Senior Manager, Security Operations
New
J
JobgetherSecurity & IT
Remote work arrangement within the United States.Full-TimeManager
Salary$140,000–$200,000 USD
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years of experience in security operations, incident response, detection engineering, threat intelligence, or a closely related field, including 3+ years leading teams.
- Required Skills
- AWSArtificial IntelligenceKubernetes
Requirements
- 8+ years of experience in security operations, incident response, detection engineering, threat intelligence, or a closely related field.
- 3+ years of experience leading teams.
- Demonstrated hands-on security expertise, including writing detections, conducting investigations, and building security automation.
- Experience building or substantially rebuilding a SOC function.
- Strong experience across both production/cloud security monitoring and corporate/enterprise security operations.
- Deep knowledge of modern security operations technologies, including SIEM, security data platforms, EDR, and SOAR.
- Strong detection engineering capabilities with the ability to develop and improve detection content.
- Experience with cloud and container security monitoring (AWS and Kubernetes strongly preferred).
- Understanding of identity-focused attack paths involving SSO, OAuth, session compromise, MFA bypass, and privilege escalation.
- Proven incident command experience during significant security events.
- Demonstrated use of AI in security operations (triage, enrichment, detection creation, investigation support, or reporting).
- Experience designing 24/7 security coverage and managing globally distributed teams.
Responsibilities
- Build and grow the SOC operating model, including coverage structures, runbooks, escalation paths, hiring, career development, and the appropriate 24/7 coverage approach.
- Define and own the detection strategy across production, cloud, corporate, and enterprise environments, explicitly mapping coverage to MITRE ATT&CK.
- Expand security monitoring into cloud and production workloads in partnership with Platform Engineering.
- Lead 24/7 incident response and serve as incident commander for significant security events.
- Own the security telemetry and analytics platform, including data collection, normalization, enrichment, retention, cost management, and operational performance measurement.
- Establish metrics covering MTTD, MTTR, detection coverage, alert precision, and automation rates.
- Develop a structured, hypothesis-driven threat hunting program and establish threat intelligence capabilities.
- Own EDR across the corporate environment and partner with Platform Engineering on runtime and workload protection for production systems.
- Design and continuously improve an AI-first SOC operating model, personally developing automation for triage, enrichment, correlation, investigation, and reporting.
View Full Description & ApplyYou'll be redirected to the employer's site