Remote job
Senior Manager, Security Operations
Job details
About this role
Role overview
This is a founding leadership opportunity to build and run a Security Operations Center (SOC) for a large, multi-product technology organization serving nearly 100,000 customers across logistics, construction, energy, manufacturing, retail, and the public sector. Reporting to the CISO, the role owns the full detection-and-response lifecycle across both the production cloud estate (services, APIs, data platforms, and connected-device fleets) and the corporate IT environment (endpoints, identity, SaaS, email, network). Success looks like a small, senior, automation-driven team rather than a traditional tiered analyst model.
Responsibilities
- Stand up and scale the SOC, including operating model, runbooks, escalation paths, hiring plans, and the chosen 24/7 coverage model (in-house follow-the-sun, MDR-augmented, or hybrid) - Define and own the detection strategy end-to-end, treating detection content as code and mapping coverage explicitly to MITRE ATT&CK and an internal threat model - Lead 24/7 incident response across product and enterprise environments, serving as incident commander for significant events and communicating with executives under pressure - Own the security telemetry and analytics platform, including collection, normalization, enrichment, retention, and cost discipline, while measuring MTTD, MTTR, coverage, precision, and automation rate - Build a hypothesis-driven threat hunting program and a tailored threat intelligence function that produces detections, hunts, and hardening priorities - Partner with Platform Engineering to extend detection into production and cloud workloads, with priority coverage for identity-to-cloud pivot paths and unmonitored endpoints or workloads
Requirements
- Senior leadership experience building or substantially transforming a SOC, with hands-on detection engineering capability - Deep familiarity with modern detection-and-response tooling: SIEM or security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry - Strong background in cloud and container security monitoring, with AWS and Kubernetes experience preferred - Solid understanding of identity-centric attack paths across SSO, OAuth, session compromise, MFA bypass, and privilege escalation in SaaS and cloud - Demonstrated incident command experience on significant incidents, with sound escalation judgment and credible executive communication - Concrete, measurable use of AI and automation inside security operations, with examples of what was built, what it replaced, and what changed
Benefits and work setup
- Base compensation range of $140,000–$200,000 USD, with total compensation potentially including equity for certain roles - Benefits include medical, pharmacy, dental, and vision coverage, paid and sick time off, short- and long-term disability, life insurance, and 401(k) contributions, subject to eligibility - Globally distributed team with flexible time-zone coverage; some interviews or onboarding may occur in person at a global office - Must be authorized to access U.S.-export-controlled technology