Senior Manager, Security Operations

Motive

Seattle (WA)

On-site

USD 140,000 - 200,000

Full time

43 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health benefits
Dental & vision coverage
401k contribution
Paid time off
Disability coverage

Job summary

Motive is hiring a Senior Manager, Security Operations to establish and lead Motive's SOC across cloud, production, and enterprise environments. You will shape the detection strategy, runbooks, and 24/7 incident response, acting as incident commander during significant events while driving automation and AI-first improvements.

You will own the telemetry platform, threat hunting, threat intelligence, and endpoint/workload security, building a small senior team to tackle hard security problems

Qualifications

  • 8+ years in security operations, incident response, detection engineering or threat intelligence.
  • 3+ years leading teams and mentoring security staff.
  • Hands-on experience writing detections and leading incidents as commander.
  • Experience rebuilding or building a SOC function from the ground up.
  • Strong experience with modern detection tools (SIEM, EDR, SOAR) and cloud-native telemetry.
  • Deep cloud and container security monitoring, with AWS and Kubernetes preferred.
  • Identity-centric attack path expertise across SaaS and cloud.

Responsibilities

  • Stand up and grow the SOC with an AI-first, data-driven operating model.
  • Own detection strategy across production and cloud estates and map to MITRE ATT&CK.
  • Lead 24/7 incident response and act as incident commander for major incidents.
  • Own telemetry, analytics platform, and automation for MTTD/MTTR and coverage.
  • Establish threat hunting and threat intelligence programs aligned to Motive’s sector.
  • Architect and build triage, enrichment, correlation, and investigation automation.

Job description

Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. For the first time ever, safety, operations and finance teams can manage their drivers, vehicles, equipment, and fleet related spend in a single system. Combined with industry leading AI, the Motive platform gives you complete visibility and control, and significantly reduces manual workloads by automating and simplifying tasks.

Motive serves nearly 100,000 customers – from Fortune 500 enterprises to small businesses – across a wide range of industries, including transportation and logistics, construction, energy, field service, manufacturing, agriculture, food and beverage, retail, and the public sector.

We are hiring a Senior Manager, Security Operations to build, lead and grow Motive's SOC. This is a founding leadership role — you will shape the team, the tooling, the detection strategy and the operating model rather than inheriting a mature organization and maintaining it. Reporting to the CISO, you will own the full detection and response lifecycle: detection engineering, 24/7 incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload security.

The scope spans Motive's entire estate. Product and production environments cover the cloud infrastructure, services, APIs and data platforms behind Fleet Management, Driver Safety, Spend Management, Workforce Management and AI Vision, plus the connected device fleet. Enterprise and corporate systems cover endpoints, identity and SSO, SaaS applications, network, email and internal tooling. These estates have different telemetry, threat models and response constraints — you cannot contain a production workload the way you isolate a laptop — and a central part of this role is running them as one detection and response capability with one view of the adversary, because real attacks cross the boundary between them.

The mandate is coverage: we want to detect everything that goes wrong. That is a deliberately high bar, and it is an engineering problem rather than a staffing problem. We expect this SOC to be built AI-first and data-driven from day one, designed around automation from the start rather than staffing a traditional tiered analyst model and layering automation on later. Success looks like a small, senior, highly leveraged team whose time goes to hard problems, not queue processing.

What You’ll Do:
  • Stand up and grow the SOC — operating model, coverage structure, runbooks, escalation paths, hiring and career development for a globally distributed team — and decide the 24/7 coverage model, whether in-house follow-the-sun, MDR-augmented or hybrid
  • Own Motive's detection strategy and coverage posture across both estates, treating detection content as code and mapping coverage explicitly against MITRE ATT&CK and Motive's own threat model, with a live view of gaps closed in risk order
  • Extend detection into production and cloud workloads in close partnership with Platform Engineering — the highest-priority coverage expansion for the function — and build detections that span the boundary, since identity compromise on a corporate endpoint pivoting into cloud infrastructure is the attack path that matters most
  • Own 24/7 incident response across product and enterprise environments, serve as incident commander for significant incidents, and be the calm, credible voice to executives when one is underway
  • Own the security telemetry and analytics platform — collection, normalization, enrichment, retention and cost — and instrument the function honestly on MTTD, MTTR, detection coverage, alert precision and automation rate
  • Establish a structured, hypothesis-driven threat hunting program and a threat intelligence capability tailored to Motive's sector, translating intel into detections, hunts and hardening priorities rather than newsletters
  • Own EDR across the corporate fleet and, with Platform Engineering, runtime and workload protection for production, treating any unmonitored endpoint as an open finding rather than an accepted condition
  • Own the operational side of phishing and social engineering defense — detection, reporting triage, takedown and credential-compromise response — partnering with the Compliance and Trust function, which owns simulation and awareness training
  • Architect the AI-first operating model for the SOC, personally building and iterating on triage, enrichment, correlation and investigation automation rather than delegating it to a vendor
What We’re Looking For:
  • 8+ years in security operations, incident response, detection engineering or threat intelligence, with 3+ years leading teams
  • Demonstrably hands-on. You have personally written detections, run investigations, led incidents as commander and built automation — recently, not early in your career. Be prepared to walk through work you did with your own hands
  • Experience building or substantially rebuilding a SOC function, rather than only operating within an established one
  • Credible across both estates — production and cloud security monitoring as well as corporate and enterprise security operations. Candidates strong in only one should be ready to show how they would build the other
  • Deep experience with modern detection and response tooling — SIEM and security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry — plus strong detection engineering skills you can apply personally
  • Strong background in cloud and container security monitoring, with AWS and Kubernetes strongly preferred, including the practical reality that production monitoring must be introduced without destabilizing production
  • Solid grounding in identity-centric attack paths — SSO, OAuth, session compromise, MFA bypass and privilege escalation across SaaS and cloud
  • Proven incident command experience on significant incidents, including executive communication under pressure, and the judgment to elevate appropriately without crying wolf or sitting on something serious
  • Concrete, demonstrated use of AI to run security operations — triage, enrichment, detection authoring, investigation support or reporting. We will ask what you built, what it replaced, and what it measurably changed. General enthusiasm for AI is not what we're looking for
  • Experience building 24/7 coverage and leading globally distributed teams across multiple timezones. Experience in transportation, logistics, IoT and connected devices, or critical infrastructure is a plus

