Manager, Security Operations & Incident Response

Trex

Winchester (VA)

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Trex is seeking a Manager, Security Operations & Incident Response to lead day-to-day security operations, incident response, and vendor governance in a hybrid work model at its Winchester, VA site. The role partners with Legal, Finance, and executive leadership to manage materiality determinations and cyber disclosures.

The candidate will direct detection engineering across EDR, SIEM, and cloud security platforms, and collaborate with IT, OT, and application teams to integrate security into IT

Qualifications

  • 7–10 years in security operations in a regulated or audit-sensitive environment.
  • Experience managing MSSP/MDR relationships, SLAs, and transitions.
  • Familiarity with SEC disclosure expectations and cyber incident reporting requirements.

Responsibilities

  • Lead 24x7 security operations delivered via the managed service model with governance and SLA alignment.
  • Own end-to-end incident response lifecycle from preparation to lessons learned, including executive communications.
  • Oversee vulnerability management, detection engineering roadmaps, and security platform operations across endpoint, cloud, email, and networks.
  • Coordinate with Legal, Finance, and IR for materiality determinations and post-incident disclosures.

Skills

Security operations
Incident response
MSSP management
SOX/compliance
SEC disclosures

Education

Bachelor's in Information Technology or related field

Tools

SIEM
EDR
Cloud security tools

Job description

Manager, Security Operations & Incident Response
  • Posted on July 31, 2026
Locations

Showing 1 location

VA Corporate
2500 Trex Way
Winchester, VA 22601, USA

  • Hybrid
  • Information Technology
  • Full-Time
  • Requisition #: MANAG003987
Description

Position Summary

The Manager, Security Operations & Incident Response is responsible for leading Trex’s day-to-day security operations, incident response program, managed security service partnerships, and operational governance of the endpoint, cloud, email, vulnerability management, and detection platforms. This role provides centralized leadership and accountability for security operations, ensuring that alert triage, incident response, vulnerability remediation, threat detection, and managed service performance are coordinated, measurable, and aligned with business risk. The position oversees the established hybrid security operations operating model, including security information and event management, endpoint detection and response, managed detection and response, application control, threat detection, incident response, and security service provider performance. The role also supports Trex’s readiness for cyber incident disclosure and materiality determination requirements in coordination with Legal, Finance, and executive leadership.

Key Duties and Responsibilities:

Security Operations Management

  • Lead 24x7 security operations delivered through the managed service model, including alert triage governance, escalation procedures, response expectations, service quality, and performance measurement against contractual SLAs.
  • Provide oversight of the SOC operating model, ensuring internal teams, offshore resources, and managed service providers have clearly defined responsibilities, documented processes, and measurable outcomes.
  • Direct the detection engineering roadmap across managed endpoint detection and response, cloud-native security information and event management, and extended detection and response platforms, ensuring detection content reflects Trex’s manufacturing environment, threat model, and technology architecture.
  • Partner with cybersecurity, infrastructure, networking, endpoint, OT, and application teams to ensure security operations are integrated into broader IT service delivery and business operations.
  • Own the end-to-end incident response lifecycle, including preparation, detection, containment, eradication, recovery, lessons learned, and post-incident improvement activities.
  • Lead executive-facing communications during high-severity security events, ensuring clear, timely, and business-appropriate updates are provided to leadership and key stakeholders.
  • Maintain the on-call rotation, escalation model, and quarterly tabletop exercise cadence, including executive-level tabletop exercises with Legal, Finance, Communications, and other business stakeholders.
  • Ensure Trex maintains readiness for SEC 4-day 8-K cyber incident reporting, including materiality determination workflows, coordination with Legal, Finance/CFO, Investor Relations, and post-incident disclosure preparation.

Vulnerability Management and Platform Operations

  • Own the vulnerability management program, including enterprise vulnerability scanning strategy, remediation governance, SLA tracking, exception handling, and coordination with IT Platforms, Servers, and application owners.
  • Lead the application control and allowlisting deployment and tuning program in partnership with IT Platforms and End User Computing, including business change management, allowlisting governance, and false-positive resolution.
  • Oversee operational security capabilities across secure web gateway, email security, endpoint detection and response, extended detection and response, security information and event management, vulnerability management, application control, and related security platforms.
  • Support Zero Trust and secure access initiatives, including zero trust network access rollout, legacy remote access VPN decommission planning, and conditional access integration in environments using a third-party primary endpoint detection and response platform.

