Remote Security Operations Lead (SecOps)
SWORD Health
At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning, safety, and real-time treatment, not generic technology applied after the fact. As both a clinical-centric frontier AI lab and an applied AI platform, Sword is reimagining how care is delivered at scale, removing traditional barriers like appointments, waiting rooms, and stigma so more people can access the care they need – and ultimately get back to lives lived in full.
Since 2020, Sword has expanded across Musculoskeletal, Women’s Health, Cardiometabolic, and Mental Health, and is now moving beyond the session to a fully AI-native, 24/7 care program that brings physical activity, therapeutic exercise, psychotherapy, nutrition, and behavior change into one connected experience. More than 1 million members across three continents have completed over 15 million AI sessions, helping 2,000+ enterprise clients avoid more than $1 billion in unnecessary healthcare costs. Backed by 59 clinical studies, 43 patents, and more than $500 million raised from leading investors including Khosla Ventures, General Catalyst, and Founders Fund, Sword is defining a new standard for healthcare.
Role
As Security Operations Lead, you’ll lead our SecOps squad and own how Sword detects, investigates, and responds to threats. You’ll help structure how this function operates — setting the direction on SIEM architecture, detection engineering, and incident response — and use automation and AI to scale a focused team across a fast-growing, multi-continent footprint. You’ll be a core voice in our security strategy, and the systems, processes, and culture you build will set the bar for how Sword protects 700,000+ members.
To get to know more about our Tech Stack, check here .
AI Proficiency at Sword Health
AI fluency is a core expectation at Sword Health. Every candidate is assessed against our three-level framework — be ready to share real examples of how AI is already part of how you work.
-
Explorer (Level 1) — Uses AI daily to boost personal productivity
-
Builder (Level 2) — Creates workflows and tools that elevate the whole team
-
Integrator (Level 3) — Embeds AI into products and processes at scale
Every hire must demonstrate at least Level 1. The expected level will vary depending on the seniority of the role.
What you’ll be doing
- Serve as the hands-on technical lead for Sword’s Security Operations Center. Setting the technical direction — architecting the SIEM, engineering detection logic, executing incident response, and building the technical roadmap to scale our defenses as the company grows.
-
Own the SIEM end-to-end (architecture, data sources, normalization, retention, cost, and tuning) and evolve detection-as-code content aligned to MITRE ATT&CK and Sword’s threat model.
-
Lead the SOC/CSIRT team technically — mentoring detection and response engineers, raising the bar on investigations, running on-call and escalation models, and acting as commander for major incidents.
-
Set the strategy and technical direction for Sword’s Security Operations Center — defining the operating model, SIEM and detection architecture, incident response capability, and the roadmap to scale them as the company grows.
-
Drive an AI- and automation-first transformation of security operations: design SOAR playbooks, agentic and LLM-assisted triage workflows, and ML-driven detection to reduce MTTD/MTTR, expand coverage, and let a lean team operate at enterprise scale.
-
Lead high-severity incident response from detection through containment, eradication, recovery, and post-incident review, partnering with engineering, IT, legal, and executive stakeholders during critical events.
-
Run the threat intelligence and threat hunting programs, converting emerging TTPs into new detections, proactive hardening, and informed risk decisions.
-
Define and report on SOC performance — MTTD, MTTR, coverage, automation rate, false-positive rate, on-call health — and use those metrics to drive measurable, continuous improvement.
-
Influence security architecture and engineering decisions across the company, ensuring detection, response, and recovery are built into new products, platforms, and infrastructure from day one.
-
Establish and continuously improve incident response playbooks, runbooks, and tabletop exercises to ensure organizational readiness.
What you need to have
- Required: Public Trust Clearance – Candidates must be able to obtain and maintain a US public trust clearance.
-
Bachelor’s degree in Computer Science, Cybersecurity, or equivalent professional experience.
