Cleo is seeking a Security Operations Lead to build, operate, and continuously improve our security detection, response, and operational resilience capabilities.
This leader will be responsible for protecting Cleoβs cloud infrastructure, SaaS platforms, endpoints, and corporate environment from evolving threats while ensuring operational stability and regulatory alignment.
The ideal candidate is hands-on, technically deep, and capable of building scalable security operations in a high-growth SaaS environment.
What You Will Be Doing
Security Monitoring and Detection
β’ Own and evolve Cleoβs detection and response strategy
β’ Lead daily monitoring of security events across cloud, endpoint, identity, and application layers
β’ Continuously tune detection rules to reduce noise and improve signal
β’ Ensure effective coverage across AWS, SaaS platforms, and corporate systems
β’ Leverage SIEM, EDR, and cloud-native tooling to improve visibility
Incident Response and Containment
β’ Lead security incident investigations and coordinate cross-functional response
β’ Develop and maintain incident response playbooks
β’ Conduct post-incident reviews focused on systemic improvement
β’ Reduce mean time to detect and contain security events
β’ Partner with Legal, Compliance, and Leadership during material incidents
Vulnerability and Exposure Management
β’ Oversee vulnerability scanning across infrastructure, endpoints, and cloud resources
β’ Prioritize remediation based on business risk
β’ Track critical vulnerability exposure windows
β’ Partner with Engineering and IT to drive timely remediation
Cloud and Identity Security Operations
β’ Monitor and secure AWS accounts and cloud-native services
β’ Identify and remediate misconfigurations
β’ Strengthen identity and access management controls
β’ Collaborate with Cloud Security and Platform teams on guardrails
Operational Metrics and Reporting
β’ Define and track security operations KPIs
β’ Report on detection efficacy, remediation timelines, and exposure trends
β’ Provide board-ready operational risk metrics
β’ Support audit and compliance evidence requirements
Automation and Continuous Improvement
β’ Automate repetitive operational tasks
β’ Improve alert triage workflows
β’ Optimize tooling effectiveness and cost efficiency
β’ Reduce operational friction through process refinement
Leadership and Collaboration
β’ Lead and mentor security analysts and engineers
β’ Partner closely with Engineering, IT, and Platform teams
β’ Contribute to the Security Champion and Guild initiatives
β’ Build a culture of proactive risk identification
Your Skills
β’ Experience in mid-market or high-growth SaaS environments
β’ Experience supporting SOC 2, ISO 27001, or similar audits
β’ Familiarity with MITRE ATT&CK framework
β’ Experience building or maturing security operations functions
β’ Relevant certifications such as CISSP, GCIA, GCIH, or similar
Your Qualifications
Education
β’ Bachelorβs degree required.
Experience
β’ 7+ years of experience in security operations, incident response, or detection engineering
β’ Strong experience securing cloud-native SaaS environments, preferably AWS
β’ Hands-on experience with SIEM, EDR, vulnerability management, and cloud security tooling
β’ Deep understanding of attacker techniques and threat detection methodologies
β’ Experience leading incident response efforts
β’ Strong communication skills with the ability to translate technical risk into business impact
A few things we have to offer:
β’ Compensation: $120,000 - $140,000
β’ Great Healthcare + Dental + Vision
β’ Flexible PTO
β’ Culture of support, encouraging Life-Work balance
β’ 401k match
β’ FSA and HSA options
β’ Employee Assistance Program
β’ Paid Parental Leave
β’ Representing a company with 4,000+ clients and a 99% retention rate
β’ Accelerated title and salary growth potential
β’ A fun and energetic work environment that makes you excited to go to work every day
We use artificial intelligence (AI) tools to assist in certain stages of our recruitment process, such as resume screening and candidate matching. These tools are designed to support fair and consistent evaluations. If you have questions about this process or would like to request an alternative assessment method, please contact us at [Upgrade to PRO to see contact].
Cleo Communications US, LLC is an equal opportunity/affirmative action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability status, protected veteran status, or any other characteristic protected by law.