Blue Team Operations and Tool Management * Lead and oversee the management, configuration, and ... SIEM (e.g., Splunk, PANW, or Azure Sentinel) * EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft ...
Blue Team Operations and Tool Management * Lead and oversee the management, configuration, and ... SIEM (e.g., Splunk, PANW, or Azure Sentinel) * EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft ...
Cybersecurity Lead
San Jose, CA · On-site
Blue Team Operations and Tool Management * Lead and oversee the management, configuration, and ... SIEM (e.g., Splunk, PANW, or Azure Sentinel) * EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft ...
Cybersecurity Lead
San Jose, CA · On-site
Blue Team Operations and Tool Management * Lead and oversee the management, configuration, and ... SIEM (e.g., Splunk, PANW, or Azure Sentinel) * EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft ...
Sr. Incident Response Manager
Irvine, CA · On-site
... blue-team capabilities across email, endpoint, identity, cloud, and network environments. In ... Security Information and Event Management (SIEM)- e.g., Microsoft Sentinel * Security Orchestration ...
Sr. Incident Response Manager
Irvine, CA · On-site
... blue-team capabilities across email, endpoint, identity, cloud, and network environments. In ... Security Information and Event Management (SIEM)- e.g., Microsoft Sentinel * Security Orchestration ...
... blue-team capabilities across email, endpoint, identity, cloud, and network environments. In ... Security Information and Event Management (SIEM)- e.g., Microsoft Sentinel * Security Orchestration ...
... blue-team capabilities across email, endpoint, identity, cloud, and network environments. In ... Security Information and Event Management (SIEM)- e.g., Microsoft Sentinel * Security Orchestration ...
... blue-team capabilities across email, endpoint, identity, cloud, and network environments. In ... Security Information and Event Management (SIEM)- e.g., Microsoft Sentinel * Security Orchestration ...
... blue-team capabilities across email, endpoint, identity, cloud, and network environments. In ... Security Information and Event Management (SIEM)- e.g., Microsoft Sentinel * Security Orchestration ...
Space Operations Instructor
$57K - $75K/yr
Participation in USSPACECOM exercises (e.g., Global Sentinel, Schriever Wargame) or relevant red team/blue team activities * Previous assignment at, or direct support to, the Combined Space Ops ...
Space Operations Instructor
$57K - $75K/yr
Participation in USSPACECOM exercises (e.g., Global Sentinel, Schriever Wargame) or relevant red team/blue team activities * Previous assignment at, or direct support to, the Combined Space Ops ...
Space Operations Instructor
Lompoc, CA · On-site
$57K - $75K/yr
Participation in USSPACECOM exercises (e.g., Global Sentinel, Schriever Wargame) or relevant red team/blue team activities * Previous assignment at, or direct support to, the Combined Space Ops ...
Quick apply
Space Operations Instructor
Lompoc, CA · On-site
$57K - $75K/yr
Participation in USSPACECOM exercises (e.g., Global Sentinel, Schriever Wargame) or relevant red team/blue team activities * Previous assignment at, or direct support to, the Combined Space Ops ...
Space Operations Instructor
Lompoc, CA · On-site
$57K - $75K/yr
Participation in USSPACECOM exercises (e.g., Global Sentinel, Schriever Wargame) or relevant red team/blue team activities * Previous assignment at, or direct support to, the Combined Space Ops ...
Space Operations Instructor
Lompoc, CA · On-site
$57K - $75K/yr
Participation in USSPACECOM exercises (e.g., Global Sentinel, Schriever Wargame) or relevant red team/blue team activities * Previous assignment at, or direct support to, the Combined Space Ops ...
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Full Stack Developer
San Diego, CA · On-site +1
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Full Stack Developer
San Diego, CA · On-site +1
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Full Stack Developer
San Diego, CA · On-site
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Quick apply
Full Stack Developer
San Diego, CA · On-site
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Quick apply
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Software Engineering Manager
San Diego, CA · On-site +1
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Software Engineering Manager
San Diego, CA · On-site +1
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Full Stack Developer
San Diego, CA · On-site
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
Full Stack Developer
San Diego, CA · On-site
Experience working with a code monitoring tool such as Sentinel or Data Dog * Creative problem ... largest blue-chip banks and financial institutions. We are a high-performing team pursuing ...
