Senior Manager of Security Operations

Motive

New York (NY)

On-site

USD 180,000 - 240,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Motive is seeking a Senior Manager, Security Operations to build and lead Motive’s SOC from the ground up. You will shape the team, tooling, detection strategy and operating model rather than inheriting a mature program.

Reporting to the CISO, you own detection engineering, 24/7 incident response, threat hunting, threat intelligence and security analytics across cloud, production and enterprise environments. You will run a globally distributed, AI‑driven team with one view of adversaries.

Qualifications

  • 8+ years in security operations, incident response, detection engineering or threat intelligence.
  • 3+ years leading teams.
  • Strong grounding in identity-centric attack paths — SSO, OAuth, session compromise, MFA bypass and privilege escalation across SaaS and cloud.

Responsibilities

  • Stand up and grow the SOC — operating model, coverage structure, runbooks, escalation paths, hiring and career development for a globally distributed team.
  • Own Motive’s detection strategy and coverage posture across both estates, mapping coverage explicitly against MITRE ATT&CK.
  • Own 24/7 incident response across product and enterprise environments and serve as incident commander for significant incidents.

Skills

Leadership
Incident response
Detection engineering
Threat hunting
Threat intelligence
Security analytics
Cloud security
Kubernetes
MITRE ATT&CK
Automation
Executive communication
Incident commander

Tools

AWS
Kubernetes
SIEM
EDR
SOAR

Job description

  • We are hiring a Senior Manager, Security Operations to build, lead and grow Motive’s SOC. This is a founding leadership role — you will shape the team, the tooling, the detection strategy and the operating model rather than inheriting a mature organization and maintaining it
  • Reporting to the CISO, you will own the full detection and response lifecycle: detection engineering, 24/7 incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload security
  • The scope spans Motive’s entire estate. Product and production environments cover the cloud infrastructure, services, APIs and data platforms behind Fleet Management, Driver Safety, Spend Management, Workforce Management and AI Vision, plus the connected device fleet. Enterprise and corporate systems cover endpoints, identity and SSO, SaaS applications, network, email and internal tooling
  • These estates have different telemetry, threat models and response constraints — you cannot contain a production workload the way you isolate a laptop — and a central part of this role is running them as one detection and response capability with one view of the adversary, because real attacks cross the boundary between them
  • The mandate is coverage: we want to detect everything that goes wrong. That is a deliberately high bar, and it is an engineering problem rather than a staffing problem. We expect this SOC to be built AI-first and data-driven from day one, designed around automation from the start rather than staffing a traditional tiered analyst model and layering automation on later
  • Success looks like a small, senior, highly leveraged team whose time goes to hard problems, not queue processing
  • Stand up and grow the SOC — operating model, coverage structure, runbooks, escalation paths, hiring and career development for a globally distributed team — and decide the 24/7 coverage model, whether in-house follow-the-sun, MDR-augmented or hybrid
  • Own Motive’s detection strategy and coverage posture across both estates, treating detection content as code and mapping coverage explicitly against MITRE ATT&CK and Motive’s own threat model, with a live view of gaps closed in risk order
  • Extend detection into production and cloud workloads in close partnership with Platform Engineering — the highest-priority coverage expansion for the function — and build detections that span the boundary, since identity compromise on a corporate endpoint pivoting into cloud infrastructure is the attack path that matters most
  • Own 24/7 incident response across product and enterprise environments, serve as incident commander for significant incidents, and be the calm, credible voice to executives when one is underway
  • Own the security telemetry and analytics platform — collection, normalization, enrichment, retention and cost — and instrument the function honestly on MTTD, MTTR, detection coverage, alert precision and automation rate
  • Establish a structured, hypothesis-driven threat hunting program and a threat intelligence capability tailored to Motive’s sector, translating intel into detections, hunts and hardening priorities rather than newsletters
  • Own EDR across the corporate fleet and, with Platform Engineering, runtime and workload protection for production, treating any unmonitored endpoint as an open finding rather than an accepted condition
  • Own the operational side of phishing and social engineering defense — detection, reporting triage, takedown and credential-compromise response — partnering with the Compliance and Trust function, which owns simulation and awareness training
  • Architect the AI-first operating model for the SOC, personally building and iterating on triage, enrichment, correlation and investigation automation rather than delegating it to a vendor

Demonstrably hands-on. You have personally written detections, run investigations, led incidents as commander and built automation — recently, not early in your career. Be prepared to walk through work you did with your own handsExperience building or substantially rebuilding a SOC function, rather than only operating within an established one8+ years in security operations, incident response, detection engineering or threat intelligence, with 3+ years leading teamsSolid grounding in identity-centric attack paths — SSO, OAuth, session compromise, MFA bypass and privilege escalation across SaaS and cloudStrong background in cloud and container security monitoring, with AWS and Kubernetes strongly preferred, including the practical reality that production monitoring must be introduced without destabilizing productionProven incident command experience on significant incidents, including executive communication under pressure, and the judgment to escape appropriately upon situational demandsExperience building 24/7 coverage and leading globally distributed teams across multiple timezones. Experience in transportation, logistics, IoT and connected devices, or critical infrastructure is a plusConcrete, demonstrated use of AI to run security operations — triage, enrichment, detection authoring, investigation support or reporting. We will ask what you built, what it replaced, and what it measurably changed. General enthusiasm for AI is not what we’re looking forDeep experience with modern detection and response tooling — SIEM and security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry — plus strong detection engineering skills you can apply personallyCredible across both estates — production and cloud security monitoring as well as corporate and enterprise security operations. Candidates strong in only one should be ready to show how they would build the other

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, Security Operations
Senior Manager, Security Operations

Motive • United States

On-site
USD 170,000 - 230,000
Senior Manager, Security Operations
Senior Manager, Security Operations

Gomotive • Northern (KY)

On-site
USD 140,000 - 200,000
Health benefits
Paid time off
401k plan
Founding SOC Leader — AI-Driven Detection & Response
Founding SOC Leader — AI-Driven Detection & Response

Motive • New York (NY)

On-site
USD 180,000 - 240,000
Founding Senior SOC Leader – Security Operations
Founding Senior SOC Leader – Security Operations

Motive • Seattle (WA)

On-site
USD 140,000 - 200,000
Health benefits
Dental & vision coverage
401k contribution
+2
Founding Head of Security Operations
Founding Head of Security Operations

Motive • United States

On-site
USD 170,000 - 230,000
AI-Driven SOC Lead: Detection & 24/7 Response
AI-Driven SOC Lead: Detection & 24/7 Response

Gomotive • Northern (KY)

Remote
USD 140,000 - 200,000
Health benefits
Paid time off
401k plan
Sr SOC and IR Manager (Remote or On Site)
Sr SOC and IR Manager (Remote or On Site)

Crane Co. • Stamford (CT)

Remote
USD 130,000 - 160,000
Director of Cyber Defense (AI-Focused)
Director of Cyber Defense (AI-Focused)

Gotham Technology Group • Irving (TX)

On-site
USD 180,000 - 260,000
SOC Lead
SOC Lead

ID.me • McLean (VA)

On-site
USD 140,000 - 190,000
Incident Detection/Response Manager (SOC Manager)
Incident Detection/Response Manager (SOC Manager)

ECS Corporate Services • Fairfax (VA)

Remote
USD 140,000 - 160,000