Lead, Agentic SecOps
"We are rewriting how Security Operations is practised."
ABOUT TRENCH
The attack landscape is changing faster than traditional Security Operations can keep up. AI is changing the speed and scale of attacks, while security teams continue to operate with more tools, more alerts, more rules and more manual investigation. We believe this model is reaching its limit. Trench is building an agentic approach to Security Operations where AI agents take on detection, investigation and response, enabling security teams to operate with greater speed, coverage and autonomy.
We are looking for a Lead, Agentic SecOps who believes in this transformation and wants to drive it with customers. This is not a traditional SOC leadership role. You will help forward-looking security teams move from the traditional SOC model to an agentic operating model and drive measurable transformation outcomes.
THE ROLE
You will work at the intersection of Security Operations, AI agents and customer transformation. You will understand how a customer's SOC operates today, identify where traditional processes create friction, design the agentic operating model and work with the customer to put it into production. You will be part security operator, part transformation leader and part customer advisor.
WHAT YOU'LL OWN
- Customer transformation: Assess existing SOC operations across people, processes, tools and workflows. Define what should be automated, redesigned or eliminated, and lead the transition to an agentic model.
- Agentic SecOps workflows: Design and operationalize workflows across detection, triage, threat hunting, investigation, threat intelligence and response.
- Hands-on security operations: Investigate real threats, validate detections, review AI-generated investigations, tune workflows and identify gaps. You should be comfortable going deep into customer environments.
- Human + Agent operating model: Help customers determine what agents should handle autonomously, where humans should remain in the loop and how trust and control should be maintained.
- Transformation outcomes: Drive measurable improvements in alert noise, investigation effort, detection coverage, response time, analyst workload and autonomous resolution.
- Product feedback loop: Work closely with Product and Engineering to turn customer learnings, security gaps and emerging attack patterns into better agents and workflows.
MINDSET
- You believe the SOC is changing. The answer to increasing security complexity is not simply more analysts and more tools.
- You are an operator first. You understand the reality behind alert queues, false positives, escalations, investigation fatigue and detection gaps.
- You challenge the status quo. You understand the existing SOC deeply enough to know what should remain, what should change and what should disappear.
- You care about outcomes. Automation is not the goal. A fundamentally better Security Operations function is.
- You are comfortable creating the playbook. Agentic SecOps is still being defined. You should enjoy operating in ambiguity, experimenting and learning from production environments.
- Most importantly, you believe in the transformation and want to drive it.
WHAT WE'RE LOOKING FOR
- 6 to 12 years in Security Operations, detection engineering, threat hunting, incident response or security engineering.
- Strong hands-on understanding of modern SOC operations.
- Experience with SIEM, SOAR, XDR, EDR, cloud, identity and security telemetry.
- Strong detection engineering, investigation and incident response skills.
- Fluency with MITRE ATT&CK and modern threat hunting.
- Experience working directly with security teams, SOC leaders or CISOs.
- Strong understanding of security automation and where human judgement is still required.
- Excellent customer-facing communication and ownership mindset.
- Strong curiosity around AI agents and their application to Security Operations.
BONUS POINTS
- Experience operating or transforming a SOC.
- Splunk, Microsoft Sentinel or other SIEM experience.
- SOAR and security automation experience.
- AI or LLM-based security workflow experience.
- MSSP, consulting, threat intelligence or purple-team experience.
WHY THIS ROLE
You will help define what an Agentic SOC actually looks like in production. You will work with customers who are ready to rethink how Security Operations should work and help answer a fundamental question: What should a SOC look like when AI agents can investigate, reason and respond at machine speed?
We are not simply building another security product. We are building the next operating model for Security Operations.
HOW TO APPLY
Send your application to career@trenchsecurity.ai with a short note about one of these:
- A SOC transformation you have led
- A security workflow you have automated
- A difficult detection or investigation problem you solved
- Your view on what the SOC should look like in the age of AI agents
No formal cover letter needed. Show us how you think. Show us how you operate.