Verified current Job

Senior Manager, Security Operations

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Manager, Security Operations based in Unite

Job Remote Full source details
Jobgether Source published Sep 22, 2026 Verified 49 minutes ago
✓ 100% verification score · Source: jobgether (lever) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull-time
Work modeRemote / location-flexible

Overview

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Manager, Security Operations based in Unite

Full job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Manager, Security Operations based in United States. This is a founding leadership role responsible for building and scaling a modern Security Operations Center from the ground up. You will shape the SOC’s team, tooling, detection strategy, operating model, and 24/7 response capabilities rather than inheriting an established function. The role spans both production and cloud environments as well as corporate and enterprise systems, creating a unified approach to detection and response across complex technology estates. Reporting to the CISO, you will lead detection engineering, incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload protection. A strong focus on AI, automation, and data-driven operations will enable a small, highly leveraged team to focus on complex security challenges rather than routine alert processing. You will also serve as a trusted incident leader and strategic security partner across engineering, compliance, and executive teams.

Build and grow the SOC operating model, including coverage structures, runbooks, escalation paths, hiring, career development, and the appropriate 24/7 coverage approach. Define and own the detection strategy across production, cloud, corporate, and enterprise environments, explicitly mapping coverage to MITRE ATT&CK and the organization’s threat model. Expand security monitoring into cloud and production workloads in partnership with Platform Engineering, developing detections that identify attack paths across corporate and production environments. Lead 24/7 incident response and serve as incident commander for significant security events, providing clear and composed communication to executives throughout incidents. Own the security telemetry and analytics platform, including data collection, normalization, enrichment, retention, cost management, and operational performance measurement. Establish metrics covering MTTD, MTTR, detection coverage, alert precision, and automation rates to provide an accurate view of SOC effectiveness. Develop a structured, hypothesis-driven threat hunting program and establish threat intelligence capabilities that translate intelligence into detections, investigations, and security hardening priorities. Own EDR across the corporate environment and partner with Platform Engineering on runtime and workload protection for production systems. Lead operational defenses against phishing and social engineering, including detection, reporting triage, takedown activities, and credential-compromise response. Design and continuously improve an AI-first SOC operating model, personally developing automation for triage, enrichment, correlation, investigation, and reporting. Partner with engineering, compliance, trust, and other cross-functional teams to strengthen security coverage and response capabilities. Requirements 8+ years of experience in security operations, incident response, detection engineering, threat intelligence, or a closely related field, including 3+ years leading teams. Demonstrated hands-on security expertise, including personally writing detections, conducting investigations, leading incidents, and building security automation. Experience building or substantially rebuilding a SOC function rather than exclusively operating within an established organization. Strong experience across both production/cloud security monitoring and corporate/enterprise security operations. Deep knowledge of modern security operations technologies, including SIEM and security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry. Strong detection engineering capabilities with the ability to develop and improve detection content directly. Experience with cloud and container security monitoring; AWS and Kubernetes experience is strongly preferred. Understanding of identity-focused attack paths involving SSO, OAuth, session compromise, MFA bypass, and privilege escalation across SaaS and cloud environments. Proven incident command experience during significant security events, including executive communication and appropriate escalation judgment. Demonstrated use of AI in security operations, such as triage, enrichment, detection creation, investigation support, or reporting, with the ability to explain measurable outcomes. Experience designing 24/7 security coverage and managing globally distributed teams across multiple time zones. Experience in transportation, logistics, IoT, connected devices, or critical infrastructure is a plus. Strong communication, prioritization, decision-making, and problem-solving skills, with the ability to remain effective during high-pressure security incidents. Must be authorized to work in the United States and authorized to receive and access commodities and technologies controlled under U.S. Export Administration Regulations. Benefits Base compensation range of $140,000–$200,000 USD . Potential eligibility for restricted stock units and other components of total compensation, depending on the role and circumstances. Health, pharmacy, optical, and dental benefits. Paid time off and sick time off. Short-term and long-term disability coverage. Life insurance. 401(k) contribution opportunities. Remote work arrangement within the United States. Opportunity to build and lead a SOC from the ground up, with significant ownership over its people, technology, detection strategy, and operating model. Exposure to AI-first security operations, cloud and production security, threat intelligence, detection engineering, and large-scale incident response. Opportunity to work across globally distributed teams and complex technology environments. Professional growth through leadership, security engineering, and cross-functional collaboration.

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

laptop-ats-crawler v3

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

jobgether (lever) ↗

Browse current Job and Scholarship listings from jobgether (lever) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books