DevOps Engineer
Sunnyvale, CA · On-site
$61.50 - $84.25/hr
... via blue/green, canary, and rolling deployments with feature flags and automated rollback. • ... or Sentinel). • Run Kubernetes (EKS, AKS, or self-managed on Proxmox) with Helm and Kustomize ...
DevOps Engineer
Sunnyvale, CA · On-site
$61.50 - $84.25/hr
... via blue/green, canary, and rolling deployments with feature flags and automated rollback. • ... or Sentinel). • Run Kubernetes (EKS, AKS, or self-managed on Proxmox) with Helm and Kustomize ...
DevOps Engineer
Sunnyvale, CA · On-site
$110K - $170K/yr
Ship via blue/green, canary, and rolling deployments with feature flags and automated rollback ... or Sentinel). * Run Kubernetes (EKS, AKS, or self-managed on Proxmox) with Helm and Kustomize.
DevOps Engineer
Sunnyvale, CA · On-site
$110K - $170K/yr
Ship via blue/green, canary, and rolling deployments with feature flags and automated rollback ... or Sentinel). * Run Kubernetes (EKS, AKS, or self-managed on Proxmox) with Helm and Kustomize.
DevOps Engineer
Sunnyvale, CA · On-site
$61.50 - $84.25/hr
... via blue/green, canary, and rolling deployments with feature flags and automated rollback. • ... or Sentinel). • Run Kubernetes (EKS, AKS, or self-managed on Proxmox) with Helm and Kustomize ...
DevOps Engineer
Sunnyvale, CA · On-site
$61.50 - $84.25/hr
... via blue/green, canary, and rolling deployments with feature flags and automated rollback. • ... or Sentinel). • Run Kubernetes (EKS, AKS, or self-managed on Proxmox) with Helm and Kustomize ...
Sentinel Blue information
What are some typical challenges faced by professionals in a Sentinel Blue team, and how can new hires best prepare for them?
What are the key skills and qualifications needed to thrive as a Sentinel Blue, and why are they important?
What are Sentinel Blue professionals?
What is the difference between Sentinel Blue vs Security Guard?
| Aspect | Sentinel Blue | Security Guard |
|---|---|---|
| Certifications | Typically requires security licenses and specialized training | Requires security licenses, basic training often sufficient |
| Work Environment | Corporate, high-security facilities, or specialized environments | Various settings including retail, events, and residential areas |
| Employer & Industry Usage | Used by private security firms, corporations, and government agencies | Commonly employed by retail stores, malls, and private clients |
Sentinel Blue often refers to a specialized security role with advanced training and specific industry applications, whereas Security Guard is a broader term for personnel providing general security services across various environments. Both roles require licensing, but Sentinel Blue typically involves more technical or high-security responsibilities.
Full-time
Re-posted 29 days ago
Job description
The Cybersecurity Lead serves as a hands-on technical leader responsible for uniting offensive and defensive security operations to continually improve the company's ability to detect, respond to, and recover from cyber threats.
This role will lead the Blue Team in managing and enhancing security monitoring tools, detection pipelines, and incident response processes, while also coordinating Red Team simulations that measure and improve the company's defensive posture.
Reporting to the Director of Cybersecurity, this leader bridges strategy and execution driving the mission to emulate adversaries, strengthen controls, and transform findings into actionable defense improvements.
