About the job
Senior Lead for Detection and Response in Security Operations
San Carlos, CA (on-site)
About 1X
At 1X, we are at the forefront of innovation, developing humanoid robots that collaborate with humans to address labor shortages and foster abundance across various industries.
Role Overview
In the capacity of Senior Lead for Detection and Response, you will take charge of 1X's comprehensive detection strategy, encompassing centralized logging, SIEM architecture, and the implementation of a high-efficiency 24/7 SOC/MDR operational model. This role demands a hands-on leader who is adept at managing the entire detection loop—from logging and incident response to ongoing enhancements. You will engineer scalable systems, mitigate alert fatigue, and ensure dependable responses during critical situations. Your contributions will significantly bolster 1X's proficiency in detecting, managing, and learning from security incidents as our organization continues to expand.
Your Responsibilities
Establish and manage the entire detection lifecycle, including log collection, normalization, detection engineering, triage, response, and post-incident analysis.
Oversee centralized logging across cloud infrastructures, endpoints, identity systems, networks, and essential SaaS platforms.
Drive the SIEM strategy, incorporating new data sources, parsing, tuning, detection engineering, routing logic, and executive-level dashboards.
Develop and maintain a 24/7 SOC/MDR partnership, outlining requirements, playbooks, SLAs, escalation pathways, and quality benchmarks.
Implement incident readiness programs, including runbooks, tabletop exercises, evidence capture protocols, and post-incident improvements.
Minimize alert noise while enhancing detection signals through continuous tuning and risk-based alerting practices.
Lead investigations, focusing on triage, containment, root cause analysis, and the facilitation of post-mortem assessments.
Pinpoint and address detection gaps with measurable advancements in detection and containment timelines.

