Manager, Security Operations (Hands On/Technical)
Core
Lead day-to-day operations for a geographically dispersed Security Operations team, serving as Incident Commander to protect Gartner's reputation, customers, and IT infrastructure against threats.
Role type
Manager, Security Operations (Hands On/Technical)
Builds
Operational response capabilities, detection content aligned with ATT&CK/Cyber Kill Chain, and automated workflows for security analysts.
Domain
Cybersecurity / Information Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Incident response leadership, SIEM/EDR tool expertise, security project management, team mentorship, technical analysis of security events, automation initiative driving
Preferred skills
Cloud platforms (AWS, Azure, GCP), scripting/programming (Python, PowerShell, Bash), CISSP/GCIH/GCFA certifications
Technologies
SIEM, EDR, web proxy, email security tools, Python, PowerShell, Bash, AWS, Azure, GCP
Responsibilities
Drive operational excellence of a geographically dispersed Security Operations team, Serve as the Incident Commander during the incident response process, Continuously seek out opportunities to improve the team's ability to rapidly and effectively respond to security incidents, Work with key business stakeholders to detect, respond to, and remediate security issues, Provide mentorship and guidance to team members, Drive automation initiatives, enhancing analyst capabilities and workflows
Seniority
Manager, hands-on IC with leadership responsibilities