Experience: 5+ years of experience in cybersecurity operations or incident response, with at least 2–3 years in a senior SOC analyst or similar role. The candidate should have a demonstrated ability to handle high-severity incidents and lead others. Prior experience in a team lead, technical lead, or supervisory capacity is strongly preferred.
Technical Proficiency: Advanced hands-on experience with SOC tools and processes. This includes expertise in using SIEM and EDR tools for analysis and an understanding of SOAR (Security Orchestration, Automation, and Response) platforms for workflow automation. In-depth familiarity with incident response procedures (containment, eradication, recovery) as formalized in frameworks like NIST or SANS. Able to step in and perform any analyst task (from triage to deep forensic analysis) if needed.
Leadership Skills: Proven track record of coordinating team activities or leading small teams during critical operations. This could be evidenced by experience as a senior analyst who has taken charge during incidents or mentored junior staff. Strong organizational skills to manage 24/7 shift scheduling and ensure coverage.
Communication: Excellent communication and interpersonal skills. Capable of effectively communicating with technical team members, as well as translating technical issues into actionable information for managers. Ability to provide clear guidance under pressure is essential for managing live security incidents.
Certifications: Recognized credentials demonstrating both technical depth and leadership potential. Examples include advanced technical certs like SANS GCIA, GCIH (or similar) to validate incident handling expertise, and broad security management or professional certifications such as CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) to indicate knowledge of governance and leadership in security operations.
Preferred Qualifications:
Exposure to IAM domains such as identity governance and administration, access request and approval, access certifications, role management, privileged access management, single sign-on, multifactor authentication, or directory services.
Scrum Master, Agile, project management, business analysis, or process improvement certification or equivalent practical experience.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Experience supporting regulated environments, audit response, control documentation, risk remediation, or compliance-driven technology initiatives.
Ability to build structured templates, dashboards, operating procedures, and reporting routines that improve transparency and repeatability.
Experience identifying repeatable work patterns and partnering with technology teams to automate tracking, reporting, intake, follow-up, evidence collection, or other recurring IAM program management activities.
About Charles Schwab
Banking33700 employeesFounded 1971
Financial services firm providing brokerage, banking, and advisory services.