Company Profile:
Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed. Lennox is a global community that values each team member’s contributions and offers a supportive environment for career development. Come, stay, and grow with us.
Job Description:
Cyber Defense Strategy & Architecture
-
Define and maintain enterprise Blue Team security architecture roadmap.
-
Design scalable cyber defense capabilities across cloud, endpoint, identity, network, applications, OT, and SaaS environments.
-
Lead security architecture decisions for SIEM, SOAR, XDR, UEBA, TIP, DSPM, and AI Security platforms.
-
Establish security engineering standards, reference architectures, and defense patterns.
SIEM Engineering & Detection Strategy
-
Own enterprise SIEM architecture, use case lifecycle, content governance, and platform optimization.
-
Develop risk-based detection frameworks aligned to MITRE ATT&CK.
-
Drive Detection-as-Code practices with CI/CD integration.
-
Improve detection fidelity through behavioral analytics, threat intelligence, and AI-powered analytics.
-
Establish threat-based detection coverage metrics.
SOAR & Autonomous Security Operations
-
Lead SOAR architecture and orchestration strategy.
-
Design automated response playbooks for high-volume attack scenarios.
-
Implement machine-speed containment actions such as:
-
Endpoint isolation
-
Account suspension
-
Token revocation
-
Network containment
-
Email quarantine
-
IOC blocking
-
Reduce analyst workload through AI-assisted investigation and autonomous workflows.
AI Security Defense
-
Design controls to detect and defend against:
-
Prompt injection attacks
-
LLM abuse
-
AI model poisoning
-
Data leakage through AI platforms
-
Autonomous agent attacks
-
Deepfake and synthetic identity threats
-
Implement AI-assisted threat detection, correlation, and investigation capabilities.
-
Establish governance, monitoring, and security controls for enterprise AI adoption.
Threat Hunting & Adversary Detection
-
Build and lead enterprise proactive threat hunting programs.
-
Develop advanced hunting methodologies focused on:
-
Living-off-the-land attacks
-
Identity compromise
-
Lateral movement
-
Cloud-native attacks
-
Ransomware precursors
-
Insider threats
-
AI-driven attack campaigns
-
Create repeatable hunt playbooks and hunting analytics.
-
Drive adversary emulation and purple team exercises.
Emerging Threat Research
-
Track evolving threat actor TTPs.
-
Conduct threat-focused research on:
-
AI-powered phishing
-
GenAI-enabled malware
-
Autonomous attack tooling
-
Ransomware evolution
-
Supply chain attacks
-
Cloud and SaaS threats
-
Translate intelligence into actionable detections and mitigations.
Security Leadership & Influence
-
Provide technical leadership across SOC, IR, CDE, DLP, Cloud Security, and AppSec teams.
-
Mentor senior security engineers, architects, and threat hunters.
-
Act as executive advisor for cyber defense modernization initiatives.
-
Lead security architecture reviews and tabletop exercises.
Qualifications:
Experience
-
15+ years of cybersecurity experience.
-
8+ years in Security Operations, SIEM Engineering, Threat Hunting, or Cyber Defense Architecture.
-
Proven experience building enterprise-scale SOC programs.
-
Experience leading security transformation initiatives.
Technical Expertise
Deep expertise in:
-
SIEM Platforms
-
Microsoft Sentinel
-
Splunk
-
Cortex XSIAM
-
Elastic
-
SOAR Platforms
-
Cortex XSOAR
-
Microsoft Security Copilot & Sentinel Automation
-
Splunk SOAR
-
Detection Engineering
-
Threat Intelligence
-
MITRE ATT&CK
-
Threat Hunting
-
Cloud Security
-
Identity Security
-
EDR/XDR
-
UEBA
-
Data Protection & DLP
-
Security Analytics
-
AI Security
Preferred Certifications
CISSP, GCIA, GCTI, GREM, GMON, SABSA, Azure Security Engineer, Microsoft Sentinel Specialist, SANS Threat Hunting Certifications