Pay Transparency
Your compensation may be based on several factors, including education, work experience, and certifications. For certain roles, total compensation may include restricted stock units. Motive offers benefits including health, pharmacy, optical and dental care benefits, paid time off, sick time off, short term and long term disability coverage, life insurance as well as 401k contribution (all benefits are subject to eligibility requirements). Learn more about our benefits by visiting Motive Perks & Benefits

The base compensation range for this role is:

$140,000 - $200,000 USD

Creating a diverse and inclusive workplace is one of Motive's core values. We are an equal opportunity employer and welcome people of different backgrounds, experiences, abilities and perspectives.

Please review our Candidate Privacy Notice here .

The applicant must be authorized to receive and access those commodities and technologies controlled under U.S. Export Administration Regulations. It is Motive's policy to require that employees be authorized to receive access to Motive products and technology.

Regarding US-based roles, depending on your role and primary work location, Motive Technologies, Inc. (“Employer”) discloses candidates may be required to execute a non-compete covenant with the Employer. This requirement does not apply to lawyers, interns, or employees working in CA, MN, MT, ND, OK, or where otherwise prohibited by law.

Non-compete covenant terms in all other jurisdictions will be subject to the applicable statutory requirements, including but not limited to, procedures, industry related prohibitions, or salary and compensation thresholds.

All job postings are for existing vacancies. Please note; some interviews or new-hire training sessions may be held in person at one of our global offices.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Motive’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, Security Operations
Senior Manager, Security Operations

Gomotive • Northern (KY)

On-site
USD 140,000 - 200,000
Health benefits
Paid time off
401k plan
Senior HR Business Partner — Temporary / Fixed-Term (6 Months) New United States - Remote
Senior HR Business Partner — Temporary / Fixed-Term (6 Months) New United States - Remote

Gomotive • Northern (KY)

On-site
USD 110,000 - 152,000
Senior Counsel, Employment
Senior Counsel, Employment

Gomotive • Northern (KY)

Hybrid
USD 175,000 - 241,000
Health, pharmacy, optical and dental
Paid time off
Sick time off
+3
Director, Readiness & Customer Education New United States - Remote
Director, Readiness & Customer Education New United States - Remote

Gomotive • Northern (KY)

Hybrid
USD 208,000 - 260,000
Health benefits
401k plan
Regional Vice President, Strategic East Sales New United States - Remote
Regional Vice President, Strategic East Sales New United States - Remote

Gomotive • Northern (KY)

Remote
USD 220,000 - 320,000
Account Executive, Enterprise - Texas
Account Executive, Enterprise - Texas

Gomotive • Town of Texas (WI)

Hybrid
USD 230,000 - 300,000
Health, dental, vision benefits
401k contribution
Paid time off
Director, Developer Platform & Experience
Director, Developer Platform & Experience

Motive • San Francisco (CA)

On-site
USD 229,000 - 285,000
GTM AI Engineer -Deal Desk New United States - Remote
GTM AI Engineer -Deal Desk New United States - Remote

Gomotive • Northern (KY)

Remote
USD 140,000 - 160,000
Sales Operations Manager, Implementation
Sales Operations Manager, Implementation

Gomotive • Northern (KY)

Hybrid
USD 106,000 - 133,000
Health benefits
Dental benefits
Vision benefits
+6
Senior Sales Recruiter
Senior Sales Recruiter

Motive • San Francisco (CA)

On-site
USD 118,000 - 163,000
Health benefits
Pharmacy benefits
Dental & vision care benefits
+5