SOC Manager

United Data Technologies, Inc.

Town of Florida (NY)

Hybrid

USD 120,000 - 150,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Healthcare benefits
401(k) with company match
Unlimited paid time off

Job summary

United Data Technologies, Inc. in Miramar, FL, is seeking a hands-on SOC Manager to lead a 24x7x365 security operations center, align playbooks with client SLAs, and drive high-severity incident response.

You will mentor analysts, own escalation paths, coordinate with NOC, PS Cyber, and partners, and ensure compliant, evidence-based security operations across multi-client environments.

Qualifications

  • Seven+ years in security operations with SOC leadership.
  • Experience with co-delivery MDR models and managed SIEM/EDR.
  • Strong incident management and cross-functional collaboration.
  • Excellent written and verbal English; executive communication.

Responsibilities

  • Lead and manage the daily operations of the 24x7x365 SOC.
  • Supervise and develop the SOC team with clear direction.
  • Own escalation matrix and defined runbooks.
  • Ensure SOC aligns with policies, SLAs, and client needs.
  • Establish on-call rotations and shift handoffs.
  • Oversee incident management from detection to post-incident review.

Skills

SOC management
Incident response
Playbooks
Leadership
Client communication

Education

Bachelor's degree in Cybersecurity/IT/CS
Master's degree preferred

Tools

Huntress
Google Chronicle
CrowdStrike
ConnectWise
Microsoft Defender
Datto SIRIS
KnowBe4

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

SOC Manager

Regular Full-Time Professionals Miramar, FL, US

UDT is a national technology solutions provider that modernizes, connects, secures, and manages technology environments for commercial enterprises, state and local governments, and educational institutions. The trusted advisor to many of the nation’s top K-12 school districts and corporate leaders across a spectrum of industries including hospitality, health care, financial services and more – UDT offers one of the most robust suites of customizable, end-to-end technology solutions in the industry. With a portfolio that spans IT managed services, endpoint lifecycle solutions, cybersecurity, networking, computing, cloud, connectivity, and voice services, UDT helps clients align technology with their most important business priorities – empowering insight-driven IT strategies that accelerate innovation, streamline costs, and reduce risk. Founded in 1995 and headquartered in Miramar, Florida, UDT has more than 400 professionals nationwide and growing operational facilities in Florida, Tennessee, Texas, and South Carolina. For more information, visit udtonline.com.

This position is hybrid, located in Miramar, FL

SOC Manager

The SOC (Security Operations Center) Manager is responsible for the strategic and day-to-day operational management of UDT’s 24x7x365 SOC, ensuring effective monitoring, detection, investigation, and response to cyber threats across client and internal environments. The SOC Manager leads a team of SOC Supervisors, Analysts (Levels 1, 2, and 3), and dispatchers, providing the leadership, structure, and process discipline required to maintain a reliable and continuously improving managed-security operation.

This role holds operational ownership of UDT’s managed detection and response (MxDR) delivery. It sits between the per-account Service Delivery Managers (SDMs) and senior leadership within the escalation chain, and is accountable for ensuring that SOC operations run on documented playbooks and defined on-call rotations rather than on individual knowledge or availability.

The SOC Manager collaborates closely with UDT’s Help Desk; Governance, Risk and Compliance (GRC) Team; Professional Services Cyber Security Team, which commands major-incident response; the NOC, which executes infrastructure containment; and UDT’s delivery partners and SIEM/SOAR platform providers, ensuring all security operations align with client SLAs, contractual obligations, and regulatory requirements.

UDT is seeking an experienced, hands-on security operations leader to assume operational ownership of the SOC. The successful candidate will demonstrate:

