Stop applying to jobs that are already dead.
Every listing verified, aged honestly, expired when filled.

All listings

Deel via Deel

Team Lead, Security Operations

lead United StatesCanada
still open verified 15h ago posted 23h ago checked just now
Apply at jobs.deel.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 15h ago — checked against Deel's own job API.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 23h ago

The date the source published, not the day we noticed it (2026-09-14). Last seen at its source just now.

Is it remote?

The listing says yes

The location field doesn't say remote, so our assessment is based on the title or the description. Read the listing before applying.

Who may apply?

United States, Canada

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay $175k–238.5k/yr

Middle 50% of 105 listings that do state pay — Operations · Lead · United States · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AWSBashBusiness ReviewsEscalation ManagementHRISISO 27001Incident ManagementKnowledge BaseKubernetesOnboardingPCI DSSPayrollProcess ImprovementProcurementPythonSIEMSLASOC 2SQLTalent Acquisition

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

Who we are is what we do. Deel is the all-in-one payroll and HR platform for global teams. Our vision is to unlock global opportunity for every person, team, and business. Built for the way the world works today, Deel combines HRIS, payroll, compliance, benefits, performance, and equipment management into one seamless platform. With AI-powered tools and a fully owned payroll infrastructure, Deel supports every worker type in 150+ countries—helping businesses scale smarter, faster, and more compliantly. Among the largest globally distributed companies in the world, our team of 7,000 spans more than 100 countries, speaks 74 languages, and brings a connected and dynamic culture that drives continuous learning and innovation for our customers. Why should you be part of our success story? As the fastest-growing Software as a Service (SaaS) company in history, Deel is transforming how global talent connects with world-class companies – breaking down borders that have traditionally limited both hiring and career opportunities. We're not just building software; we're creating the infrastructure for the future of work, enabling a more diverse and inclusive global economy. In 2024 alone, we paid $11.2 billion to workers in nearly 100 currencies and provided healthcare and benefits to workers in 109 countries—ensuring people get paid and protected, no matter where they are. Our momentum is reflected in our achievements and customer satisfaction: CNBC Disruptor 50, Forbes Cloud 100, Deloitte Fast 500, and repeated recognition on Y Combinator's top companies list – all while maintaining a 4.83 average rating from 15,000 reviews across G2, Trustpilot, Captera, Apple and Google. Your experience at Deel will be a career accelerator. At the forefront of the global work revolution, you'll tackle complex challenges that impact millions of people's working lives. With our momentum—backed by a $17.3 billion valuation and $1 B in Annual Recurring Revenue (ARR) in just over five years—you'll drive meaningful impact while building expertise that makes you a sought-after leader in the transformation of global work. Shift: EST 9–5, on-call for Sev-1 escalations Job Description: We're looking for a Team Lead, Security Operations with an AI first mindset to own Deel's security operations pod end to end. This is a player-coach role: you'll manage a globally distributed team of security analysts, set the strategy and metrics for how Deel detects and responds to threats, and stay hands-on at the same time, leading major incidents, hunting, and building detections alongside your team. You'll govern our managed security partner (MSSP), who provides 24x7 tier-one monitoring, and lead our in-house team, which provides 24x5 escalation, investigation, and response across regions. You'll own that model completely: the escalation path, the partner relationship, the quality of every outcome, and the people who deliver it. You'll lead AI first security operations and response from strategy through implementation, including modernizing our SIEM/SOAR platform: requirements and evaluation, data onboarding, detection parity, SOAR automation, cutover, and day-two operations. The pod's core responsibilities include, but are not limited to, threat hunting, insider threat, incident response, security event management, purple teaming, and phishing and email threat assessment across a remote-first, AWS-native environment. Responsibilities: Lead and manage the Security Operations pod. Coach and develop a team of Security Analysts distributed across regions. Set goals, run performance and career conversations, and build a high-trust, blameless culture. Flex your working hours when needed so every team member gets real face time with their lead, regardless of time zone. Own incident response end to end. Act as the escalation point and incident commander for high-severity incidents, define the severity matrix and runbooks, coordinate internal and external stakeholders during response, and run blameless post-incident reviews that drive remediation to closure. Lead the SIEM/SOAR modernization program. Define requirements, run the evaluation, and lead the implementation, migration, and operationalization of a modern SIEM / AI SOC platform: log source inventory and onboarding, parsing and normalization, detection parity and detection-as-code, SOAR playbook migration, parallel run and cutover, and cost and retention governance. Govern the MSSP partnership. Own SLAs, escalation criteria, alert-tuning feedback loops, quality sampling of tier-one work, and QBRs. Make the handoff between 24x7 partner coverage and internal 24x5 response seamless and measurable. Build and run the threat hunting and detection engineering program. Lead hypothesis-driven hunts mapped to MITRE ATT&CK, own the detection lifecycle and coverage gap analysis, integrate threat intelligence, and continuously tune to reduce alert fatigue. Lead the insider threat program. Partner with internal stakeholders on monitoring use cases across endpoints and SaaS (such as EDR, SWG, ZTNA, CASB, and DLP ), balancing detection effectiveness with privacy, proportionality, and evidence handling. Run the purple team program. Plan and execute adversary-emulation exercises with offensive partners, validate detections and response playbooks, and