- 7+ years experience in Security Operations
-
Proven experience scaling a SOC through automation and AI — SOAR, hyperautomation, LLM-assisted triage, agentic workflows, or ML-driven detection — with measurable impact on MTTR, coverage, or analyst leverage.
-
Hands-on experience structuring a SOC, either building one from the ground up or maturing one through significant transformation — SIEM selection, implementation or migration, detection engineering practice, runbook libraries, on-call rotations, and operating metrics.
-
Deep SIEM expertise (Splunk, Sentinel, Chronicle, Elastic, or similar) — ingestion architecture, detection-as-code, query optimization, and coverage-versus-cost tradeoffs.
-
Prior experience as the technical lead of a SOC or CSIRT team — owning the full incident response lifecycle, mentoring analysts and engineers, and acting as on-call/incident commander during major incidents.
-
Strong incident response track record — leading high-severity investigations, root cause analysis, digital forensics, and post-incident reviews that produced durable improvements.
-
Solid experience in cloud environments (AWS and/or GCP), with strong understanding of cloud-native threats and controls.
-
Strong scripting and development skills (Python, Go, Bash, or similar) for building automation, integrations, and internal tooling.
-
Working knowledge of EDR/XDR, identity, and network detection telemetry, and how to combine signals into high-fidelity detections.
-
Fluency with security frameworks and standards (NIST 800-61, CIS Controls, MITRE ATT&CK, ISO 27001) and the judgment to apply them pragmatically.
-
Background in threat modeling, adversary emulation, and risk-based alert tuning.
-
Excellent communicator — able to brief executives during a Sev1, write a clear post-mortem, and translate technical risk into business language for non-technical audiences.
-
Proven track record of leading cross-functional efforts in high-pressure situations and fostering collaboration across InfoSec, IT, and engineering.
-
Forensics experience, investigating incidents and preserving digital evidence.
Public Trust Clearance
Candidates must be able to obtain and maintain a US public trust clearance.
Please note that US citizenship is required to obtain and maintain a government security clearance.
Compensation
Additional Information
*This range includes base, variable and equity.
These compensation bands are just the starting point. Once someone joins and proves they’re outlier talent, we adjust quickly to ensure their compensation aligns with their impact.
Our job titles may span more than one career level. Actual pay is determined by skills, qualifications, experience, location, market demand, and other factors. Compensation details listed in this posting reflect the base salary and any potential variable, bonus or sales incentives, and the Company’s estimation of the value of private company stock options, if applicable. The pay range is subject to change, future value of company stock options is not guaranteed, and compensation may be modified in the future. In addition to our total compensation, Sword offers a number of benefits as listed below.
US – Sword Benefits & Perks:
• Comprehensive health, dental and vision insurance*
• Life and AD&D Insurance*
• Financial advisory services*
• Supplemental Insurance Benefits (Accident, Hospital and Critical Illness)*
• Health Savings Account*
• Equity shares*
• Discretionary PTO plan*
• Parental leave*
• 401(k)
• Flexible working hours
• Remote-first company
• Paid company holidays
• Free digital therapist for you and your family
*Eligibility: Full-time employees regularly working 25+ hours per week
Note: Applicants must have a legal right to work in the United States, and immigration or work visa sponsorship will not be provided.
SWORD Health, which includes SWORD Health, Inc. and Sword Health Professionals (consisting of Sword Health Care Providers, P.A., SWORD Health Care Providers of NJ, P.C., SWORD Health Care Physical Therapy Providers of CA, P.C.*) complies with applicable Federal and State civil rights laws and does not discriminate on the basis of Age, Ancestry, Color, Citizenship, Gender, Gender expression, Gender identity, Gender information, Marital status, Medical condition, National origin, Physical or mental disability, Pregnancy, Race, Religion, Caste, Sexual orientation, and Veteran status.
