SOC Manager

TEKsystems

Rocklin (CA)

On-site

USD 96,000 - 103,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental & vision
401(k) Retirement Plan
Life Insurance
Short and long-term disability
Health Spending Account
Transportation benefits
Employee Assistance Program
Time Off/Leave

Job summary

TEKsystems in Rocklin, CA seeks a Manager, Cyber Threat Intelligence & Security Operations to lead a team of approximately 12 cybersecurity professionals across Threat Intelligence, Detection Engineering, Security Operations, and Incident Response.

This is a hands-on management position responsible for the operational effectiveness of the Security Operations Center while driving the organization's threat intelligence program and continuously improving detection capabilities.

Qualifications

  • 7–10 years in Cyber Security across SOC, threat intel, detection, and IR.
  • Experience leading enterprise Security Operations Centers.
  • Hands-on with SIEM, SOAR, EDR, endpoint security.
  • Strong communication and leadership skills with ability to influence executives.

Responsibilities

  • Lead day-to-day SOC activities including monitoring, investigations, containment, eradication, and recovery.
  • Direct major cyber incident response from identification through post-incident review.
  • Develop and maintain incident response playbooks and procedures.
  • Partner with cross-functional teams to improve security platforms and detection capabilities.
  • Ensure alignment with MITRE ATT&CK and current threat landscape.

Skills

Cyber threat intel
SOC leadership
Threat detection
Incident response
Security operations

Tools

SIEM
SOAR
EDR
Threat intel platforms

Job description

Job Description

As the Manager, Cyber Threat Intelligence & Security Operations, you will lead a team of approximately 12 cybersecurity professionals across Threat Intelligence, Detection Engineering, Security Operations, and Incident Response. This is a hands-on technical management position responsible for the operational effectiveness of the Security Operations Center while driving the organization's threat intelligence program and continuously improving detection capabilities. You will work closely with Security Engineering, Identity & Access Management, Cloud Security, Enterprise Architecture, Legal, Privacy, Fraud Prevention, and Information Technology teams to ensure cyber threats are rapidly identified, investigated, and mitigated.

Responsibilities
Leadership & Team Management

Lead, mentor, and develop a multidisciplinary team consisting of:

  • Cyber Threat Intelligence Analysts
  • Detection Engineers
  • SOC Analysts
  • Incident Responders
  • Foster a collaborative, high-performing culture focused on operational excellence and continuous learning
  • Provide technical coaching, career development, and mentorship across the organization
  • Establish operational priorities and coordinate security response activities across multiple teams
  • Serve as the escalation point during significant security incidents
Security Operations Center Leadership
  • Lead day-to-day Security Operations Center activities including monitoring, investigation, containment, eradication, and recovery efforts
  • Direct major cyber incident response activities from identification through post-incident review
  • Ensure operational readiness for security events across cloud, on-premises, endpoint, identity, and application environments
  • Drive continuous improvement of operational procedures, investigation methodologies, and response playbooks
  • Partner with Security Engineering to improve operational supportability of security platforms
Cyber Threat Intelligence
  • Lead the enterprise Cyber Threat Intelligence program
  • Oversee intelligence collection, analysis, enrichment, and dissemination
  • Monitor emerging threat actors, campaigns, vulnerabilities, and industry trends
  • Translate external intelligence into actionable defensive capabilities
  • Manage Indicators of Compromise (IOCs), adversary tracking, and threat intelligence repositories
  • Produce executive and technical threat intelligence briefings
  • Partner with Fraud, Legal, Privacy, and business leadership regarding emerging cyber risks
Detection Engineering
  • Lead development and continuous improvement of enterprise detection capabilities
  • Oversee SIEM content development and detection engineering
  • Drive detection use-case development and continuous tuning
  • Improve alert fidelity while reducing false positives
  • Lead proactive threat hunting initiatives
  • Develop new analytics based on adversary tactics, techniques, and procedures (TTPs)
  • Ensure security content aligns with the MITRE ATT&CK framework and current threat landscape
Security Platforms

Provide technical leadership for security operations technologies including:

  • Google SecOps
  • CrowdStrike Falcon
  • Cortex XSOAR
  • MISP Threat Intelligence Platform
  • Tanium
  • Collaborate with Security Engineering regarding architecture, upgrades, integrations, and operational improvements across the enterprise security technology stack.
Incident Response
  • Lead enterprise cyber incident response activities
  • Coordinate investigations involving malware, ransomware, insider threats, account compromise, phishing, and advanced attacks
  • Direct technical response teams during high-severity incidents
  • Conduct post-incident reviews and identify opportunities to strengthen defenses
  • Develop and maintain incident response procedures, playbooks, and operational readiness
Governance & Cross-Functional Collaboration
  • Support regulatory investigations, internal audits, and security assessments
  • Prepare executive summaries and threat reports for security leadership
  • Partner closely with
  • Security Engineering
  • Identity & Access Management
  • Enterprise Security Architecture
  • Legal
  • Privacy
  • Fraud Prevention
  • Information Technology
  • Contribute to long-term cyber defense strategy and operational planning
Basic Qualifications
  • 7-10 years of experience in Cyber Security with expertise in Security Operations, Threat Intelligence, Detection Engineering, and Incident Response
  • Previous experience leading technical cybersecurity teams
  • Proven experience managing enterprise Security Operations Centers
  • Strong understanding of modern cyber threats, adversary tactics, and threat intelligence methodologies
  • Experience leading major cyber incident investigations
  • Hands-on experience with SIEM, SOAR, EDR, endpoint security, and threat intelligence platforms
  • Strong understanding of enterprise networking, operating systems, identity technologies, cloud environments, and application security
  • Excellent communication and leadership skills with the ability to influence technical and executive stakeholders
  • Experience mentoring engineers and analysts while fostering technical growth
Preferred Qualifications
  • Experience with Google SecOps
  • Experience with CrowdStrike Falcon
  • Experience with Cortex XSOAR
  • Experience with MISP or other Threat Intelligence Platforms
  • Experience with Tanium
  • Experience implementing threat hunting programs
  • Familiarity with MITRE ATT&CK, Cyber Kill Chain, Diamond Model, and intelligence-driven defense methodologies
  • Experience supporting regulatory investigations and compliance initiatives
  • Experience building or maturing enterprise detection engineering programs
  • Knowledge of automation and scripting using Python or PowerShell
Job Type & Location

This is a Permanent position based out of Rocklin,CA.

Pay and Benefits

The pay range for this position is $70.00 - $75.00/hr.

Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following:

  • Medical, dental & vision
  • Critical Illness, Accident, and Hospital
  • 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available
  • Life Insurance (Voluntary Life & AD&D for the employee and dependents)
  • Short and long-term disability
  • Health Spending Account (HSA)
  • Transportation benefits
  • Employee Assistance Program
  • Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type

This is a fully onsite position in Rocklin,CA.

Application Deadline

This position is anticipated to close on Sep 11, 2026.

San Francisco Fair Chance Ordinance

Per the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.

Massachusetts Lie Detector

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Use of Artificial Intelligence (AI)

We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.

Equal Opportunity Employer Statements

The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Manager
SOC Manager

TEKsystems • San Francisco (CA)

On-site
USD 96,000 - 103,000
Medical, dental & vision
401(k) retirement plan
Life insurance
+2
Security Engineer
Security Engineer

TEKsystems • Rocklin (CA)

On-site
USD 96,000 - 103,000
Medical, dental & vision
401(k) Retirement Plan - Pre-tax and R
Life Insurance (Voluntary Life & AD&D)
+5
Security Engineer
Security Engineer

TEKsystems • San Francisco (CA)

On-site
USD 96,000 - 103,000
Health benefits
401(k) plan
Life Insurance
+5
Aws & Devops Engineer
Aws & Devops Engineer

TEKsystems • Chicago (IL)

Hybrid
USD 103,000 - 110,000
Medical, dental & vision
401(k)
Life Insurance
+4
Sr. Cybersecurity Engineer
Sr. Cybersecurity Engineer

TEKsystems • Winston-Salem (NC)

Hybrid
USD 69,000 - 83,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+4
Lead Full Stack Python Developer (Agentic SOC)
Lead Full Stack Python Developer (Agentic SOC)

TEKsystems • Minneapolis (MN)

Hybrid
USD 123,000 - 131,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+5
Lead Full Stack Python Developer (Agentic SOC)
Lead Full Stack Python Developer (Agentic SOC)

TEKsystems • Charlotte (NC)

Hybrid
USD 123,000 - 131,000
Medical, dental & vision
401(k) Retirement Plan
Time Off/Leave
Staff Security Engineer I, Security Operations
Staff Security Engineer I, Security Operations

Etsy, Inc. • New York (NY)

On-site
USD 204,000 - 240,000
Equity package
Annual performance bonus
Competitive benefits supporting employees and families
Malware Analyst
Malware Analyst

TEKsystems • Irving (TX)

On-site
USD 57,000 - 81,000
Medical, dental & vision
401(k) retirement plan
Life Insurance
+5
Cyber Operations Lead, Critical Harm Operations
Cyber Operations Lead, Critical Harm Operations

Triwill Group • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Relocation assistance