convert every finding into a tracked detection or process improvement. Own phishing and email threat assessment. Run the user-reported phishing workflow, lead analysis of suspicious emails, tune the email security gateway, and automate the high-volume, low-complexity cases. Drive detection and response for the AWS platform. Partner with Platform Engineering, Product Security, and Cloud Security on telemetry (e.g., CloudTrail, GuardDuty, VPC Flow Logs, EKS and container signals, IAM activity), cloud incident response playbooks, and detection coverage for the AWS environment Deel's product runs on. Build the metrics and tell the story. Define and report SOC KPIs such as MTTD, MTTR, escalation and false-positive rates, detection coverage, automation rate, and hunt outcomes. Translate them into a risk narrative leadership can act on. Operate AI first. Embed AI-assisted triage, enrichment, investigation, and automation into daily workflows. Define the guardrails, confidence thresholds, and human-in-the-loop governance for any autonomous action. Set the roadmap. Develop and maintain a 1–3 year security operations roadmap aligned with business growth, the threat landscape, and compliance obligations. Own vendor management for the pod. Stay hands-on. Lead investigations, write detections, build automations, and pair with team members to raise the technical bar. Job Requirements: AI first mindset! 8+ years of experience in cybersecurity, with a minimum of 3 years directly managing people in a SOC, incident response, or security operations team. Proven, hands-on experience implementing, migrating, and operationalizing SIEM and SOAR platforms at enterprise scale, including data onboarding, detection content migration, playbook automation, and cost and retention governance. Experience with modern cloud-native SIEM and AI SOC platforms is critical for this role. Deep incident response experience, including incident command for high-severity incidents, forensics fundamentals, and structured post-incident review. Solid understanding of AWS platform security: IAM, CloudTrail, GuardDuty, Security Hub, VPC Flow Logs, container and Kubernetes security, and cloud incident response. Diverse hands-on experience across the security stack: EDR ( CrowdStrike or similar), SWG/CASB ( Netskope, Zscaler, or similar), email security gateways, SaaS security posture tooling, and threat intelligence platforms. Experience leading or contributing to threat hunting, insider threat, purple team, and phishing analysis programs, with detections mapped to MITRE ATT&CK. Experience managing an MSSP or MDR partner, including SLAs, escalation design, and quality governance. Scripting and automation (Python, Bash, PowerShell) and fluency in at least one SIEM query language (e.g., KQL, SPL, DataPrime, Lucene, or SQL) for hunting, detection, and SOAR development. Familiarity with AI solutions such as Claude and Gemini, and comfortable using MCP solutions and agentic workflows in security operations. Comfortable leading a globally distributed team, flexible to meet team members outside standard EST hours, and available as the escalation point for Sev-1 incidents outside working hours. Excellent English in both verbal and written communication, with the ability to brief executives during an incident and coach analysts through one. Advantages CISSP or CISM; GIAC GCIH, GCFA, or GCDA; AWS Certified Security – Specialty are good to have. Experience in fintech, payments, or other regulated environments (SOC 2, ISO 27001, PCI DSS). Total Rewards Our workforce deserves fair and competitive pay that meets them where they are. With scalable benefits, rewards, and perks, our total rewards programs reflect our commitment to inclusivity and access for all. Our salary range reflects gross base salary. For commercial roles with commission eligibility, this figure represents On-Target Earnings (OTE), inclusive of base salary and target commission. Salary ranges are quoted in USD as a consistent global reference. Your offer will be localized to your country's currency using a market-aligned conversion. Final pay is based on objective, job-related criteria including experience, skills, and location. We don't ask about salary history. Offers are based on the role and what you bring to it. Some things you'll enjoy Stock grant opportunities dependent on your role, employment status and location Additional perks and benefits based on your employment status and country Optional flexible working office membership, with IWG At Deel, we're an equal-opportunity employer that values diversity and positively encourage applications from suitably qualified and eligible candidates regardless of race, religion, sex, national origin, gender, sexual orientation, age, marital status, veteran status, disability status, pregnancy or maternity or other applicable legally protected characteristics. Unless otherwise agreed, we will communicate with job applicants using Deel-specific emails, which include @ deel.com and other acquired company emails like @ payspace.com and @ paygroup.com. You can view the most up-to-date job listings at Deel by visiting our careers page. Deel welcomes persons with disabilities to apply to any of our open roles. We will provide application and/or interview accommodations on request throughout the recruitment, selection and assessment process for applicants with disabilities or other needs. If you require application and/or interview accommodations, please inform our Talent Acquisition Team via email ( recruiting@deel.com ) and a team member will be in touch to ensure your equal participation. As part of our hiring process, we primarily rely on interviews and role-related assessments. In limited cases, we may also consider informal background information relevant to the role, in line with our privacy and fairness obligations. This application process may utilise Automated Employment Decision Tools (AEDT) and AI systems to assist in evaluating candidates based on experience level, technical skills and qualifications. This processing is conducted in compliance with applicable Data Protection, AI Governance and Labour Laws. We ensure human oversight is maintained in all final hiring decisions. Your personal data is not used to train AI models. For more information on how we process your personal data, please see our Recruitment Privacy Policy. For NYC Residents: In accordance with NYC Local Law 144, an independent bias audit has been conducted on AEDT

Apply at jobs.deel.com