Jobicy JobID: 152249- ...To build and run the SecOps function at a rapidly scaling AI infrastructure platform, the full-time Security Operations Lead will manage incident response, define detection and response... ...with cross-functional teams in a remote environment. Key responsibilities Lead...Remote workFull time
- ...collaborative team that's building the future of enterprise AI. About the role We're hiring our first Security Operations Lead to build and run the SecOps function at Fireworks AI. As we scale our AI infrastructure platform globally, we're investing in a modern detection...Remote work
- ...building one of the world’s leading fintech companies and are off... ...About the Role As the Security Operations Lead, you will take strategic... ...of Lendable’s internal SecOps capability and serve as the... ...days in-office weekly; fully remote roles include regular opportunities...Remote workWork at officeFlexible hours
- ...solutions to complex national security issues. With over 50 years of... ...in space, cyber, and special operations in support to military... ...Manager & Operations Integration Lead.ResponsibilitiesThe successful... ...support classified deployments remotely, wherever possible, as well...Remote workFull timeWork at officeImmediate startFlexible hours
- Bring your energy to Aggreko as a Security Operations Team Lead, based in Glasgow. You’ll lead our Security Operations team to proactively identify... ...events that last a few weeks to mining operations and remote communities who rely on us for decades.What you’ll do as a...Remote workFull time
$135.41k - $250.75k
...now.We are currently seeking a Automation Operations Lead to join our team in Atlanta, Georgia (US... ...on-premises server infrastructure and secure public cloud tenants in Microsoft Azure... ...client’s needs. While many positions offer remote or hybrid work options, these...Remote workTemporary workWork at officeFlexible hours$130k - $135k
...Serve as the senior hands-on technical lead for IT operations, working closely with ONI’s outsourced... ...of core systems, infrastructure, security, access, service quality, and IT projects... ...provided and returned promptly for local and remote employees. Documentation and Knowledge...Remote workFull timeWork at officeLocal areaFlexible hours- ...NANA Management Services is seeking a Security Captain to lead security operations across client locations, including remote environments where safety is paramount. You will supervise security personnel, ensure policy compliance, and maintain strong client relationships...Remote work
- ...NMS seeks a Security Captain to lead security operations across client locations, including remote environments. You will supervise personnel, enforce policies, manage schedules, and foster strong client relationships to ensure safe, compliant service delivery. Qualifications...Remote work
- ...Revenue Operations Lead Aegis AI is building the next generation of email security—powered by AI agents that think and act like human analysts. Our mission is to keep users safe. Our agents stop Phishing and Spam attacks before they reach employees, using hundreds of...Remote work
$60k
...critical programs across national security, defense, and public service... ...work focuses on sustaining, operating, and improving essential... ...directed cyber activities. Lead and support containment and restoration... ...#clearance #veteranspage#LI-Remote Minimum Requirements...Remote workContract workShift work- ...Network & Infrastructure Operations Lead Hybrid | 3 Days Onsite Role Overview Our client... ...role supporting the stability, security, and evolution of our enterprise infrastructure... ..., access controls, and secure remote connectivity. Contribute to infrastructure...Remote work
- Offchain Labs, Inc. is seeking a highly organized Business Operations Manager to drive operational excellence across the company. This... ...business operations, project management, and execution, owning security initiatives while coordinating cross-functional teams. The ideal...Remote job
- ...Services of Texas, LLC is seeking an IT Operations Team Lead in Fort Worth, TX. The role supervises... ...reliable infrastructure, and drives security improvements while coordinating with leadership... ...and incident response with travel to remote locations as needed. Strong leadership...Remote work
- Figma is seeking a Security Operations Manager to lead its security operations program, focusing on monitoring and incident response. In this full-time... ...in automation techniques. This position allows for remote work from anywhere in the United States. #J-18808-Ljbffr...Remote jobFull time
- Offchain Labs is hiring a hands-on Business Operations Manager to drive operational excellence across the company. This role sits at the... ..., project management, and execution, owning high-priority security and technical initiatives while coordinating cross-functional...Remote job
