Island is the ideal environment for enterprise work, where security is everywhere without ever getting in the way.
The Island Enterprise Platform unifies AI enablement, network access, data protection, identity, and endpoint control into one coherent workspace—so organizations get universal visibility and control, and users get a fast, fluid, beautifully simple experience. It's not just a better way to secure work. It's a better way to work. Backed by investors like Coatue Management, Insight Partners, Sequoia Capital and Cyberstarts, and trusted by some of the largest, most respected enterprises on the planet, Island is redefining what the modern workplace can be.
Come join us in building something that's already changing how the world works, we’re always looking for world-class human beings (not resumes) to join the movement.
As a SecOps Lead at Island, you will own the core of the security operations function: detection, response, automation, and the processes that connect them. You will guide incident response from first alert through post-mortem, keeping efforts structured and stakeholders informed along the way. You will shape how the team detects, triages, and resolves, and communicate that work clearly to leadership, engineering, and customers.
This is a hands-on role with broad ownership. You should be comfortable writing a detection rule, coordinating a live incident, and walking stakeholders through a post-incident review.
Key Responsibilities
- Lead Incident Response: Own the end-to-end incident response lifecycle across Island's infrastructure and enterprise browser platform, driving investigations, coordinating responders, and ensuring timely resolution and post-incident improvements.
- Own the IR Framework: Build, maintain, and continuously improve incident response processes, including runbooks, severity definitions, escalation paths, on-call procedures, and communication standards.
- Drive Detection Engineering: Design, implement, and continuously improve high-fidelity detections across SIEM, EDR, cloud, and endpoint security platforms, closing visibility gaps and strengthening detection coverage.
- Automate Security Operations: Build automation and AI-driven workflows that streamline triage, investigation, enrichment, and response, reducing manual effort and improving operational efficiency.
- Threat Hunting & Research: Proactively hunt for threats, leverage threat intelligence, and identify emerging attack techniques relevant to modern enterprise environments.
- Own Security Operations: Serve as the technical owner for Security Operations within Product Security, driving strategy, setting best practices, and continuously improving detection and response capabilities.
- Partner Across Engineering: Collaborate closely with Engineering, IT, Infrastructure, and Compliance teams to embed security into new services, infrastructure changes, FedRAMP initiatives, and customer-facing security requirements.
- Communicate During Incidents: Provide clear, timely communication throughout incident response, keeping technical teams, leadership, and stakeholders aligned on impact, progress, risks, and next steps.
Requirements
- 5+ years of hands-on experience in Security Operations, Incident Response, or Detection Engineering.
- Proven experience leading end-to-end incident response for high-severity security incidents in cloud or enterprise environments.
- Strong understanding of detection engineering, threat hunting, and modern security operations, with hands-on experience using SIEM, EDR, and cloud security platforms.
- Experience building and improving incident response processes, including runbooks, severity frameworks, escalation paths, and post-incident reviews.
- Hands-on experience automating security operations using SOAR platforms and AI-powered workflows (Torq, Tines, or similar).
- Solid understanding of AWS security fundamentals, including IAM, CloudTrail, and containerized environments (EKS is an advantage).
- Strong knowledge of modern attack techniques, threat intelligence, detection methodologies, and investigation best practices.
- Excellent written and verbal communication skills, with the ability to communicate effectively during incidents and present findings to both technical and non-technical stakeholders.
- Experience collaborating across Engineering, Infrastructure, IT, and Compliance teams to improve security posture.
- Experience mentoring engineers or leading cross-functional security initiatives is an advantage.
- Familiarity with SOC2, FedRAMP, or other regulated compliance frameworks is a plus.