Sr. Manager, Technology - Security

Williams-Sonoma, Inc.

San Francisco (CA)

On-site

USD 170,000 - 202,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) plan and investment options
Paid vacation & holidays
Health, dental, vision benefits
Employee discounts
Learning & development opportunities

Job summary

Williams-Sonoma, Inc. seeks a hands‑on, strategic Manager of Cyber Threat Intelligence & Security Operations to lead a multidisciplinary team across threat intelligence, detection engineering, SOC, red team, and incident response.

You will shape strategy, drive execution, and oversee major security operations and modernization efforts. You will manage enterprise tools and coordinate with cross‑functional teams to mature detections, automate workflows, and reduce cyber risk across a global retail

Qualifications

  • 7–10 years of progressive experience in Cyber Security with expertise in Security Operations, Threat Intelligence, Detection Engineering, and Incident Response.
  • Proven experience managing technical teams and hands‑on approach to verify configurations and adjust settings.
  • Expertise across SIEM, SOAR, EDR, Threat Intelligence, endpoint security, penetration testing and incident response technologies.
  • Experience developing and reporting operational metrics including MTTD, MTTR, detection coverage, alert fidelity, incident trends, automation effectiveness, and threat intelligence impact.
  • Experience developing and executing a multi‑year roadmap to mature SOC capabilities across people, process, technology, and automation.
  • Strong understanding of enterprise networking, cloud, identity, operating systems, and modern attack techniques.
  • Excellent communication, leadership, and cross‑functional collaboration skills.

Responsibilities

  • Lead and mentor a ~24-person cybersecurity team across Threat Intelligence, Detection Engineering, Security Operations, Red Team, and Incident Response.
  • Define, execute, and mature the enterprise Cyber Threat Intelligence, Detection Engineering, and Security Operations strategy.
  • Oversee operation of Google SecOps, CrowdStrike, Cortex XSOAR, MISP, Tanium, and associated detection technologies.
  • Direct enterprise cyber incident response from initial triage through containment, eradication, recovery, and lessons learned.
  • Drive proactive threat hunting, IOC management, and intelligence collection and analysis.
  • Lead Detection Engineering including SIEM content development, use‑case creation, alert tuning, and detection quality improvements.
  • Expand automation and Ai-assisted capabilities to accelerate investigation and response.
  • Develop intelligence-driven detections based on evolving TTPs.
  • Lead Red Team operations including adversary emulation and purple team exercises.
  • Collaborate with IT, Legal, Privacy, and other teams to strengthen enterprise defenses.
  • Provide hands‑on support during major incidents and platform integrations.

Skills

Cyber Threat Intel
Security Operations
Incident Response
SIEM/SOAR/EDR
Threat Hunting
Leadership
Metrics & Reporting
MITRE ATT&CK
Cloud & Network

Tools

Google SecOps
CrowdStrike
Cortex XSOAR
MISP
Tanium

Job description

About the Team

You will lead the Cyber Threat Intelligence (CTI) and Security Operations (SOC) functions within the Cyber Security organization. This teamis responsible formonitoring, detecting, investigating, and responding to cyber threats while continuously improving the organization's detection and response capabilities. This role reports to the Director of Cybersecurity and is a critically strategic domain within the WSI Security Governance program.

The CTI and SOC team's mission is to proactively defend the enterprise byleveragingintelligence-driven operations, detection engineering, incident response, and threat hunting to reduce cyber risk and enable secure business operations.

About the Role

As Manager, Cyber Threat Intelligence & Security Operations, you will lead a multidisciplinary team of Threat Intelligence Analysts, Detection Engineers, SOC Analysts, and Incident Responders. This is a hands‑on technical leadership role where you will drive strategy, execution, and operations for this critical security domain while actively contributing to engineering and incident response efforts.

This role offers the opportunity to shape the future of cyber defense across a globally recognized portfolio of retail brands by building modern detection, response, intelligence, and automation capabilities.

