Manager, Security Operations Center
Manages global SOC operations, analyst development, shift coverage, quality assurance, and process improvement for 24/7 incident response. Requires 5+ years of SOC analyst experience, Windows forensics expertise, and at least 2 years leading or managing security operations teams.
About the job
Responsibilities
- Design, implement, and enforce processes, workflows, and playbooks that improve Security Operations Center productivity and reduce analyst burnout.
- Manage shift coverage to maintain 24/7 operations throughout the year.
- Hold weekly one-on-one meetings with analysts to communicate initiatives, gather and provide feedback, and support career growth.
- Contribute to analyst training programs covering digital forensics, incident response, malware analysis, detection engineering, threat hunting, and automation.
- Collaborate with Product teams to prioritize capabilities that augment analyst effectiveness.
- Maintain regional quality assurance accountability.
- Partner with Support to streamline workflows for customer requests requiring SOC analysis.
- Mature processes and relationships with Tactical Response, Threat Hunting, and Detection Engineering teams.
- Provide technical leadership to SOC analysts and communicate organizational goals.
- Advise Marketing, Sales, Support, Product, and other stakeholders.
- Develop, track, and report Objectives and Key Results for SOC initiatives.
- Operationalize new technologies and services.
- Participate in webinars and in-person public speaking engagements.
Requirements
- Experience leading diverse cybersecurity teams across security operations, digital forensics, incident response, malware analysis, threat hunting, and detection engineering.
- 5+ years of Security Analyst experience in a global 24/7 Security Operations Center, with a focus on Windows forensics.
- 2+ years of team lead or management experience in a global operations center or incident response role; MSSP, MDR, or incident response service experience preferred.
- Active participation in the information security community through conferences or public contributions.
- Current knowledge of threat actor tradecraft, detection techniques, and security operations.
- Ability to document workflows using process diagrams and operating procedures.
- Ability to communicate technical concepts to stakeholders with varying technical backgrounds.
- Experience leading initiatives or projects through delegation and accountability.
- Data-driven approach and familiarity with data science concepts.
Compensation and Benefits
- $165,000–$185,000 base salary plus bonus and equity.
- 100% remote work environment.
- Paid time off, including vacation, sick time, and holidays.
- 12 weeks of paid parental leave.
- Medical, dental, and vision benefits.
- 401(k) with a 5% contribution regardless of employee contribution.
- Life and disability insurance.
- Stock options for full-time employees.
- $500 one-time home office reimbursement.
- Annual education and professional development allowance.
- $75 USD monthly digital reimbursement.
- Access to coaching and professional growth resources.
Skills
Security Operations, Digital Forensics, Incident Response, Malware Analysis, Threat Hunting, Detection Engineering, Windows Forensics, Process Mapping, Operating Procedures, Data Science
Similar jobs
Security Engineering jobsDevelops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.
The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.
Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.
The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.
Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.