Principal Security Architect - Cyber Operations and Incident Response
Job description
Join the transformative team at City of Hope, where we're changing lives and making a real difference in the fight against cancer, diabetes, and other life-threatening illnesses. City of Hope’s growing national system includes its Los Angeles campus, a network of clinical care locations across Southern California, a new cancer center in Orange County, California, and treatment facilities in Atlanta, Chicago and Phoenix. Our dedicated and compassionate employees are driven by a common mission\: To deliver the cures of tomorrow to the people who need them today.
Position Summary\:
The Principal Security Architect, Cyber Operations and Incident Response serves as the senior technical authority responsible for the architecture, design, and continuous improvement of enterprise detection, monitoring, threat detection, incident response, and cyber defense capabilities. This role establishes security monitoring strategies, incident response architectures, detection engineering standards, threat intelligence integration, and cyber resilience capabilities that protect clinical, research, business, and technology environments.
The position partners closely with SOC leadership, Incident Response teams, Threat Intelligence, Infrastructure, Identity, Cloud, and Engineering teams to ensure cybersecurity controls generate actionable visibility, effective detection coverage, rapid response capabilities, and measurable risk reduction across enterprise environments.
As a successful candidate, you will\:
- Define and maintain enterprise architecture, standards, and roadmaps for SOC operations, SIEM, SOAR, UEBA, threat intelligence, digital forensics, incident response, and cyber defense platforms.
- Lead the design and optimization of enterprise detection engineering programs, security monitoring capabilities, threat hunting frameworks, use-case development, and adversary detection strategies aligned with MITRE ATT&CK and industry best practices.
- Architect and enhance incident response, forensic investigation, cyber resilience, ransomware recovery, and crisis management capabilities across enterprise environments.
- Lead assessment and improvement of security telemetry, log management, detection coverage, alert fidelity, incident workflows, automation opportunities, and response processes.
- Partner with security engineering teams to ensure security technologies generate adequate logging, visibility, and actionable telemetry to support detection and response objectives.
- Provide strategic leadership and technical guidance to SOC analysts, incident responders, threat hunters, detection engineers, and management teams. Develop documentation, standards, executive metrics, and board-level reporting.
- Evaluate emerging threats, adversary techniques, AI-assisted attack methods, security operations technologies, and threat intelligence capabilities to enhance organizational cyber defense effectiveness.
- Follows established City of Hope and department policies, procedures, objectives, performance improvement, attendance, safety, environmental, and infection control guidelines, including adherence to the workplace code of Conduct and Compliance Plan.
- Practices a high level of integrity and honesty in maintaining confidentiality.
- Performs other related duties as assigned or requested.
Skills mentioned
Apply for this job
Use the application link supplied with this listing to apply to City of Hope. Check the destination before entering personal information.

