Job Description
Manage insider and external threat incident analysis and triage from initial indicators through scoping, forensic review, evidence preservation, case disposition, and root-cause analysis, producing defensible investigative narratives for executive, legal, and compliance review. Drive changes to systems and processes based on incident and risk learnings that cross and impact other teams. Define and drive the requirements, architecture, operating model, and prioritized engineering backlog for an AI-enabled QSIT SOC, covering signal enrichment, triage, investigation, response recommendations, analyst-in-the-loop controls, auditability, and sensitive-data handling. Translate AI SOC needs into measurable capabilities and acceptance criteria, evaluate first- and third-party solutions, guide implementation, and assess operational effectiveness, risk, and readiness for production use. Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response Doctorate in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience. CISSP CISA CISM SANS OSCP Security+ 6+ years of experience in cybersecurity, security operations, incident response, insider threat, threat analytics, security information and event management (SIEM), or equivalent experience. Demonstrated experience leading complex security incidents end-to-end, including technical investigation, containment, recovery, root-cause analysis, executive communication, and post-incident remediation. CISSP certification or other relevant (CISA, CISM, SANS GCIA, GCIH, OSCP, Security+). Experience collaborating with corporate insider threat, investigations, legal, or trade compliance functions; exposure to dedicated insider threat platforms such as Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint. Experience designing, deploying, or evaluating agentic AI or LLM-based automation in a security operations context is strongly desired; familiarity with post-quantum cryptography concepts and CNSA 2.0. Experience or interest in the specific challenges of protecting strategic research programs from sustained external targeting; familiarity with export control (EAR / ITAR) and government program environments.