Vendor and Managed Service Management

  • Manage managed security service provider and managed detection and response vendor relationships, including service transitions, ongoing service governance, SLA management, escalation handling, and vendor performance reviews.
  • Coordinate with internal stakeholders and vendors to ensure security platforms, managed services, and incident response retainers are aligned to Trex’s operational requirements and risk profile.
  • Lead structured knowledge transfer of platform ownership from in-house senior staff to offshore managed service resources, including acceptance criteria, documentation, service expectations, and quarterly review milestones.

Business Partnership and Compliance Support

  • Work closely with IT Platforms and Servers, OT Engineering, Legal, Internal Audit, End User Computing, and other business partners on shared workstreams including segmentation, network access control modernization, conditional access, OT/ICS security, and security operations maturity.
  • Support M&A cyber due diligence and post-close integration activities in partnership with the Security Architect and other IT leaders.
  • Contribute to Trex’s NIST CSF maturity targets and help align security operations practices with NIST CSF, NIST 800-53, CIS Critical Security Controls, SOX ITGC expectations, and cybersecurity disclosure obligations.

Leadership and Team Development

  • Manage and develop a hybrid team of in-house and offshore security resources responsible for incident response, vulnerability management, cloud security, email security, platform operations, and managed SOC coordination.
  • Provide coaching, prioritization, performance direction, and operational guidance to ensure the team can support current-state operations while maturing Trex’s security operations capability.
  • Establish clear operating procedures, documentation expectations, accountability models, and review cadences to ensure work is repeatable, measurable, and sustainable as Trex scales.
Qualifications
Skills
Behaviors

:

Motivations

:

Education
Required

Bachelors or better in Information Technology or related field.

Experience
Required

7-10 years: Experience working in a publicly traded, SOX-scoped, or audit-sensitive environment, with familiarity with cyber-related SEC disclosure expectations.One or more relevant professional certifications, or equivalent experience, such as CISSP, GCIH, GCIA, GCFA, or CISM.Experience managing MSSP, MDR, or SOC service provider relationships, including SLA governance, transition planning, escalation management and performance measurement.

Licenses & Certifications

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Security Operations & Incident Response
Manager, Security Operations & Incident Response

Trex Company • Winchester (VA)

On-site
USD 140,000 - 175,000
Health, dental, and vision insurance
401(k) with company match
Tuition reimbursement
+3
Security Operations & Incident Response Leader
Security Operations & Incident Response Leader

Trex Company • Winchester (VA)

On-site
USD 140,000 - 175,000
Health, dental, and vision insurance
401(k) with company match
Tuition reimbursement
+3
Manager - Cybersecurity Operations
Manager - Cybersecurity Operations

Plexus Corp. • Neenah (WI)

On-site
USD 110,000 - 150,000
Sr. Trellix Cybersecurity Engineer
Sr. Trellix Cybersecurity Engineer

Arena Technical Resources, LLC (ATR) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Manager - Cybersecurity Operations
Manager - Cybersecurity Operations

Plexus Corp • Neenah (WI)

On-site
USD 100,000 - 130,000
Reasonable accommodations for disabilities
Equal Opportunity Employer
Senior Manager, Transformation
Senior Manager, Transformation

Trellix • Northern (KY)

Hybrid
USD 90,000 - 150,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
Head of 24/7 Security Operations & Incident Response
Head of 24/7 Security Operations & Incident Response

Trex • Winchester (VA)

Hybrid
USD 120,000 - 180,000
Platform & Cloud Engineer
Platform & Cloud Engineer

Trex Company • Winchester (VA)

On-site
USD 110,000 - 130,000
Time Off
Health, Dental, and Vision Insurance
401(k) With Company Match
+4
Cyber Threat Hunter (TS/SCI Clearance Required)
Cyber Threat Hunter (TS/SCI Clearance Required)

Trellix • Fairfax (VA)

On-site
USD 120,000 - 170,000
Retirement Plans
Medical, Dental and Vision Coverage
Paid Time Off
+1
Platform & Cloud Engineer
Platform & Cloud Engineer

Trex • Winchester (VA)

On-site
USD 110,000 - 130,000
Health insurance
401(k) with company match
Tuition reimbursement
+4