HealthEquity administers Health Savings Accounts (HSAs), FSAs, HRAs, COBRA, and
commuter benefits for millions of members nationwide. Our Cyber Defense & Engineering
team protects the systems and data that members and employers rely on every day.
Position Summary
The Cyber Ops Lead I SOC Lead is responsible for the day-to-day operation Of HealthEquity's
Security Operations Center. This role owns the intake, triage, and resolution Of the cases,
alerts, and issues flowing into the team, and acts as the primary point of coordination when
security work intersects with Technology Operations. The ideal teammate combines hands-on
SOC leadership with the organizational discipline to keep queues moving, escalations timely,
and stakeholders informed.
This is an on-site role based at our Draper, UT office
Key Responsibilities
Case & Queue Management
• Own the SOC case queue: triage incoming alerts, tickets, and requests; assign priority and
ownership; track cases through to resolution.
• Maintain SLAs for case handling and escalation; identify and clear bottlenecks before they
become backlogs.
• Ensure consistent documentation, categorization, and closure quality across all cases.
SOC Leadership & Operations
Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident
response.
• Coordinate shift coverage and on-call rotations to maintain continuous monitoring.
• Serve as a senior escalation point for analysts on complex or ambiguous cases.
• Drive continuous improvement Of detection content, playbooks, and standard operating
procedures.
Partnering with Technology Operations
• Act as the primary liaison between Cyber Defense and Tech Operations on issues that span
both teams (eg., system changes, outages, access requests, infrastructure-related findings).
• Coordinate response and remediation activities that require Tech Operations involvement,
ensuring clear handoffs and shared visibility into status.
• Participate in change management and operational reviews where security input is needed.
Incident Response
• Support incident response efforts, including initial triage, containment recommendations, and
coordination across teams during active incidents.
• Contribute to post-incident reviews and help translate lessons learned into process or tooling
improvements.
Mentorship & Team Development
• Mentor and provide day-to-day guidance to SOC analysts; support onboarding and skills
development.
• Help set expectations for case quality, communication, and escalation practices.
Reporting & Metrics
• Track and report on SOC operational metrics (case volume, time-to-triage, time-to-resolution,
escalation rates) to the Director, Cyber Defense & Strategy.
• Flag trends or recurring issues that indicate a need for process, tooling, or staffing changes.
Required Qualifications
5+ years of experience in a Security Operations Center or similar cyber defense role, including
at least 1-2 years in a lead, senior analyst, or shift-lead capacity
• Demonstrated experience managing case/ticket queues and driving them to resolution in a
fast-paced environment.
• Working knowledge Of SIEM, EDR, and case/ticket management tooling
Solid understanding Of incident response fundamentals (triage, containment, escalation).
• Comfortable working cross-functionally with Technology Operations, IT, and Engineering
teams.
• Strong written and verbal communication skills; able to translate technical detail for varied
audiences.
• Willingness and ability to work on-site in Draper, UT, including participation in on-call/shift
coverage as needed.
Preferred Qualifications –
• Experience in a regulated industry (healthcare, financial services, or similar) handling
sensitive data.
• Relevant certifications such as GCIH, GCIA, Security+, CySA+, or equivalent.
• Familiarity with cloud environments (AWSlAzure) and common cloud security tooling.
• Prior experience building or refining SOC playbooks, runbooks, or standard operating
procedures.
What Success Looks Like in the First 6 Months
• SOC case queue is triaged consistently with clear ownership and no unexplained aging
• Escalation paths to Tech Operations are documented and running smoothly, with fewer
dropped handoffs.
• Analyst team has clear expectations, regular feedback, and improving case quality.
• Director, Cyber Defense & Strategy has reliable visibility into SOC health through regular
reporting