Company Profile:
Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed. Lennox is a global community that values each team member’s contributions and offers a supportive environment for career development. Come, stay, and grow with us.
Job Description:
Key Responsibilities
SOC Leadership
-
Lead enterprise Security Operations Center (SOC) and continuous security monitoring programs.
-
Manage analysts and ensure effective detection, triage, investigation, escalation, and response.
-
Drive operational excellence through process improvements, metrics, governance, and maturity initiatives.
-
Oversee monitoring across cloud, identity, endpoint, network, applications, OT, and SaaS environments.
Incident Response & Crisis Management
-
Lead cyber incident response activities including investigation, containment, eradication, recovery, and lessons learned.
-
Coordinate with IT, Legal, Compliance, Privacy, and Business teams during major incidents.
-
Maintain incident response plans, playbooks, escalation procedures, and conduct tabletop exercises.
SIEM & Detection Engineering
-
Own SIEM operations, administration, governance, and platform optimization.
-
Manage detection use case lifecycle, tuning, validation, and MITRE ATT&CK aligned coverage.
-
Improve visibility through log onboarding, threat intelligence integration, and detection effectiveness programs.
EDR/XDR Operations
-
Oversee enterprise EDR/XDR monitoring, investigations, and response activities.
-
Lead containment actions including endpoint isolation, account suspension, credential resets, malware remediation, and IOC blocking.
-
Ensure endpoint telemetry coverage and continuous enhancement of threat detection capabilities.
Data Loss Prevention (DLP)
-
Manage enterprise DLP operations across endpoints, email, collaboration platforms, cloud applications, and data repositories.
-
Investigate data protection incidents and drive policy tuning, classification, and governance initiatives.
-
Ensure compliance with regulatory, privacy, and data protection requirements.
Threat Intelligence & Threat Hunting
-
Operationalize threat intelligence into actionable detections and response strategies.
-
Lead proactive threat hunting focused on ransomware, insider threats, identity compromise, cloud attacks, and advanced adversary activity.
-
Convert hunting findings into detections, playbooks, and preventive controls.
AI /Automation & Operational Excellence
-
Drive automation and AI-assisted workflows to improve analyst productivity and response efficiency.
-
Partner with engineering teams to implement SOAR capabilities and reduce MTTD/MTTR.
-
Standardize SOPs, runbooks, quality processes, and operational reporting.
Leadership & Governance
-
Lead, mentor, and develop SOC analysts, incident responders, SIEM engineers, and DLP specialists.
-
Manage cybersecurity vendors, service providers, budgets, and operational performance metrics.
-
Support audits, compliance assessments, executive reporting, and act as the primary escalation point for cyber defense operations.
Qualifications:
- 15+ years of cybersecurity experience.
-
5+ years managing SOC, Incident Response, or Cyber Defense teams.
-
Experience operating enterprise-scale security monitoring programs.
-
Proven experience handling major cybersecurity incidents.
-
Experience leading security transformation and operational maturity initiatives.