  • Direct technical engagement. Comfortable working within the toolset (Huntress, Google Chronicle, CrowdStrike, ConnectWise) — producing reports, extracting metrics, and authoring playbooks personally. This is a working management position rather than a purely supervisory one.
  • The ability to operate independently. A record of taking ownership of an objective and executing it with limited day-to-day direction.
  • An improvement orientation. Experience assessing an established operation objectively, applying industry best practices, and strengthening operational discipline.
  • Customer-facing composure. Skill in conflict resolution and in conducting client conversations with professionalism and credibility.
  • Audience-appropriate communication. Able to engage in technical depth with analysts, engineers, and partners, and to present the same material to executive and client audiences in business terms. Strong written and verbal English is required, including the ability to independently produce clear, professional correspondence and reports.
Responsibilities:
SOC Operations Management:
  • Lead and manage the daily operations of the 24x7x365 SOC, ensuring timely detection, triage, investigation, and response to security events across all delivery paths.
  • Supervise and develop the SOC team — Supervisors, Analysts (Levels 1, 2, and 3), and the dispatcher pool — providing direction, coaching, and accountability.
  • Own the escalation matrix and serve as the standing intermediate tier within the UDT escalation chain (SDM to SOC Manager to senior leadership), ensuring escalations follow a defined path.
  • Maintain and refine incident-response playbooks, standard operating procedures (SOPs), runbooks, and escalation protocols so that response procedures are documented, repeatable, and independent of any individual.
  • Ensure the SOC operates in accordance with UDT security policies, contractual scope, and client SLAs.
Coverage, Shift Discipline, and On-Call:
  • Establish and own a defined, rotating, documented on-call tier so that after-hours and weekend escalation follows a published rotation.
  • Establish a formal shift-handoff process at each shift overlap — a structured written and verbal pass of open incidents, watch items, pending customer callbacks, and in-flight investigations, logged in ConnectWise — to maintain continuity across the shift overlaps (Shifts 1, 2, and 3) and at the UDT-partner boundary.
  • Define and enforce after-hours coverage standards, ensuring overnight and dispatcher coverage follows documented response procedures rather than automated notification alone.
Incident Detection and Response:
  • Oversee all phases of incident management — detection, triage, investigation, containment, and post-incident review — across UDT’s detection stack:
  • Huntress (Managed EDR/MDR/ITDR — Ransomware Canaries, Persistent Footholds)
  • Google Chronicle (SIEM, SOAR, and threat-intelligence plane)
  • CrowdStrike (alternate endpoint MDR engine), Microsoft Defender (managed endpoint telemetry), Datto SIRIS (backup and disaster recovery), and KnowBe4 (security awareness)
  • Act as the senior point of escalation for high-severity incidents, coordinating the SOC, NOC, PS Cyber, the customer, and, where engaged, legal and executive leadership.
  • Operate within UDT’s defined control boundaries:
  • Infrastructure containment follows a SOC-to-NOC handoff — the SOC raises the ticket and the NOC executes — managed to avoid delay at the handoff.
  • Major-incident response command resides with PS Cyber. The SOC detects, confirms true-positive status and indicators of compromise, and provides support.
  • Support the adoption of pre-authorized emergency incident-response authorization so that containment of a confirmed breach is not delayed pending contractual approval.
  • Ensure breach-notification requirements — for example, contractual 24-hour written notification for regulated accounts — are tracked and met, escalating legal determinations to counsel.
Partner and Vendor Operational Governance:
  • Assume operational ownership of UDT’s co-delivery and managed-SIEM partner relationships, including participation in partner quarterly business reviews with a UDT-maintained coverage, escalation, miss-rate, and SLA scorecard, and governance of the UDT-partner handoff.
  • Manage the operational fit of SOC subcontractors and partners with respect to coverage, shift, and escalation. Cost decisions route to Finance.
  • Evaluate detection and response tooling for operational effectiveness and recommend stack changes to SecOps.
Detection Coverage and Tuning Quality:
  • Build and maintain a single, UDT-owned, validated MITRE ATT&CK coverage baseline spanning the Huntress and Chronicle paths, including customer-tenant Sentinel, mapped to ingested log sources, with gaps ranked and tracked.
  • Maintain a detection-tuning and false-positive backlog feeding the SIEM/SOAR platform and governing tool-direct alert volume. Detection quality is addressed through tuning; alert suppression is not an acceptable substitute.
  • Partner with the SIEM/SOAR platform’s detection-engineering function — parser and UDM mapping, use-case authoring, and detection scoring — so that UDT’s coverage view consumes those outputs rather than duplicating them.
SLAs, Metrics, and Reporting:
  • Maintain outcome-based SLAs and SLOs. MTTA, MTTD, and MTTR are measured against the defined, severity-based classification-completion clock, including the 60-day Service Alignment Phase and documented pause states.
  • Own the monthly Customer Service Review (CSR) and quarterly business review (QBR) cadence: coverage assessment, MITRE use-case coverage, alert breakdown, and gap reporting via UDT HUB, ARMED, and Smart Analytics.
  • Report metrics that accurately reflect risk reduction and response performance, including known gaps.
Team Development and Mentorship:
  • Provide leadership, mentorship, and career development for the SOC team; conduct performance reviews and identify training and certification paths.
  • Partner with Human Resources on role standards and professional development plans to build out the Level 1 to Level 2 to Level 3 analyst progression and senior-bench depth. Indicative certification path: Security+, CrowdStrike Falcon, BTL1, MITRE ATT&CK, and CySA+, advancing toward CISSP, CISM, or GCIH for senior roles.
Compliance and Stakeholder Engagement:
  • Ensure SOC activities align with applicable frameworks and regulations across the client base, including NIST, ISO 27001, CIS, MITRE ATT&CK, HIPAA, PCI-DSS, and GLBA for regulated accounts, and others as contracted.
  • Serve as a primary SOC point of contact for senior leadership and clients regarding SOC performance, the threat landscape, and incidents.
Other:
  • Enter time and all work — activities, service tickets, and project tickets — into the ConnectWise Manage PSA as it occurs.
  • This position is based at UDT’s headquarters in Miramar, FL and follows a hybrid schedule; occasional travel to customer sites may be required.
  • Other duties related to the scope of the department and the business may be assigned.
Education and Experience:
  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field; master’s degree preferred.
  • Seven or more years in security operations, including at least three years in a SOC leadership or management role.
  • Demonstrated experience managing SOC teams and directing high-severity incidents in a fast-paced, multi-client MSSP or MSP environment.
  • Experience operating a co-delivery or partner-fronted MDR model (managed SIEM and EDR delivered through partners) is strongly preferred.
Technical Skills:
  • Working fluency with a modern MDR stack: EDR and MDR platforms (Huntress, CrowdStrike, Microsoft Defender); SIEM and SOAR platforms (Google Chronicle, or comparable platforms such as Microsoft Sentinel or Splunk); and ticketing and PSA-driven escalation. Familiarity with ConnectWise Manage is a strong plus.
  • Strong command of incident management, threat intelligence, forensic fundamentals, and vulnerability-management processes.
  • Working knowledge of MITRE ATT&CK as a coverage‑design and validation discipline.
  • Understanding of cybersecurity frameworks and regulatory regimes, including NIST, ISO 27001, HIPAA, PCI-DSS, and GLBA.
Certifications:
  • Manager-level security certification required or strongly preferred: CISSP or CISM.
  • Governance, risk, and audit credentials, one or more strongly preferred: CISA or CRISC.
  • Hands-on detection and incident‑response credentials, one or more a plus: GCIH, GCIA, GIAC, or CEH.
  • Baseline expected: CompTIA Security+ or CySA+.
  • Operational excellence, a plus: ITIL Foundation and a process‑improvement credential such as Lean Six Sigma (Green Belt or above).
Soft Skills:
  • Strong leadership and team‑building skills, with the ability to motivate and develop a diverse, multi‑tier SOC team.
  • Sound judgment under pressure during high‑severity incidents.
  • Clear communication of complex technical matters to technical, non‑technical, executive, and client audiences.
  • Strong organizational and prioritization skills in a 24x7, multi‑client environment.
Required Knowledge, Skills, and Abilities:
  • Cross‑functional leadership, with the ability to lead and achieve results with a strong customer orientation.
  • Strategic planning across a 6‑ to 12‑month horizon, with the discipline to operationalize the plan.
  • Excellent written and verbal communication, including the ability to translate technical issues into business terms.
  • Self‑directed, results‑driven, detail‑oriented, and accurate, with the ability to manage multiple priorities concurrently.
  • Proficiency with Microsoft Office and the ability to develop reports, recommendations, and executive and client presentations.
What UDT offers you

