Senior Manager, Security Operations

gomotive

United States

Remote

USD 140,000 - 200,000

Full time

5 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision coverage
401(k) contributions
Disability & life insurance
Paid time off & sick leave

Job summary

gomotive is seeking a founding security leader to build and run a modern SOC for a multi-product technology organization serving diverse sectors in the United States. You will own the end-to-end detection and response across production cloud and corporate IT, with a vision of a small, senior, automation-driven team rather than a traditional analyst model.

You’ll stand up a scalable SOC, define detection strategy linked to MITRE ATT&CK, and lead 24/7 incident response as incident commander while

Qualifications

  • Senior leadership experience building or transforming a SOC with hands-on detection engineering
  • Experience with SIEM/EDR/SOAR and cloud telemetry
  • Cloud and container security monitoring; AWS and Kubernetes preferred
  • Identity-centric attack paths across SaaS and cloud
  • Incident command experience with executive communication
  • Demonstrated AI/automation use in security operations

Responsibilities

  • Stand up and scale the SOC with operating model, runbooks, escalation paths, hiring plans, and 24/7 coverage model
  • Define and own the detection strategy end-to-end mapped to MITRE ATT&CK and internal threat model
  • Lead 24/7 incident response as incident commander and communicate with executives
  • Own the security telemetry and analytics platform, including data collection, normalization, enrichment, retention, and cost control
  • Build a hypothesis-driven threat hunting program and a tailored threat intel function
  • Partner with Platform Engineering to extend detection into production and cloud workloads

Skills

Leadership
Detection engineering
Incident command
AI/automation in SecOps

Tools

SIEM
EDR
SOAR
Cloud telemetry
AWS
Kubernetes

Job description

Role overview

This is a founding leadership opportunity to build and run a Security Operations Center (SOC) for a large, multi-product technology organization serving nearly 100,000 customers across logistics, construction, energy, manufacturing, retail, and the public sector. Reporting to the CISO, the role owns the full detection-and-response lifecycle across both the production cloud estate (services, APIs, data platforms, and connected-device fleets) and the corporate IT environment (endpoints, identity, SaaS, email, network). Success looks like a small, senior, automation-driven team rather than a traditional tiered analyst model.

Responsibilities
  • Stand up and scale the SOC, including operating model, runbooks, escalation paths, hiring plans, and the chosen 24/7 coverage model (in-house follow-the-sun, MDR-augmented, or hybrid)
  • Define and own the detection strategy end-to-end, treating detection content as code and mapping coverage explicitly to MITRE ATT&CK and an internal threat model
  • Lead 24/7 incident response across product and enterprise environments, serving as incident commander for significant events and communicating with executives under pressure
  • Own the security telemetry and analytics platform, including collection, normalization, enrichment, retention, and cost discipline, while measuring MTTD, MTTR, coverage, precision, and automation rate
  • Build a hypothesis-driven threat hunting program and a tailored threat intelligence function that produces detections, hunts, and hardening priorities
  • Partner with Platform Engineering to extend detection into production and cloud workloads, with priority coverage for identity-to-cloud pivot paths and unmonitored endpoints or workloads
Requirements
  • Senior leadership experience building or substantially transforming a SOC, with hands-on detection engineering capability
  • Deep familiarity with modern detection-and-response tooling: SIEM or security data platforms, EDR, SOAR or equivalent automation, and cloud-native telemetry
  • Strong background in cloud and container security monitoring, with AWS and Kubernetes experience preferred
  • Solid understanding of identity-centric attack paths across SSO, OAuth, session compromise, MFA bypass, and privilege escalation in SaaS and cloud
  • Demonstrated incident command experience on significant incidents, with sound escalation judgment and credible executive communication
  • Concrete, measurable use of AI and automation inside security operations, with examples of what was built, what it replaced, and what changed
Benefits and work setup
  • Base compensation range of $140,000–$200,000 USD, with total compensation potentially including equity for certain roles
  • Benefits include medical, pharmacy, dental, and vision coverage, paid and sick time off, short- and long-term disability, life insurance, and 401(k) contributions, subject to eligibility
  • Globally distributed team with flexible time-zone coverage; some interviews or onboarding may occur in person at a global office
  • Must be authorized to access U.S.-export-controlled technology
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Lead
Security Operations Lead

Segment (Twilio) • Foster City (CA)

On-site
USD 140,000 - 210,000
Health, Dental, Vision
401(k)
Paid time off
+2
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

Hybrid
USD 110,000 - 150,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Senior Detection and Response Analyst
Senior Detection and Response Analyst

Prestige Staffing • Dallas (TX)

On-site
USD 120,000 - 180,000
Contract extension potential
Remote work
Career growth
+2
Cybersecurity Operations & Incident Response Manager
Cybersecurity Operations & Incident Response Manager

Jobgether • Town of Texas (WI)

Hybrid
USD 162,000 - 200,000
Competitive salary range: $162,681 – $200,000
Health, dental, and vision coverage
401(k) retirement savings plan
+3
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

Hybrid
USD 120,000 - 180,000
Principal Consultant – SOC Transformation and XSIAM Deployment
Principal Consultant – SOC Transformation and XSIAM Deployment

Palo Alto Networks • California (MO)

On-site
USD 163,000 - 184,000
Detection & Response Engineering Manager
Detection & Response Engineering Manager

InfraTech Solutions LLC • Chicago (IL)

Hybrid
USD 150,000 - 180,000
Health, dental, and vision insurance
Paid time off and holidays
Parental leave
+2
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000