Island is the ideal environment for enterprise work, where security is everywhere without ever getting in the way.
The Island Enterprise Platform unifies AI enablement, network access, data protection, identity, and endpoint control into one coherent workspace—so organizations get universal visibility and control, and users get a fast, fluid, beautifully simple experience. It's not just a better way to secure work. It's a better way to work. Backed by investors like Coatue Management, Insight Partners, Sequoia Capital and Cyberstarts, and trusted by some of the largest, most respected enterprises on the planet, Island is redefining what the modern workplace can be.
Come join us in building something that's already changing how the world works, we’re always looking for world-class human beings (not resumes) to join the movement.
As a SecOps Lead at Island, you will own the core of the security operations function: detection, response, automation, and the processes that connect them. You will guide incident response from first alert through post-mortem, keeping efforts structured and stakeholders informed along the way. You will shape how the team detects, triages, and resolves, and communicate that work clearly to leadership, engineering, and customers.
This is a hands-on role with broad ownership. You should be comfortable writing a detection rule, coordinating a live incident, and walking stakeholders through a post-incident review.
Key Responsibilities
- Lead Incident Response: Own the end-to-end incident response lifecycle across Island's infrastructure and enterprise browser platform, driving investigations, coordinating responders, and ensuring timely resolution and post-incident improvements.
- Own the IR Framework: Build, maintain, and continuously improve incident response processes, including runbooks, severity definitions, escalation paths, on-call procedures, and communication standards.
- Drive Detection Engineering: Design, implement, and continuously improve high-fidelity detections across SIEM, EDR, cloud, and endpoint security platforms, closing visibility gaps and strengthening detection coverage.
- Automate Security Operations: Build automation and AI-driven workflows that streamline triage, investigation, enrichment, and response, reducing manual effort and improving operational efficiency.
- Threat Hunting & Research: Proactively hunt for threats, leverage threat intelligence, and identify emerging attack techniques relevant to modern enterprise environments.
- Own Security Operations: Serve as the technical owner for Security Operations within Product Security, driving strategy, setting best practices, and continuously improving detection and response capabilities.
- Partner Across Engineering: Collaborate closely with Engineering, IT, Infrastructure, and Compliance teams to embed security into new services, infrastructure changes, FedRAMP initiatives, and customer-facing security requirements.
- Communicate During Incidents: Provide clear, timely communication throughout incident response, keeping technical teams, leadership, and stakeholders aligned on impact, progress, risks, and next steps.