We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to the organization. UDT’s Total Rewards package includes medical, dental, vision, life and disability coverage as of the 1 st of the month, health savings accounts, flexible savings accounts, 401(k) plan with company match, 7 annual holidays and unlimited paid time off options.

Join us and be part of an inclusive, energizing, and collaborative environment. UDT is an Equal Opportunity Employer who is committed to workforce diversity. Qualified applicants will receive consideration without regard to age, race, color, religion, sex, sexual orientation, disability, or national origin. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Employment is contingent upon successful completion of background and pre-employment drug screen. UDT is not currently hiring individuals for this position who now or in the future require sponsorship for employment visa status

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Manager
SOC Manager

ADP, Inc. • Town of Florida (NY)

Hybrid
USD 130,000 - 170,000
SOC Manager
SOC Manager

United Data Technologies • Town of Florida (NY)

Hybrid
USD 120,000 - 150,000
Medical coverage
Dental coverage
Vision coverage
+3
SOC Manager
SOC Manager

UDT • Town of Florida (NY)

Hybrid
USD 140,000 - 180,000
Medical benefits
Dental benefits
401(k) match
Senior SOC Analyst | MDR
Senior SOC Analyst | MDR

UltraViolet Cyber • United States

Remote
USD 100,000 - 110,000
401(k) match
Health, Dental, Vision insurance
Life Insurance
+3
Service Desk Manager
Service Desk Manager

ADP, Inc. • Town of Florida (NY)

Hybrid
USD 90,000 - 130,000
Dispatcher
Dispatcher

Sucrée • Town of Florida (NY)

Hybrid
USD 35,000 - 50,000
Service Desk Manager
Service Desk Manager

UDT • Town of Florida (NY)

Hybrid
USD 90,000 - 120,000
Hybrid/Remote work
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

Remote
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
SOC Manager
SOC Manager

GMI - Global Market Innovators • Scottsdale (AZ)

On-site
USD 100,000 - 130,000
Competitive salary and benefits package
401(k) match
Stock Appreciation Rights
+2
SOC Analyst
SOC Analyst

DMI • Crownsville (MD)

On-site
USD 90,000 - 130,000