Responsibilities
  • Lead, mentor, and develop approximately 24 cybersecurity professionals across Threat Intelligence, Detection Engineering, Security Operations, Red Team, and Incident Response; think Player/Coach, someone coaching from experience gained from being a former individual contributor.
  • Define, execute, and continuously mature the enterprise Cyber Threat Intelligence, Detection Engineering, and Security Operations strategy aligned to business risk.
  • Lead the operation and continuous evolution of Google SecOps, CrowdStrike, Cortex XSOAR, MISP, Tanium, and supporting detection technologies.
  • Direct enterprise cyber incident response frominitialtriage through containment, eradication, recovery, executive communications, and lessons learned.
  • Drive proactive threat hunting, adversary tracking, IOC management, and intelligence collection and analysis.
  • Lead Detection Engineering including SIEM content development, use‑case creation, alert tuning, and continuous improvements in detection quality.
  • Expand automation, orchestration and Ai-assisted capabilities toeliminaterepetitive analyst work and accelerate investigation and response.
  • Develop intelligence-driven detections based on emerging threat actor tactics, techniques, and procedures (TTPs).
  • Lead Red Team operations including adversary emulation, penetration testing, purple team exercises, and validation of defensive controls and ensure Detection Engineering translates findings into improved detections and defensive capabilities.
  • Partner with Security Engineering, Identity & Access Management, Enterprise Security Architecture, Legal, Privacy, Fraud, and Information Technology teams to strengthen enterprise cyber defenses.
  • Provide hands‑on support during major security incidents, investigations, platform integrations, and complex operational escalations.
  • Establish andmaintainoperational standards, playbooks, investigation procedures, and best practices.
  • Develop, track, and communicate key operational metrics and program maturity to executive leadership, driving continuous improvement through measurable outcomes.
  • Lead audit, governance, regulatory investigations, and executive cyber threat reporting.
Basic Qualifications
  • 7–10 years of progressive experience in Cyber Security withexpertisein Security Operations, Threat Intelligence, Detection Engineering, and Incident Response.
  • Proven experience managing technical teams and comfortable rolling up sleeves and logging into consoles to verify configurations and adjust settings.
  • Demonstratedexpertiseacross SIEM, SOAR, EDR, Threat Intelligence, endpoint security, penetrationtestingand incident response technologies.
  • Experience developing and reporting operational metrics including MTTD, MTTR, detection coverage, alert fidelity, incident trends, automation effectiveness, and threat intelligence impact.
  • Experience developing and executing a multi‑year roadmap to mature the organization's SOC capabilities across people, process, technology, and automation.
  • Strong understanding of enterprise networking, cloud, identity, operating systems, and modern attack techniques.
  • Excellent communication, leadership, and cross‑functional collaboration skills.
Preferred Qualifications
  • Hands‑on experience with Google SecOps, CrowdStrike, Cortex XSOAR, MISP, and Tanium.
  • Experience building or maturing enterprise Detection Engineering and Threat Intelligence programs.
  • Capable of delivering automation and scripting (Python, PowerShell, etc.); agentic AI experience is an emerging plus.
  • Experience supporting regulatory investigations, governance, and compliance initiatives.
  • Strong familiarity with MITRE ATT&CK and intelligence‑driven defense methodologies.
About Williams‑Sonoma, Inc.

Founded in 1956, Williams‑Sonoma, Inc. is the premier specialty retailer of high‑quality products for the home. Our family of brands includes Williams Sonoma, Pottery Barn, Pottery Barn Kids,PBteen, West Elm, Williams‑Sonoma Home,Rejuvenation, andMark and Graham. Today,we'rea multi‑brand, multi‑channel, global enterprise supported bystate‑of‑the‑arttechnology and talented teams.

Benefits

Once you are here, you can look forward to a wide variety of benefits designed to help you grow personally and professionally, keep you healthy, prepare you for the unexpected, care for your family, and build a secure future.

