Manager / Sr. Manager, SecOps & Cyber Defense

Bullish, Inc.

New York (NY)

On-site

USD 185,000 - 235,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CoinDesk seeks an experienced Manager/Sr. Manager of SecOps & Cyber Defense to lead our 24/7 security detection and response across the US, UK, and EMEA.

Based in NYC, you will work onsite at the Chelsea office four days per week and guide a lean SOC across time zones, building detection pipelines in cloud and hybrid environments. You will own incident response from detection through remediation, design detection rules, perform forensics when needed, and advance threat hunting and readiness

Qualifications

  • 8+ years of hands-on SOC experience.
  • 2+ years in people management or team leadership.
  • Cloud-native threat investigation across AWS/GCP/Azure.
  • Proficient with SIEM, EDR/XDR, log aggregators, and SOAR.
  • Scripting in Python, Bash, or Go to automate triage.
  • Strong networking and cloud architecture knowledge.
  • Ability to stay calm under pressure during incidents.
  • Experience in Financial Services/FinTech is a plus.

Responsibilities

  • Lead and mentor SOC Analysts and IR engineers across time zones.
  • Serve as primary escalation point for high-severity incidents.
  • Define and track SOC metrics (MTTD, MTTR, false positives).
  • Collaborate with Infra, Cloud, DevOps, Legal, and Compliance.
  • Drive end-to-end incident management from detection to remediation.
  • Design and tune high-precision detection rules (SIEM/EDR/Cloud logs).
  • Perform hands-on digital forensics and reverse unusual scripts.
  • Research threats and fortify detection capabilities and playbooks.
  • Lead Red/Purple team exercises and threat hunting activities.
  • Build automated response playbooks using Python and SOAR.

Skills

SOC operations
Threat detection
Incident response
People management
Cloud-native threats
SIEM/EDR/SOAR
Python/Bash/Go
Networking fundamentals
Digital forensics basics
Calm under pressure

Education

Bachelor's degree in CS or InfoSec
GIAC CISSP OSCP or equivalent

Tools

SIEM platforms
EDR/XDR suites
SOAR tools
AWS
GCP
Azure
Kubernetes
Docker
Forensics tools

Job description

CoinDesk is the most trusted media, events, indices and data company for the global crypto economy. Since 2013, CoinDesk Media has led the story of the future of money and investing, illuminating the transformation in society and culture that comes with it. Our award-winning team of journalists delivers news and unparalleled insights that bring transparency, comprehension and context. CoinDesk Events gathers the global crypto, blockchain and Web3 communities at annual events such as Consensus, the world’s largest and longest-running crypto festival. CoinDesk Indices offers expertise in digital asset indices, data and research to educate and empower investors. For more information on CoinDesk media and events, please visit http://coindesk.com [coindesk.com] and for breaking headlines, data and indices visit http://coindeskmarkets.com [coindeskmarkets.com] In November 2023, CoinDesk was acquired by the Bullish group, owner of Bullish, a regulated, digital assets exchange. For more information on Bullish, please visit https://bullish.com . CoinDesk operates as an independent subsidiary with an editorial committee to protect journalistic independence.

Reports to: Head of Security Engineering

Position Overview

We are seeking an experienced, hands-on Manager / Sr. Manager of SecOps & Cyber Defense to lead, scale, and actively drive our 24/7 security detection and response capabilities in the US, UK, & EMEA. In this dual-capability role, you will lead a lean, highly technical group of SOC analysts and incident responders while remaining deeply connected to the engineering work. You will sit in the hot seat during major incidents, build high-efficacy detection engineering pipelines across cloud and hybrid infrastructure, and continuously elevate our threat hunting and triage posture. This role is based in NYC and will be required to work onsite at our office located in Chelsea a minimum of 4 days per week. The position reports to the Head of Security Engineering.

