Cyber Security Operations Lead
Brown Brothers HarrimanAbout the role
At BBH, Partnership is more than a form of ownership—it’s our approach to business and relationships. We know that supporting your professional and personal goals is the best way to help our clients and advance our business. We take that responsibility seriously. With a 200-year legacy and a shared passion for what’s next, this is the right place to build a fulfilling career.
As the Cyber Security Monitoring Lead within our Security Operations Center (SOC), you will make a significant impact in safeguarding our organization from cyber threats and mitigating cyber risks. While managing a team of SOC analysts, you will contribute to, enhance, and mature our ability to effectively identify, detect, and respond to active threats against our networks, systems, data, employees, and clients. The ideal candidate will have experience leading SOC and Incident Response (IR) operations, have an analytical mindset, and a passion for continuous learning and growth.
Key responsibilities include:
- Management and oversight of SOC Analysts and day-to-day operations of the Cyber Threat Monitoring team
- Responding to and performing in-depth technical analysis and risk assessment of all security events and incidents
- Analyzing and investigating suspicious activities, performing log analysis, applying data analytics techniques, and utilizing a wide-array of industry leading security tools
- Participating in technical discussions around security events and activities with various non-technical and technical parties
- Maintain key risk and performance indicators (KRIs/KPIs) and metrics around established service-level agreements (SLAs)
- Collaborate and coordinate with the Cyber Threat Intelligence (CTI) and SOC Engineering teams to maintain alerts and develop alert and IR runbooks/decision-trees
Other duties and Responsibilities:
- Analyze security alerts and data from various sources to detect and prioritize malicious, suspicious, or risky activities
- Perform root cause analysis to identify security control gaps and develop effective prevention and detection strategies
- Work closely with internal teams and systems owners to refine incident and event management processes, assess vulnerabilities, and recommend measures for detecting anomalous behavior
- Enhance monitoring processes through seamless integration with a Security Incident and Event Management (SIEM) solution and other security tools
- Conduct proactive analysis of alert trends to identify and prioritize missing or ineffective detection capabilities
- Support security incident investigations using data analytics and digital forensics methodologies
- Perform privileged and general user access monitoring across various platforms (Windows, Unix/Linux, RHEL, databases, network components, applications, cloud infrastructure)
- Stay abreast of emerging cyber risks, threats, vulnerabilities, trends, and best practices, and make recommendations for continuous improvement
- Align and evaluate security practices and controls with the MITRE ATT&CK / D3FEND framework to enhance threat detection and response strategies for known adversary Tactics, Techniques, Procedures (TTPs)
- Develop, document, and uphold procedures, standards, and policies for effective threat analysis and response
- Assist in creating reports and presentations for various stakeholders to provide insights into team metrics, active threats, and mitigation strategies
- Provide expert technical guidance and security insights to various teams across the organization
Required Qualifications:
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field
- 8+ years of experience in Security Operations, Incident Response, and/or related roles.
- Significant relevant experience (e.g., military) in the above roles may be considered in lieu of degree
- Experience as an effective leader and people manager
- Excellent collaboration and communication skills, particularly in high-stress situations
- A desire to understand and maintain awareness of changes to the cyber threat landscape
- Strong analytical and quantitative skills as well as good priority management
Nice to Have:
- Master's degree in Cybersecurity, Computer Science, Information Technology, or related field
- Hands-on experience in three or more of the following areas: Security Operations, Incident Response, Cyber Threat Intelligence, Threat Hunting, Detection Engineering, Security Engineering, Insider Threat Analysis, Digital Forensics, All-Source Intelligence, Penetration Testing, Red Teaming, Malware Analysis, Network Traffic Analysis, Network Security Man
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s