Cyber Threat Intel & SOC Leader

Williams-Sonoma, Inc.

San Francisco (CA)

On-site

USD 170,000 - 202,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

401(k) plan and investment options
Paid vacation & holidays
Health, dental, vision benefits
Employee discounts
Learning & development opportunities

Job summary

Williams-Sonoma, Inc. seeks a hands‑on, strategic Manager of Cyber Threat Intelligence & Security Operations to lead a multidisciplinary team across threat intelligence, detection engineering, SOC, red team, and incident response.

You will shape strategy, drive execution, and oversee major security operations and modernization efforts. You will manage enterprise tools and coordinate with cross‑functional teams to mature detections, automate workflows, and reduce cyber risk across a global retail

Qualifications

  • 7–10 years of progressive experience in Cyber Security with expertise in Security Operations, Threat Intelligence, Detection Engineering, and Incident Response.
  • Proven experience managing technical teams and hands‑on approach to verify configurations and adjust settings.
  • Expertise across SIEM, SOAR, EDR, Threat Intelligence, endpoint security, penetration testing and incident response technologies.
  • Experience developing and reporting operational metrics including MTTD, MTTR, detection coverage, alert fidelity, incident trends, automation effectiveness, and threat intelligence impact.
  • Experience developing and executing a multi‑year roadmap to mature SOC capabilities across people, process, technology, and automation.
  • Strong understanding of enterprise networking, cloud, identity, operating systems, and modern attack techniques.
  • Excellent communication, leadership, and cross‑functional collaboration skills.

Responsibilities

  • Lead and mentor a ~24-person cybersecurity team across Threat Intelligence, Detection Engineering, Security Operations, Red Team, and Incident Response.
  • Define, execute, and mature the enterprise Cyber Threat Intelligence, Detection Engineering, and Security Operations strategy.
  • Oversee operation of Google SecOps, CrowdStrike, Cortex XSOAR, MISP, Tanium, and associated detection technologies.
  • Direct enterprise cyber incident response from initial triage through containment, eradication, recovery, and lessons learned.
  • Drive proactive threat hunting, IOC management, and intelligence collection and analysis.
  • Lead Detection Engineering including SIEM content development, use‑case creation, alert tuning, and detection quality improvements.
  • Expand automation and Ai-assisted capabilities to accelerate investigation and response.
  • Develop intelligence-driven detections based on evolving TTPs.
  • Lead Red Team operations including adversary emulation and purple team exercises.
  • Collaborate with IT, Legal, Privacy, and other teams to strengthen enterprise defenses.
  • Provide hands‑on support during major incidents and platform integrations.

Skills

Cyber Threat Intel
Security Operations
Incident Response
SIEM/SOAR/EDR
Threat Hunting
Leadership
Metrics & Reporting
MITRE ATT&CK
Cloud & Network

Tools

Google SecOps
CrowdStrike
Cortex XSOAR
MISP
Tanium

Job description

Williams-Sonoma, Inc. seeks a hands‑on, strategic Manager of Cyber Threat Intelligence & Security Operations to lead a multidisciplinary team across threat intelligence, detection engineering, SOC, red team, and incident response.

You will shape strategy, drive execution, and oversee major security operations and modernization efforts. You will manage enterprise tools and coordinate with cross‑functional teams to mature detections, automate workflows, and reduce cyber risk across a global retail

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Threat Management Lead | SOC & Incident Response
Cyber Threat Management Lead | SOC & Incident Response

WPS Data Logistics, Inc. • Madison (WI), Northern (KY)

Hybrid
USD 140,000 - 180,000
Senior Cyber Threat & Incident Management Lead
Senior Cyber Threat & Incident Management Lead

WPS—A health solutions company • Alabama

Hybrid
USD 140,000 - 180,000
Hybrid work options
Performance bonus
401(k) match
+2
Senior SOC & Threat Intelligence Lead
Senior SOC & Threat Intelligence Lead

TEKsystems • San Francisco (CA)

On-site
USD 96,000 - 103,000
Medical, dental & vision
401(k) retirement plan
Life insurance
+2
Cyber Threat Management Lead | SOC & Incident Response
Cyber Threat Management Lead | SOC & Incident Response

WPS Health Solutions • Monona (WI)

Hybrid
USD 140,000 - 180,000
Hybrid work options
401(k) with generous match
Health insurance
+1
Cyber Threat Management Leader | Hybrid Role
Cyber Threat Management Leader | Hybrid Role

Wis Phys Svc Ins Corp • Madison (WI)

Hybrid
USD 140,000 - 180,000
Health insurance
Dental insurance
Telehealth
+3
Senior SOC Lead: Threat Hunting & IR (Remote)
Senior SOC Lead: Threat Hunting & IR (Remote)

SPS Commerce • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Senior Cyber Threat & SOC Operations Leader
Senior Cyber Threat & SOC Operations Leader

TEKsystems • Rocklin (CA)

On-site
USD 96,000 - 103,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+5
Senior Cyber Defense Lead - Threat Hunting & IR Hybrid
Senior Cyber Defense Lead - Threat Hunting & IR Hybrid

SPS Commerce, Inc. • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000
Threat Management Leader: SOC, IR & Intelligence
Threat Management Leader: SOC, IR & Intelligence

RXinsider LTD. • Naperville (IL)

On-site
USD 168,000 - 253,000
Director, Cyber Threat Intelligence: Strategy & Leadership
Director, Cyber Threat Intelligence: Strategy & Leadership

Roundel • Brooklyn Park (MN)

Hybrid
USD 149,000 - 268,000
Health benefits
401(k)