  • A generous associate discount across Williams‑Sonoma brands
  • 401(k) plan and investment opportunities
  • Paid vacation, holidays, and time‑off programs
  • Comprehensive health, dental, and vision benefits
  • Wellness and employeeassistanceprograms
  • Learning and development opportunities
  • Cross‑brand career opportunities
  • Volunteer time and matching charitable donations
Continued Learning
  • In‑person and online learning opportunities through WSI University
  • Cross‑brand and cross‑function career opportunities
  • Resources for self‑development
  • Advisor (Mentor) program
  • Career development workshops, learning programs, and speaker series

WSI will not now or in the future commence an immigration case or "sponsor" an individual for this position (for example, H‑1B or other employment‑based immigration).

This role is not eligible for relocation assistance.

Williams‑Sonoma, Inc. is an Equal Opportunity Employer. Williams‑Sonoma, Inc. will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance, or other applicable state or local laws and ordinances.

The expected starting pay range for this position is $170,000-$202,000. Applicable pay ranges may differ across markets. Actual pay will bedeterminedbased on experience and other job‑related factorspermittedby law. In addition to competitive pay, compensation may include a variety of other components like benefits, paid time off, merit, and bonus opportunities

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager Technology, Security Compliance
Manager Technology, Security Compliance

Williams-Sonoma, Inc. • Rocklin (CA)

On-site
USD 150,000 - 180,000
Discount on Williams-Sonoma brands
401(k) plan
Paid vacations and holidays
+1
Senior Manager, Technology Risk - Audit and Assurance
Senior Manager, Technology Risk - Audit and Assurance

Williams-Sonoma, Inc. • San Francisco (CA)

Hybrid
USD 170,000 - 190,000
401(k) plan
Health benefits
Paid vacations
+1
Producer, Photo - West Elm
Producer, Photo - West Elm

West Elm • New York (NY)

On-site
USD 75,000 - 84,000
Employee discount
401(k) plan
Paid vacations and holidays
+3
Analyst, Customer Relationship Marketing
Analyst, Customer Relationship Marketing

Williams-Sonoma, Inc. • San Francisco (CA)

On-site
USD 71,000 - 83,000
Generous discount on all WSI brands
401(k) plan and investment opportunities
Health benefits including dental and vision
+1
HR Generalist
HR Generalist

Williams-Sonoma, Inc. • San Francisco (CA)

On-site
USD 80,000 - 90,000
Employee discount
401(k) plan
Paid vacations and holidays
+4
Assistant Site Manager - Mark & Graham
Assistant Site Manager - Mark & Graham

Mark & Graham • San Francisco (CA)

On-site
USD 64,000 - 73,000
Generous discount on all WSI brands
401(k) plan
Paid vacations and holidays
+3
Associate Manager, Field Operations Asset Protection
Associate Manager, Field Operations Asset Protection

Williams-Sonoma, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 90,000 - 130,000
Discount on all brands
401(k) plan
Paid vacations
+3
Associate Inventory Planner - GreenRow
Associate Inventory Planner - GreenRow

Williams-Sonoma, Inc. • San Francisco (CA)

Hybrid
USD 71,000 - 84,000
Employee discount on Williams-Sonoma,
401(k) with company match
Paid vacations and holidays
+4
Inventory Planner, Bath - West Elm
Inventory Planner, Bath - West Elm

West Elm • New York (NY)

Hybrid
USD 71,000 - 84,000
A generous discount on all WSI brands
401(k) plan and other investment机会s
Paid vacations, holidays, and time off
+3
Manager, Inventory Management - Williams Sonoma
Manager, Inventory Management - Williams Sonoma

Williams-Sonoma, Inc. • San Francisco (CA)

Hybrid
USD 120,000 - 145,000
Employee discount
401(k) plan
Paid time off
+1