threat Insights to Drive Improvement
    Track key operational metrics (MTTD, MTTR, alert fidelity) and conduct advanced threat analysis to inform decisions, strengthen defenses, and continuously improve security posture.

Requirements: 

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent practical experience).
  • Security+, GCIH, GCIA, GCED, or equivalent certifications.
  • 5–8+ years of experience in cybersecurity operations or SOC environments 
  • Proven experience leading or coordinating incident response activities 
  • Hands-on experience with SIEM platforms and building detection-driven operations 
  • Strong familiarity with security technologies such as EDR, NDR, email security, WAF, and identity/security monitoring tools

RB Global (NYSE: RBA)


RB Global (NYSE: RBA) (TSX: RBA) is a leading, omnichannel marketplace that provides value-added insights, services and transaction solutions for buyers and sellers of commercial assets and vehicles worldwide. Through its auction sites in 13 countries and digital platform, RB Global serves customers in more than 170 countries across a variety of asset classes, including automotive, commercial transportation, construction, government surplus, lifting and material handling, energy, mining and agriculture.


The company’s marketplace brands include Ritchie Bros., the world’s largest auctioneer of commercial assets and vehicles offering online bidding, and IAA, a leading global digital marketplace connecting vehicle buyers and sellers. RB Global’s portfolio of brands also includes Rouse Services, which provides a complete end-to-end asset management, data-driven intelligence and performance benchmarking system; SmartEquip, an innovative technology platform that supports customers’ management of the equipment lifecycle and integrates parts procurement with both OEMs and dealers; Xcira, a leader in live simulcast auction technologies; and Veritread, an online marketplace for heavy haul transport.


RB Global full-time employees are offered medical, dental, vision, and basic life insurances. Employees are able to enroll in our company’s 401k plan and RB Global will match 100% for the first 4% contributed.  Employees will also receive 15 days of PTO each year.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.