Key Responsibilities:
Blue Team Operations and Tool Management
Lead and oversee the management, configuration, and tuning of security detection and response platforms, including:
SIEM (e.g., Splunk, PANW, or Azure Sentinel)
EDR/XDR (e.g., CrowdStrike, SentinelOne, Microsoft Defender)
SOAR automation platforms
Network IDS/IPS, NDR, and threat intelligence platforms (TIPs)
Ensure all detection tools are integrated for end-to-end visibility across endpoints, cloud environments, and production systems
Define standards for log collection, parsing, and correlation to enhance alert accuracy and reduce false positives
Drive continuous tuning of detection rules, signatures, and use cases to align with MITRE ATT&CK and emerging threats
Collaborate with IT and Engineering teams to ensure security telemetry is fully integrated into cloud and CI/CD environments
Oversee threat hunting, alert triage, and incident response playbook execution across the security stack
Partner with DevOps and infrastructure teams to embed security monitoring hooks into hybrid environments and new deployments
Red Team and Offensive Security
Design and conduct controlled adversary emulation exercises to test detection and response capabilities
Execute attack chains including phishing, privilege escalation, persistence, and lateral movement using real-world TTPs
Develop and maintain custom adversary scripts and payloads to simulate targeted threats
Provide detailed post-exercise reports with actionable defensive improvement recommendations
Collaborate with Blue Team engineers to operationalize detections based on Red Team findings
Incident Response and Continuous Improvement
Lead or co-lead major incident response efforts, coordinating containment, investigation, and recovery
Build and maintain detailed incident response runbooks, integrating lessons learned from purple team exercises
Conduct root cause analysis and lead retrospectives that drive measurable improvements in detection and resilience
Integrate threat intelligence and forensic insights into detection content and defensive playbooks.
Plan and execute adversarial simulations that validate threat detection, alert fidelity, and incident response readiness
Develop the roadmap for continuous improvement of detection coverage, response automation, and control validation
Serve as a technical escalation point for complex investigations, guiding both Red and Blue Team staff
Translate technical results into executive-level insights that demonstrate risk reduction and readiness improvement
Qualifications:
Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience)
8+ years of cybersecurity experience, with proven leadership across Blue, Red, or Purple Team operations
Demonstrated ownership of enterprise security detection tools, including SIEM, EDR/XDR, SOAR, and threat intel platforms
Strong understanding of MITRE ATT&CK, Cyber Kill Chain, and threat emulation frameworks.
Deep technical expertise in one or more of the following areas:
Endpoint and network forensics
Cloud security monitoring (AWS, Azure, GCP)
Scripting and automation (Python, PowerShell, Bash)
Security engineering in hybrid or production environments
Proven ability to lead incident response and purple team exercises from start to finish
Certifications such as OSCP, GCFA, GCIH, GPEN, GXPN, or GCTI highly desirable
Strong communication and leadership skills, with ability to engage both executive stakeholders and technical teams
Preferred Experience:
Experience in enterprise or production-scale environments, ideally within SaaS, networking, or hybrid cloud infrastructures
Familiarity with DevSecOps practices, CI/CD pipeline security, and cloud-native monitoring
Prior experience mentoring Blue Team analysts and managing tool life cycles and vendor relationships
Exposure to purple team automation frameworks (e.g., AttackIQ, Caldera, Scythe)
AI Use Guidelines for Interviews:Our interviews are designed to reflect your own skills and thinking. The use of AI or recording tools during live interviews is not permitted unless explicitly invited by the interviewer or approved in advance as part of a reasonable accommodation. If these tools are used inappropriately or in a way that misrepresents your work, your application may not move forward in the process.
Why Join Us:
This role sits at the intersection of offensive and defensive cybersecurity where every exercise directly strengthens the company's real-world resilience. As Cybersecurity Lead, you'll shape how attacks are simulated, how detections evolve, and how incidents are contained ensuring the organization stays one step ahead of its adversaries.
A10 Networks is an equal opportunity employer and a VEVRAA federal subcontractor. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. A10 also complies with all applicable state and local laws governing nondiscrimination in employment.#LI-AN1 - HybridTargeted compensation guideline: $140,000 - $185,000. Compensation will vary based on number of factors, including market demand for specific skills, role type, job level, and individual qualifications. Final salary offers are determined by considerations including, but not limited to, subject matter expertise, demonstrated skill level, relevant experience, geographic location, education, certifications, and training.