CAI is seeking a Senior Technical Lead for a Cybersecurity Operations Center (COC) to assess, rebuild, and optimize a clientβs SOC organization, processes, and tool environment. This full-time 4β6 month onsite engagement in the Chicago loop focuses on improving how the team detects, analyzes, and responds to security events, while ensuring the underlying managed detection and response capabilities operate effectively.
In this role, you will lead evaluation of the current-state COC, shape a future operating model, and oversee the deployment and tuning of security monitoring and endpoint/logging solutions. You will also coordinate incident response execution, vulnerability assessment and remediation, and continuous improvements aligned to recognized cybersecurity frameworks.
What youβll do
- Analyze the clientβs current COC organization, technology environment, and operational processes to define process and procedure and identify organizational gaps
- Define the future-state COC organization, including roles and responsibilities and staff alignment, as well as skills gaps, processes (including event triage and playbooks), and technology recommendations
- Understand the clientβs current infrastructure and teach the team how to tune systems, identify redundancies, and apply practical knowledge so they can operate effectively
- Manage deployment, ongoing tuning, configuration, and operation of managed detection and response (MDR) tools and services, endpoint detection solutions, software logging and scanning tools, and other cybersecurity solutions
- Oversee assessment and remediation of security events, incidents, and vulnerabilities identified by the security operations team
- Collaborate with IT teams and business stakeholders to define expectations, develop security strategies, build consensus on remediation plans, and facilitate implementation
- Create, refine, test, and enforce cybersecurity policies and procedures to identify security gaps and remediation actions
- Develop and maintain disaster recovery plans and coordinate organizational readiness for disruptive events and business continuity
- Implement cybersecurity awareness and training programs focused on recognizing, responding to, and reporting cybersecurity threats
- Monitor emerging threats, vulnerabilities, industry best practices, and regulatory requirements to support compliance and continuous improvement
- Provide expertise on security data analysis methodologies and collaborate cross-functionally to enhance detection and response capabilities
- Recommend risk-reduction strategies across cloud environments, on-premises infrastructure, servers, network devices, and endpoints
- Review, update, communicate, and execute incident response plans, coordinating exercises and ensuring stakeholders understand their responsibilities
Required qualifications
- Bachelorβs degree in Information Technology, Engineering, Management Information Systems, or a related field, or four years of equivalent experience in IT networking or cybersecurity in lieu of a degree
- Eight years of experience in IT networking or cybersecurity, including six years as a security analyst, network engineer, or systems engineer
- Recent and practical hands-on experience with the MS stack: EntraID, Defender (cloud, endpoint, email), and Sentinel
- Two years of cybersecurity operations team leadership experience
- Considerable knowledge of security event monitoring, analysis, triage, vulnerability scanning, asset management, and MDR/SIEM tools and processes
- Considerable knowledge of PCs, servers, firewalls, TCP/IP, network administration tools, intrusion detection systems, anti-virus software, Active Directory, data encryption, and security best practices
- Knowledge of cybersecurity frameworks and methodologies including NIST 800-53, ISO 27001, MITRE ATT&CK, and CIS Controls
- Strong problem-solving skills balancing business requirements and cybersecurity risk
- Strong program and project management skills
- Strong verbal and written communication skills for working effectively with vendors and stakeholders at all organizational levels
- Strong organizational, analytical, and critical thinking skills for evaluating cybersecurity controls and recommending improvements
- Ability to build and lead high-performing teams through clear direction, accountability, and results-driven leadership
- Ability to evaluate control effectiveness, recommend improvements, build consensus, and facilitate execution
- Ability to prioritize and execute tasks in a high-pressure environment while balancing risk and business needs
- Ability to collaborate effectively with IT teams, business users, and external partners to deliver secure technology solutions
Technical skills and tools
- EntraID
- Defender (cloud, endpoint, email)
- Sentinel
- MDR and SIEM
- NIST 800-53, ISO 27001, MITRE ATT&CK, CIS Controls
- Active Directory, TCP/IP, intrusion detection systems, anti-virus software
Education and experience
- Bachelorβs degree in Information Technology, Engineering, Management Information Systems, or a related field
- Minimum 8 years of relevant experience in IT networking or cybersecurity
Location and worksite
Compensation
- $90β$100 per year
- Exact compensation may vary based on factors including location, experience, and education
Benefits
- Medical, dental, and vision insurance
- 401k retirement account access
- Paid time off
- May also be entitled to paid sick leave and/or other paid time off as provided by applicable law
Preferred qualifications
- Experience standing up a COC
- CISM
- CISSP
- CompTIA Security+
Physical demands
- Ability to safely perform essential job functions consistent with ADA and other federal, state and local standards
- Sedentary work involving sitting or remaining stationary most of the time, with occasional need to move around the office to attend meetings
- Ability to conduct repetitive tasks on a computer using a mouse, keyboard, and monitor
Reasonable accommodation
If you require a reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employment selection process, please direct your inquiries to application.accommodations@cai.io or (888) 824 - 8111.