- Cohere, a leading security-first enterprise AI company, seeks a Contract Manager to scale contract operations for a fast-paced growth environment. You will partner with Legal, Sales... ...compliance and timely renewals. Remote (US/Canada) role offering a comprehensive...Remote jobContract work
- NMS is seeking a Security Captain to lead security services across client locations, including remote environments in Alaska. You will supervise security personnel, enforce... ...while supporting effective security operations in public and office settings. Responsibilities...Remote workWork at office
- Ledgent Technology is seeking a Lead Security Operations Analyst to join our mature security team in Houston, TX. You will lead investigations, mentor analysts, and drive detection engineering and automation across endpoint, cloud, identity, email, and network environments...Remote job
- ...Hours is hiring our first dedicated IT Operations Lead to own systems, devices, and access company... ...SaaS and identity administration, and security alignment with Legal and Compliance.... ...the company scales across SF, NY, and remote teams. The role requires 5-8 years in IT...Remote workWork at office
- Mntn is hiring a Senior Manager for Security Operations to enhance and lead their security program. In this key role, you will protect Mntn’s people,... ...cloud security and incident response. Join us for a fully remote position and enjoy benefits like a flexible vacation...Remote jobFlexible hours
- United States Digital Space LLC is seeking a Security Operations Manager to lead the strategy and execution of our security operations program. You... ...the org. This full-time role can be based at a US hub or remotely within the United States, offering opportunities to build...Remote jobFull time
$26.88 - $35.82 per hour
...entity backed by some of the leading practitioners of the mortgage... ...mortgage continuum and enhance security, compliance, customer... ...and project outcomes in the Operations department. Work group is generally... ...Range $26.88 - $35.82 Hourly, Remote. This hiring range is a reasonable...Remote jobHourly pay$117.6k - $156.8k
...currently seeking a Technology Strategy & Operations Lead (Hybrid position in Irving, TX or... ...capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and... ...client’s needs. While many positions offer remote or hybrid work options, these arrangements...Remote workFull timeTemporary workWork experience placementWork at officeFlexible hours$110k - $130k
ACS is seeking a Sr Specialist for Security Training and Event Operations in Washington, DC. The role focuses on security planning for meetings, executive... .... The position offers a hybrid schedule with onsite and remote work, and compensation in the $110,000-$130,000 range...Remote workWeekend workAfternoon shift- ...is seeking an IT Infrastructure & Operations Manager in Deerfield Beach, FL to lead planning, execution, and delivery... ...initiatives. You will own Azure governance, security controls, disaster recovery, and... ...sites including branches and remote workers. The role requires hands-...Remote work
- Allegiance Search is seeking an IT Operations Manager to own the corporate technology environment... ...while improving service delivery, security, and the employee experience. You will manage... ..., while overseeing hardware lifecycle, remote connectivity, and vendor relations. #J-...Remote work
- ...A technology solutions company is seeking a motivated SecOps T1/Account Admin to monitor security alerts and manage user access. The role requires US citizenship and an active Secret security clearance. Candidates should have at least 1 year of related experience or an...Remote workFlexible hours
$78.98k - $117k
...integrated solutions deliver value across enterprise security performance, digital supply chains, cyber... ...Boston, Raleigh, New York, Lisbon, Singapore, and remote We are building an AI-native Customer Success operating model from the ground up, and we’re looking for a...Remote workFull timeFlexible hours$136k - $204k
...Job SummaryWe are looking for a Product Manager, SecOps to lead the strategy, roadmap, and adoption of security capabilities embedded directly into our engineering... ..., developer-friendly, and measurable.Security Operations depends on tight coordination between the teams that...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Remote Security Operations Lead (SecOps). Be the first to apply!
- network operations center team lead Remote
- operations leader Remote
- operations lead Remote
- senior network engineer remote Remote
- business intelligence analyst remote Remote
- document specialist remote Remote
- chief of staff remote Remote
- remote legal intern Remote
- remote accounts receivable Remote
- revit remote Remote

