Security Operations and Engineering Manager
Job Summary
The Information Security Operations and Engineering Manager is a hands-on leader responsible for guiding the team that protects the company’s systems and data from cyber threats. This individual will oversee all aspects of the security operations center (SOC), including threat monitoring, incident response, and threat hunting. Concurrently, they will lead the security engineering efforts, focusing on the design, implementation, and automation of security tools and processes. The ideal candidate will mentor team members, act as a senior escalation point for complex security incidents, and develop a strategic roadmap to ensure our defensive capabilities are effective and efficient.
The Information Security Operations and Engineering Manager is a hands-on leader responsible for guiding the team that protects the company’s systems and data from cyber threats. This individual will oversee all aspects of the security operations center (SOC), including threat monitoring, incident response, and threat hunting. Concurrently, they will lead the security engineering efforts, focusing on the design, implementation, and automation of security tools and processes. The ideal candidate will mentor team members, act as a senior escalation point for complex security incidents, and develop a strategic roadmap to ensure our defensive capabilities are effective and efficient.
Responsibilities
- Team Leadership and Strategy: Lead, mentor, and develop a team of security analysts and engineers. Set strategic goals, manage priorities, conduct performance reviews, and foster a culture of continuous improvement and collaboration.
- Security Operations Management: Oversee the 24/7 monitoring of security alerts, manage the security event lifecycle, and ensure the timely triage and escalation of potential threats.
- Incident Response and Forensics: Serve as the senior incident commander for significant security events. Lead hands-on digital forensic investigations, ensuring evidence is collected and analyzed in a forensically sound manner. Develop and refine incident response playbooks.
- Security Engineering and Automation: Direct the architecture, implementation, and optimization of the company's security toolset. Drive the automation of incident response procedures, data collection, and routine security tasks to enhance response times and team efficiency.
Minimum Qualifications
- A bachelor's degree and 7 years of professional work experience (or equivalent experience) is required. 2 years management experience is required.
Additional Qualifications
- Professional certifications such as CISSP, CISM, GCIH, GCFA, or other relevant security credentials are highly desirable.
- Deep knowledge of security operations frameworks (e.g., NIST Cybersecurity Framework, MITRE ATT&CK) and incident response procedures.
- Strong understanding of security engineering principles, cloud security architecture (AWS, Azure), and network security concepts.
- Proven hands-on experience in security engineering, including tuning and managing SIEM, SOAR, and EDR platforms.
- Proficiency in a scripting language (e.g., Python, PowerShell) to automate security tasks and workflows.
- Demonstrated experience leading major incident response efforts and conducting complex digital forensic investigations.
- Excellent communication, leadership, and project management skills with the ability to articulate complex technical topics to diverse audiences.