Responsibilities
  • Leadership & Team Operations Manage & Mentor: Lead and mentor a small, high-performing team of SOC Analysts and Incident Response engineers across multiple time zones.
  • On-Call & Escalations: Serve as the primary point of escalation for high-severity security incidents, managing the global operational shift structure and continuous coverage model.
  • Metrics & Maturity: Define and track key SOC operational metrics (MTTD, MTTR, false positive ratios, incident coverage against MITRE ATT&CK) to drive continuous improvement.
  • Cross-Functional Collaboration: Partner closely with Infrastructure, Cloud Platform, DevOps, Corporate IT, Legal, and Compliance teams during critical triage and investigation phases.
  • Incident Management: Drive end-to-end response for major security incidents—from initial detection, containment, and eradication to root-cause analysis and post-mortem reporting.
  • Detection Engineering: Design, write, and tune high-precision detection rules (SIEM, EDR, Cloud-native logs) to minimize noise and highlight sophisticated threat activity.
  • Forensics & Triage: Perform hands-on digital forensics (memory, disk, network artifact analysis) and reverse-engineer suspicious scripts/payloads when necessary.
  • Threat Research & Readiness: Conduct targeted research into emerging threat actor TTPs, zero-days, and cloud vulnerabilities to preemptively fortify detection capabilities and response playbooks.
  • Adversarial Testing & Exercises: Lead and participate in regular Red/Purple team operations and executive tabletop exercises to stress-test incident response readiness and validate control coverage.
  • Threat Hunting: Proactively hunt for undetected threat actor behavior using internal logs, intelligence feeds, and custom queries.
  • SOAR & Automation: Build and refine automated response playbooks using Python, API integrations, and SOAR tools to streamline repetitive analyst workflows.
Experience & Qualifications
  • 8+ years of dedicated, hands-on experience in SOC operations, threat detection, and security incident response.
  • 2+ years of direct people management or formal team leadership experience, preferably overseeing a geographically distributed workforce.
  • Deep operational expertise in investigating cloud-native threats (AWS, GCP, or Azure), container environments (Kubernetes, Docker), and modern SaaS infrastructure.
  • Advanced proficiency with modern SIEM platforms, EDR/XDR suites, log aggregators, and SOAR tools.
  • Strong scripting and automation skills in Python, Bash, or Go to automate triage tasks and query APIs.
  • Strong knowledge of network protocols, cloud architecture, identity systems (Okta, Azure AD), and digital forensics fundamentals.
  • Proven ability to stay calm, decisive, and communicative under pressure during high-severity security incidents.
Nice-to-Have
  • Prior experience in Financial Services, FinTech, Digital Assets, or high-throughput trading environments operating under strict regulatory audit standards (SOC 2, ISO 27001, SEC/FINRA frameworks).
  • Relevant industry certifications such as GIAC (GCIH, GCFA, GNFA, GCDA), CISSP, or OSCP.

Bullish US LLC & CoinDesk Inc. are committed to offering competitive compensation and benefits. The anticipated base salary for this position is $185,000 - $235,000 + discretionary annual target bonus + performance incentives/benefits. Offered salary will be reflective of job related knowledge, skills and commensurate experience.

EQUAL OPPORTUNITY

In an effort to attract, retain, develop and promote the most qualified individuals, CoinDesk is committed to treating all applicants and employees in a nondiscriminatory manner with respect to the terms and conditions of employment, without regard to race, color, religion or belief, sex, national or ethnic origin, ancestry, age, marital status, sexual orientation, gender identity, veteran status/service, physical or mental disability, or any other classification protected by applicable law.

This mandate governs all aspects of employment, including recruitment, selection, promotion, training, education, social and recreation programs, compensation, discipline, termination and access to benefits.

ACCOMMODATION

CoinDesk is also committed to providing reasonable accommodations to individuals with disabilities.

If you need a reasonable accommodation because of a disability for any part of the application process, please send an e-mail to recruiting@coindesk.com and let us know the nature of your request. Learn more at www.coindesk.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Program Manager
Program Manager

Bullish, Inc. • New York (NY)

On-site
USD 200,000 - 250,000
Discretionary bonus
Performance incentives
Senior Accountant
Senior Accountant

CoinDesk • New York (NY)

On-site
USD 135,000 - 150,000
SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

Crane Company • Stamford (CT)

On-site
USD 90,000 - 130,000
BSA/AML Officer
BSA/AML Officer

CoinDesk • New York (NY)

On-site
USD 175,000 - 215,000
Lead Software Engineer, BTH Engineering
Lead Software Engineer, BTH Engineering

CoinDesk • New York (NY)

On-site
USD 250,000 - 280,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Manager, Security Engineering
Manager, Security Engineering

The Trade Desk • Ventura (CA)

On-site
USD 124,000 - 229,000
Health insurance
401k with company match
Stock-based compensation (plans)
Manager, Security Engineering
Manager, Security Engineering

The Trade Desk • Denver (CO)

On-site
USD 125,000 - 229,000
Healthcare
401(k) plan
Disability coverage
+4
Global SecOps Leader: Incident Response
Global SecOps Leader: Incident Response

Bullish, Inc. • New York (NY)

On-site
USD 185,000 - 235,000
Sr. Backend Engineer II (Hybrid)
Sr. Backend Engineer II (Hybrid)

CrowdStrike, Inc. • New York (NY)

On-site
USD 160,000 - 250,000
Market leader in compensation and equity awards
Comprehensive wellness programs
Competitive vacation and holidays
+3