Senior Manager, Security Operations Center (SOC)
The Team
We are seeking a Senior Manager, Security Operations Center (SOC) to lead and manage the day-to-day operations of the Security Operations Center, ensuring continuous monitoring, detection, investigation, and response to cybersecurity threats across the enterprise.
This role is responsible for overseeing SOC analysts, threat detection activities, security monitoring platforms, and incident response coordination to protect the organization from cyber threats. The Senior Manager will drive operational excellence, enhance detection capabilities, improve response processes, and ensure effective use of security technologies to reduce organizational risk.
The ideal candidate possesses strong technical expertise in security operations, cyber defense, threat detection, and incident response, along with proven people leadership skills and experience managing global security operations teams.
Responsibilities
Security Operations Leadership
Lead the daily operations of the Security Operations Center, ensuring effective monitoring and response to security events and alerts.
Manage and develop SOC analysts across multiple levels, fostering a culture of accountability, continuous improvement, and operational excellence.
Establish and track key performance indicators (KPIs), service level agreements (SLAs), and operational metrics.
Drive SOC maturity initiatives, process improvements, and operational efficiencies.
Ensure continuous monitoring coverage and operational readiness for emerging cyber threats.
Security Monitoring & Threat Detection
Oversee the monitoring, investigation, escalation, and resolution of security events across enterprise environments.
Ensure effective operation and optimization of SIEM, SOAR, EDR/XDR, SaaS monitoring, cloud security, and threat detection platforms.
Lead the development, tuning, and maintenance of detection rules, use cases, dashboards, alerts, and workflows.
Drive improvements in detection quality, alert fidelity, and analyst efficiency.
Collaborate with Security Engineering and Architecture teams to improve visibility and threat detection capabilities.
Incident Response & Investigations
Manage security incident investigations from initial detection through containment, eradication, recovery, and closure.
Serve as an incident commander or escalation lead for medium and high-severity cybersecurity incidents.
Coordinate response efforts with infrastructure, cloud, identity, application, legal, privacy, and business teams.
Ensure incident response playbooks and procedures remain current and effective.
Conduct post-incident reviews and implement lessons learned to improve future response capabilities.
Threat Hunting & Threat Intelligence
Partner with Threat Intelligence and Threat Hunting teams to identify emerging threats and adversary activity.
Leverage threat intelligence to enhance detection coverage and prioritize investigations.
Support proactive threat hunting activities and identification of advanced threats.
Ensure SOC operations align with threat-informed defense methodologies and MITRE ATT&CK frameworks.
Security Engineering & Automation
Collaborate with Detection Engineering teams to improve alert automation, orchestration, and response processes.
Drive adoption of SOAR workflows and automation to reduce analyst workload and improve response times.
Ensure security technologies are properly configured, maintained, and continuously optimized.
Participate in security tool evaluations, implementations, and technology enhancements.
Stakeholder Management & Reporting
Provide operational reporting and security metrics to senior leadership.
Communicate incident impacts, risks, and remediation activities to technical and non-technical stakeholders.
Partner with IT Operations, Infrastructure, Cloud, Identity, and Business teams to improve overall cybersecurity posture.
Manage vendor relationships supporting SOC technologies and managed security services.
What We are looking for:
Required Skills
8+ years of cybersecurity experience with significant focus in Security Operations, Incident Response, or Cyber Defense.
3+ years of people leadership experience managing SOC analysts or security operations teams.
Deep understanding of security monitoring, threat detection, incident response, and cyber defense operations.
Hands-on experience with SIEM, SOAR, EDR/XDR, Endpoint Security, Cloud Security Monitoring, and Threat Intelligence platforms.
Experience managing security incidents and coordinating cross-functional response activities.
Strong knowledge of attacker tactics, techniques, and procedures (TTPs), threat actor behaviors, and detection methodologies.
Experience developing operational metrics, dashboards, and executive reporting.
Familiarity with NIST CSF, MITRE ATT&CK, CIS Controls, and incident response best practices.
Preferred skills
Experience operating in a 24x7 SOC environment supporting global business operations.
Experience with cloud environments including AWS, Azure, and Google Cloud Platform.
Experience with threat hunting, digital forensics, malware analysis, or detection engineering.
Industry certifications such as CISSP, GCIH, GCIA, GCFA, CISM, Security+, or equivalent.
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
Key Competencies
Security operations leadership
Cyber incident management
Threat detection and analysis
Strong analytical and investigative skills
Operational excellence and process improvement
Team leadership and development
Executive communication and reporting
Crisis management and decision-making
Collaboration and stakeholder engagement
Continuous learning and adaptability
Expected Hours of Work
This is a full-time position. Work is generally performed Monday through Friday; however, participation in on-call rotations, after-hours escalations, weekends, and holidays may be required to support cybersecurity operations and major incidents.
Travel Requirements
Up to 10% domestic and international travel may be required.
Travel may include team meetings, training events, leadership workshops, cybersecurity conferences, and operational reviews.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.