Manage insider and external threat incident analysis and triage from initial indicators through scoping, forensic review, evidence preservation, case disposition, and root-cause analysis, producing defensible investigative narratives for executive, legal, and compliance review. Drive changes to systems and processes based on incident and risk learnings that cross and impact other teams. Define and drive the requirements, architecture, operating model, and prioritized engineering backlog for an AI-enabled QSIT SOC, covering signal enrichment, triage, investigation, response recommendations, analyst-in-the-loop controls, auditability, and sensitive-data handling. Translate AI SOC needs into measurable capabilities and acceptance criteria, evaluate first- and third-party solutions, guide implementation, and assess operational effectiveness, risk, and readiness for production use. Doctorate in Statistics, Mathematics, Computer Science, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat modeling, cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), or operations incident response Doctorate in Statistics, Mathematics, Computer Science, or related field AND 5+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, or related field AND 8+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, or related field AND 12+ years experience in software development lifecycle, large scale computing, threat modeling, cyber security, or anomaly detection OR equivalent experience. CISSP CISA CISM SANS OSCP Security+ 6+ years of experience in cybersecurity, security operations, incident response, insider threat, threat analytics, security information and event management (SIEM), or equivalent experience. Demonstrated experience leading complex security incidents end-to-end, including technical investigation, containment, recovery, root-cause analysis, executive communication, and post-incident remediation. CISSP certification or other relevant (CISA, CISM, SANS GCIA, GCIH, OSCP, Security+). Experience collaborating with corporate insider threat, investigations, legal, or trade compliance functions; exposure to dedicated insider threat platforms such as Purview, DTEX, Proofpoint ITM, Magnet Axiom, or Forcepoint. Experience designing, deploying, or evaluating agentic AI or LLM-based automation in a security operations context is strongly desired; familiarity with post-quantum cryptography concepts and CNSA 2.0. Experience or interest in the specific challenges of protecting strategic research programs from sustained external targeting; familiarity with export control (EAR / ITAR) and government program environments.
QUANTUM ROLE CONTEXT | Appended by Quantum.Jobs v2
Role context:
This role exists to protect critical organizational infrastructure, sensitive IP, and technical operations from complex cybersecurity threats. Positioned within the security engineering function, it connects live threat detection, incident triage, and forensic investigation with overarching system architecture. Professionals in this capacity design automated detection workflows, establish incident response protocols, and refine operational models to defend core assets. They collaborate with legal, compliance, and engineering teams to ensure regulatory alignment and build resilient defenses across distributed computing environments.
Quantum ecosystem relevance:
The position supports the quantum ecosystem by securing sensitive quantum research programs and preparing organizational infrastructure for emerging post-quantum cryptographic standards. As quantum computing advances, protecting intellectual property from targeted external threats and insider risks becomes critical. Furthermore, implementing post-quantum cryptography frameworks ensures that high-value systems remain resilient against future quantum-enabled decryption techniques. Positioned within the protective infrastructure layer, this function helps safeguard long-term technological assets and specialized research operations.
Capability signals:
- Deep technical knowledge of security operations center architecture and incident response frameworks
- Experience integrating advanced artificial intelligence models into automated threat detection workflows
- Expertise in forensic investigation, root-cause analysis, and threat telemetry enrichment methods
- Familiarity with post-quantum cryptography transition standards and cryptographic migration planning
- Understanding of compliance standards, export control regulations, and trade governance protocols