Senior Manager, Security Operations
Quick Summary
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Manager, Security Operations based in United States.
This is a founding leadership role responsible for building and scaling a modern Security Operations Center from the ground up. You will shape the SOC’s team, tooling, detection strategy, operating model, and 24/7 response capabilities rather than inheriting an established function. The role spans both production and cloud environments as well as corporate and enterprise systems, creating a unified approach to detection and response across complex technology estates. Reporting to the CISO, you will lead detection engineering, incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload protection. A strong focus on AI, automation, and data-driven operations will enable a small, highly leveraged team to focus on complex security challenges rather than routine alert processing. You will also serve as a trusted incident leader and strategic security partner across engineering, compliance, and executive teams.
- Build and grow the SOC operating model, including coverage structures, runbooks, escalation paths, hiring, career development, and the appropriate 24/7 coverage approach.
- Define and own the detection strategy across production, cloud, corporate, and enterprise environments, explicitly mapping coverage to MITRE ATT&CK and the organization’s threat model.
- Expand security monitoring into cloud and production workloads in partnership with Platform Engineering, developing detections that identify attack paths across corporate and production environments.
- Lead 24/7 incident response and serve as incident commander for significant security events, providing clear and composed communication to executives throughout incidents.
- Own the security telemetry and analytics platform, including data collection, normalization, enrichment, retention, cost management, and operational performance measurement.
- Establish metrics covering MTTD, MTTR, detection coverage, alert precision, and automation rates to provide an accurate view of SOC effectiveness.
- Develop a structured, hypothesis-driven threat hunting program and establish threat intelligence capabilities that translate intelligence into detections, investigations, and security hardening priorities.
- Own EDR across the corporate environment and partner with Platform Engineering on runtime and workload protection for production systems.
- Lead operational defenses against phishing and social engineering, including detection, reporting triage, takedown activities, and credential-compromise response.
- Design and continuously improve an AI-first SOC operating model, personally developing automation for triage, enrichment, correlation, investigation, and reporting.
- Partner with engineering, compliance, trust, and other cross-functional teams to strengthen security coverage and response capabilities.
Requirements
~2 min read- 8+ years of experience in security operations, incident response, detection engineering, threat intelligence, or a closely related field, including 3+ years leading teams.
- Demonstrated hands-on security expertise, including personally writing detections, conducting investigations, leading incidents, and building security automation.
- Experience building or substantially rebuilding a SOC function rather than exclusively operating within an established organization.
- Strong experience across both production/cloud security monitoring and corporate/enterprise security operations.
- Deep knowledge of modern security operations technologies, including SIEM and security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry.
- Strong detection engineering capabilities with the ability to develop and improve detection content directly.
- Experience with cloud and container security monitoring; AWS and Kubernetes experience is strongly preferred.
- Understanding of identity-focused attack paths involving SSO, OAuth, session compromise, MFA bypass, and privilege escalation across SaaS and cloud environments.
- Proven incident command experience during significant security events, including executive communication and appropriate escalation judgment.
- Demonstrated use of AI in security operations, such as triage, enrichment, detection creation, investigation support, or reporting, with the ability to explain measurable outcomes.
- Experience designing 24/7 security coverage and managing globally distributed teams across multiple time zones.
- Experience in transportation, logistics, IoT, connected devices, or critical infrastructure is a plus.
- Strong communication, prioritization, decision-making, and problem-solving skills, with the ability to remain effective during high-pressure security incidents.
- Must be authorized to work in the United States and authorized to receive and access commodities and technologies controlled under U.S. Export Administration Regulations.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- September 22, 2026
- First seen
- September 27, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 46%
- Scored at
- September 28, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.