SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Altruist is building an AI platform for wealth management professionals, transforming the multi-trillion dollar wealth management industry. The company partners with financial advisors nationwide to help them grow, optimize resources, and deliver superior outcomes for clients.
You will lead the Security Operations and Detection & Response team for a self-clearing broker-dealer, building and managing a 24x7 security monitoring program that protects the platform and advisors' clients. This is a hands-on leadership role where you'll own the full incident response lifecycle—from detection through containment, eradication, recovery, and post-incident review.
Key responsibilities include:
- Leading, mentoring, and growing the security operations team while setting priorities and career development paths
- Owning the 24x7 security monitoring strategy across managed detection & response providers
- Running the end-to-end incident response program
- Defining and reporting SecOps metrics and SLAs (MTTD/MTTR, alert quality, coverage) to security and executive leadership
- Maturing detection engineering, threat intelligence ingestion, and response automation (SOAR) capabilities
- Driving tabletop and purple-team exercises; partnering with Cloud, IT, and Engineering teams to close security gaps
- Managing the security operations tooling stack roadmap and day-to-day operations
You bring 6+ years in security operations with at least 2+ years leading or managing a SOC or detection & response team. You have hands-on incident response experience in cloud-first environments, depth with SIEM tools (Datadog/Splunk), EDR/MDR solutions (CrowdStrike/SentinelOne), and AWS cloud telemetry. Experience managing MDR/MSSP and IR retainer relationships is valued. You're technically savvy across modern cloud and detection stacks (AWS, Kubernetes, SIEM query languages, detection-as-code, Terraform). A B.A./B.S. in Computer Science, Computer Engineering, Information Security, or equivalent experience is required.
The role is hybrid with three days per week onsite in either the San Francisco FiDi or Culver City office.