About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Operations Manager based in United States.
Responsibilities
- Lead the Security Operations function, overseeing security monitoring, threat detection, investigation, escalation, containment, remediation, and recovery activities.
- Manage and optimize security technologies and processes covering Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), email security, vulnerability management, and threat intelligence.
- Develop and maintain security alerts, detection rules, dashboards, use cases, monitoring standards, and escalation procedures.
- Lead cybersecurity incident response activities, including investigation, containment, recovery, root-cause analysis, and post-incident reviews.
- Maintain, test, and continuously improve cybersecurity incident response plans, procedures, and supporting playbooks.
- Lead the vulnerability management lifecycle across servers, endpoints, applications, cloud environments, and network infrastructure.
- Establish risk-based vulnerability prioritization and remediation standards to ensure security weaknesses are addressed according to business impact and threat level.
- Monitor emerging cybersecurity threats and coordinate proactive threat-hunting activities to identify and mitigate potential risks.
- Assess and respond to threats involving ransomware, phishing, business email compromise, credential theft, insider threats, and sensitive healthcare data theft.
- Strengthen identity and access security through effective controls covering privileged access, multifactor authentication (MFA), conditional access, and account monitoring.
- Support security monitoring and incident response across cloud platforms, SaaS environments, endpoints, networks, and other technology infrastructure.
- Support compliance with applicable security and regulatory frameworks, including HIPAA, HITRUST, SOC 2, PCI DSS, and client-specific security requirements.
- Partner with Privacy, Compliance, Legal, and Risk teams on investigations involving sensitive, confidential, or regulated information.
- Lead, mentor, and develop Security Operations personnel while establishing clear performance expectations and opportunities for professional growth.
- Establish effective on-call procedures, incident escalation paths, and after-hours response processes.
- Manage relationships with security technology vendors, managed security service providers, and incident response partners.
- Develop operational dashboards and executive reports covering security performance, risks, incidents, and control effectiveness.
- Track and communicate key security and risk indicators, including incident response times, vulnerability remediation, endpoint coverage, phishing trends, and security control performance.
- Identify opportunities to improve security operations, strengthen controls, increase operational efficiency, and enhance the organization’s overall cybersecurity maturity.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field, or an equivalent combination of education and relevant experience.
- At least 8 years of progressive cybersecurity or information security experience.
- At least 3 years of experience leading security operations, incident response, security engineering, or a comparable cybersecurity function.
- Demonstrated experience managing cybersecurity incidents across multiple technical and business teams, from initial investigation through containment and recovery.
- Strong working knowledge of Security Information and Event Management (SIEM), security monitoring, Endpoint Detection and Response (EDR), Extended Detection and Response (XDR), incident response, vulnerability management, identity and access security, network security, email security, AI security, threat intelligence, and security logging.
- Experience operating security programs in environments that handle sensitive, confidential, or regulated information.
- Knowledge of common cyberattack techniques, tactics, and frameworks such as MITRE ATT&CK.
- Strong analytical, investigative, organizational, and problem-solving skills, with the ability to assess complex security events and determine appropriate actions.
- Strong understanding of security risk management and the ability to balance technical priorities with business requirements.
- Excellent communication skills, with the ability to explain complex cybersecurity risks, incidents, and recommendations clearly to both technical and non-technical stakeholders.
- Strong organizational and strategic planning skills.