Cybersecurity Operations Manager
Core
Lead and mature day-to-day SOC operations, incident response, and vulnerability management for a national retail organization.
Role type
Senior IC cybersecurity operations manager
Builds
SOC workflows, incident response playbooks, vulnerability management programs, and security automation capabilities
Domain
Retail / Cybersecurity Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOC operations leadership, incident response lifecycle management, MDR/EDR/SIEM/SOAR administration, vulnerability management, MSSP management, security frameworks (NIST/CIS/PCI/SOX/CCPA), cross-functional leadership, high-pressure decision making, AI concepts in security
Preferred skills
CISM/CISSP certification, Rapid7/Microsoft Defender/Intune/Jamf/Workato experience, SOAR workflow development, cloud security (AWS/Azure/GCP), SaaS environment experience, DLP program ownership, retail/high-growth background
Technologies
AI, AWS, Azure, GCP, Rapid7, Microsoft Defender, Intune, Jamf, Workato, SIEM, SOAR, MDR, EDR
Responsibilities
Lead and mature SOC operations including monitoring, alert triage, escalation, and incident response workflows; Partner with external MSSP to strengthen SLA accountability and alert quality; Oversee vulnerability management including prioritization, remediation tracking, and executive reporting; Drive endpoint security initiatives across Intune, Jamf, and Defender; Enhance SIEM and SOAR capabilities including automation for level 1 response; Build and refine incident response processes including playbooks and post-incident reviews; Collaborate with IT, GRC, engineering, and business stakeholders to improve security posture; Support DLP strategy and monitoring for sensitive data protection; Evaluate responsible AI use in security operations; Mentor team members while staying hands-on with technical operations
Seniority
Senior, hands-on IC