
This position is based on‑site and requires four days per week in the Brea office to support collaboration and business needs.
We are seeking a strategic and hands-on Security Operations and Engineering Lead to drive enterprise cybersecurity operations, detection engineering, incident response, and security platform capabilities.
This leader owns the SOC, incident response program, detection lifecycle, and security tooling ecosystem, and is responsible for building scalable, threat-informed, and measurable security operations.
PRIMARY DUTIES AND RESPONSIBILITIES:
Security Operations Leadership
Lead enterprise security operations including monitoring, triage, investigation, escalation, and response
Oversee SOC and MSSP/MDR partnerships including SLAs, alert quality, escalation paths, and performance metrics
Establish 24x7 monitoring aligned to enterprise risk
Define KPIs/KRIs including MTTD, MTTR, alert fidelity, detection coverage, and response effectiveness
Security Engineering & Platform Management
Lead lifecycle management of SIEM, SOAR, EDR/XDR, CSPM, DLP, identity security, and cloud security platforms
Drive automation across triage, enrichment, containment, and reporting workflows
Define enterprise logging and telemetry strategy including onboarding, parsing, normalization, retention, and coverage standards
Ensure tools are integrated, cost-effective, and aligned to risk priorities
Incident Response & Threat Management
Own incident response program including playbooks, exercises, breach workflows, and communications
Lead major incidents through containment, eradication, recovery, and root cause analysis
Ensure post-incident reviews drive durable control improvements
Coordinate with Legal, Privacy, HR, IT, and Communications
Detection Engineering & Monitoring
Build detection engineering lifecycle: hypothesis → development → testing → tuning → deployment → validation → retirement
Develop behavior-based and threat-informed detections aligned to MITRE ATT&CK
Expand monitoring across endpoint, identity, cloud, SaaS, network, and critical applications
Identify and close detection gaps via red team, pentest, and vulnerability insights
Exposure & Control Operations
Support exposure management, asset inventory visibility, and attack surface monitoring
Drive continuous control monitoring and validation of key security controls
Improve vulnerability remediation workflows and risk reduction outcomes
Leadership & Stakeholder Management
Build and lead high-performing security operations and engineering teams
Establish clear roles, operating model, and accountability
Provide executive reporting on threats, incidents, control gaps, and maturity
Partner with GRC, Audit, IT, Architecture, and business leadership
Job Requirements:
Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, Business, Engineering, or a related fields OR equivalent industry experience, military service, professional certifications, and demonstrated leadership experience are valued equally.
7+ years of experience in cybersecurity, security operations, detection engineering, incident response, or security engineering.
5+ years leading security operations, engineering, SOC, or incident response teams.
Experience operating security capabilities across cloud, SaaS, endpoint, identity, and enterprise environments.
Experience managing MSSP, MDR, SOC-as-a-Service, or strategic security service providers.
Hands-on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Chronicle, etc.)
Experience in Azure, AWS, or GCP environments.
Understanding of Zero Trust security principles and modern detection strategies.
Ability to communicate technical risks to executive leadership and business stakeholders.
Experience coordinating investigations across security, IT, legal, privacy, HR, and executive stakeholders.
PREFERRED SKILLS & EXPERIENCE:
10+ years of cybersecurity experience.
Experience building or transforming a SOC program.
Experience supporting a global or multi-business-unit environment.
Experience leading incident response for major cybersecurity events.
One or more of the following certifications: CISSP; CISM; CCSP; GIAC certifications (GCIH, GCIA, GCFA, GMON); Microsoft Security certifications; Splunk certifications; Microsoft Sentinel certifications; CrowdStrike certifications; AWS/Azure/GCP security certifications.
#LI-SC1
IND123
Target Market Salary Range:
Actual compensation packages take into account a wide range of factors that are unique to each candidate, including but not limited to geographic location; skill sets; relevant education and certifications; depth of experience; performance; and other business and organizational needs. The disclosed reasonable estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Envista, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. The total compensation package for this position may also include an annual performance bonus, medical/dental/vision benefits, 401K match, and/or other applicable compensation plans.
$156,400 - $191,200
Operating Company:
Corporate
Envista is a global leader in the dental industry, uniting more than 30 trusted brands—including DEXIS, Kerr, Nobel Biocare, and Ormco—under one mission: partnering with dental professionals to improve patients’ lives. With a heritage of category-defining innovation, our brands have shaped modern dentistry: Nobel Biocare introduced the first dental implant, Ormco is a pioneer in both traditional and digital orthodontics, DEXIS has long been at the forefront of 2D, 3D and intraoral imaging, and Kerr has supported clinicians for over 135 years. Our high-performing culture is underpinned by our CIRCLe Values and the Envista Business System. Guided by these, we deliver a comprehensive portfolio of technologies, consumables, and services that empower clinicians to provide confident, efficient care—today and for the future. Learn more at http://envistaco.com
Envista and all Envista Companies are equal opportunity employers that evaluate qualified applicants without regard to race, color, national origin, religion, sex, age, marital status, disability, veteran status, sexual orientation, gender identity, or other characteristics protected by law. The “EEO is the Law” poster is available at: http://www.dol.gov/ofccp/regs/ compliance/posters/pdf/eeopost.pdf.
Envista and its family of companies (Envista) will not accept unsolicited resumes from any source other than directly from a candidate. Envista will consider unsolicited referrals and/or resumes submitted by vendors such as search firms, staffing agencies, professional recruiters, fee-based referral services and recruiting agencies (Agency) to have been referred by the Agency free of charge and Envista will not pay a fee for any placement resulting from the receipt such unsolicited resumes. An Agency must obtain advance written approval from Envista's internal Talent Acquisition or Human Resources team to submit resumes, and then only in conjunction with a valid fully-executed contract approved by the Global Talent Acquisition leader and in response to a specific job opening. Envista will not pay a fee to any Agency that does not have such agreement and written approval in place.

Envista is a global family of more than 30 trusted dental brands, united by a shared purpose: to partner with professionals to improve lives. Envista helps its partners deliver the best possible patient care through industry-leading products, solutions, and technology. Our comprehensive portfolio covers a wide range of dentists' clinical needs for diagnosing, treating, and preventing dental conditions, as well as improving the aesthetics of the human smile.
Our differentiated combination of continuous improvement, a bias toward action and innovation, and a deep respect for the more than one million professionals we serve embolden us to champion dental professionals like no one else can.
The operating companies that form Envista, including Nobel Biocare, Implant Direct, Ormco, DEXIS, Kerr, Metrex, and more represent more than 125 years of dental industry excellence. These brands meet the end-to-end needs of dental professionals worldwide.
We are committed to helping dental professionals improve their patients’ lives by digitizing, personalizing, and democratizing oral care. Every day, our products and solutions are accelerating the future of dentistry. Operating with high sustainability standards guides our decision-making so that we can deliver enhanced outcomes for our people, the environment, and communities.
View our Environmental, Social, and Governance report at https://bit.ly/Envista2022ESG to learn more about our commitment to sustainability.
Learn more at www.envistaco.com.