Manager, Security Operations
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
About the job
Responsibilities
- Lead and grow a global Security Operations team.
- Define the team’s security operations strategy and implement robust security protocols.
- Leverage AI to improve team processes and the maturity of the security program.
- Lead incident response from detection and remediation through prevention, including serving as incident commander.
- Develop and implement processes for the security operations program.
- Identify emerging technologies and threats, and plan technology-driven approaches to address new risks.
- Configure, monitor, and maintain security tools and infrastructure.
- Partner cross-functionally to maintain compliance and improve security maturity.
Requirements
- Strong leadership experience in security and the ability to lead a global team transparently and trustfully.
- Strong security operations experience in SaaS and cloud environments.
- Experience developing detection and observability strategies for security events.
- Familiarity with GDPR, ISO 27001, NIST 800-53, and related security standards.
- Experience leveraging AI to improve security processes.
- Experience with incident response and acting as incident commander.
- Ability to assess security risks across business and technical impacts and prioritize remediation against business objectives.
- Ability to build trust and strong partnerships with internal teams.
- Curiosity, sound judgment, and willingness to apply AI responsibly.
Compensation & Benefits
- Base salary range: $178,000–$209,000.
- Equity and industry-competitive compensation.
- Medical, dental, and vision coverage, with employee-only premiums covered for most medical plans.
- 16 weeks of paid parental leave.
- Health and wellness stipend.
- Remote workspace, internet, and cellphone stipends.
- Commuter benefits for San Francisco and New York City office reporters.
- Family planning benefits.
- Matching 401(k) contribution with immediate vesting.
- Flexible PTO, 80 hours of sick time, and 11 company-paid holidays.
- Virtual team-building activities, lunch-and-learns, and company-wide events.
Skills
Security Operations, Incident Response, Security Engineering, Cloud Security, Saas Security, AI, Security Controls, Detection Engineering, Observability, GDPR, ISO 27001, Nist 800-53, Risk Assessment, Security Tools, Security Infrastructure
Similar jobs
Security Engineering jobsOwn and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.
The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.
Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.
Leads vulnerability management and application-security initiatives across the technology stack, securing operating-system images, open-source dependencies, CI/CD pipelines, containers, and cloud-native systems. Requires 5+ years of application-security experience, coding ability, and expertise in vulnerability-scanning practices.