← Back to Connect Jobs
CONNECT VERIFIED

Senior Manager, Security Operations

Jobgether

US · remote · Full-time

Jobgether

Accountabilities:: Build and grow the SOC operating model, including coverage structures, runbooks, escalation paths, hiring, career development, and the appropriate 24/7 coverage approach. Define and own the detection strategy across production, cloud, corporate, and enterprise environments, explicitly mapping coverage to MITRE ATT&CK and the organization’s threat model. Expand security monitoring into cloud and production workloads in partnership with Platform Engineering, developing detections that identify attack paths across corporate and production environments. Lead 24/7 incident response and serve as incident commander for significant security events, providing clear and composed communication to executives throughout incidents. Own the security telemetry and analytics platform, including data collection, normalization, enrichment, retention, cost management, and operational performance measurement. Establish metrics covering MTTD, MTTR, detection coverage, alert precision, and automation rates to provide an accurate view of SOC effectiveness. Develop a structured, hypothesis-driven threat hunting program and establish threat intelligence capabilities that translate intelligence into detections, investigations, and security hardening priorities. Own EDR across the corporate environment and partner with Platform Engineering on runtime and workload protection for production systems. Lead operational defenses against phishing and social engineering, including detection, reporting triage, takedown activities, and credential-compromise response. Design and continuously improve an AI-first SOC operating model, personally developing automation for triage, enrichment, correlation, investigation, and reporting. Partner with engineering, compliance, trust, and other cross-functional teams to strengthen security coverage and response capabilities. Requirements 8+ years of experience in security operations, incident response, detection engineering, threat intelligence, or a closely related field, including 3+ years leading teams. Demonstrated hands-on security expertise, including personally writing detections, conducting investigations, leading incidents, and building security automation. Experience building or substantially rebuilding a SOC function rather than exclusively operating within an established organization. Strong experience across both production/cloud security monitoring and corporate/enterprise security operations. Deep knowledge of modern security operations technologies, including SIEM and security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry. Strong detection engineering capabilities with the ability to develop and improve detection content directly. Experience with cloud and container security monitoring; AWS and Kubernetes experience is strongly preferred. Understanding of identity-focused attack paths involving SSO, OAuth, session compromise, MFA bypass, and privilege escalation across SaaS and cloud environments. Proven incident command experience during significant security events, including executive communication and appropriate escalation judgment. Demonstrated use of AI in security operations, such as triage, enrichment, detection creation, investigation support, or reporting, with the ability to explain measurable outcomes. Experience designing 24/7 security coverage and managing globally distributed teams across multiple time zones. Experience in transportation, logistics, IoT, connected devices, or critical infrastructure is a plus. Strong communication, prioritization, decision-making, and problem-solving skills, with the ability to remain effective during high-pressure security incidents. Must be authorized to work in the United States and authorized to receive and access commodities and technologies controlled under U.S. Export Administration Regulations. Benefits Base compensation range of $140,000–$200,000 USD. Potential eligibility for restricted stock units and other components of total compensation, depending on the role and circumstances. Health, pharmacy, optical, and dental benefits. Paid time off and sick time off. Short-term and long-term disability coverage. Life insurance. 401(k) contribution opportunities. Remote work arrangement within the United States. Opportunity to build and lead a SOC from the ground up, with significant ownership over its people, technology, detection strategy, and operating model. Exposure to AI-first security operations, cloud and production security, threat intelligence, detection engineering, and large-scale incident response. Opportunity to work across globally distributed teams and complex technology environments. Professional growth through leadership, security engineering, and cross-functional collaboration. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

AWSKubernetesSaaSAIGitUI
FREE MATCHED JOB ALERTS

Get jobs like this without searching manually.

Tell Connect what you want once. We will use your preferences to surface matching opportunities and invite you into your free career workspace.