Sr SOC and IR Manager (Remote or On Site)

102 Crane Company

Stamford (CT)

Remote

USD 140,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Comprehensive health
Wellness incentives
Retirement savings
Paid time off
Paid holidays
Tuition reimbursement
Bonus programs

Job summary

Crane Company is seeking a Senior Manager, Security Operations & Incident Response to lead our SOC and IR program. This hands-on leader will shape the operating model, mentor a distributed team, and coordinate across Global Information Security, IT, and business units to deliver security outcomes worldwide.

You will act as incident commander for high-severity investigations, drive automation, and advance detection across endpoints, networks, cloud, and identity telemetry.

Qualifications

  • 7+ years relevant professional experience in security operations and incident response.
  • 3+ years managing or leading others in a security operations/incident response context.

Responsibilities

  • Lead and continuously improve the SOC and incident response program.
  • Serve as incident commander for high-severity investigations, coordinating cross-functional response and driving clear decisions, timelines, and communications.
  • Lead and develop a distributed team of analysts/engineers; build a culture of learning, quality, and operational excellence.
  • Own detection and response capability across endpoint, network, cloud, SaaS, and identity telemetry; tune to reduce noise.
  • Define, maintain, and test playbooks/runbooks and escalation paths; drive readiness via exercises.
  • Drive automation and orchestration (SOAR) to streamline triage and response; integrate systems.
  • Guide AI-assisted workflows with governance and analyst enablement.
  • Manage SOC tooling, service partnerships, and performance with measurable SLAs.
  • Develop program metrics and executive-ready reporting; track improvements in speed and quality.
  • Partner with Legal, Privacy, HR, GRC, Risk Management, and IT to align response processes and communications.

Skills

SOC leadership
Incident response
SIEM engineering
SOAR / automation
Cross-functional leadership
Cloud security
Windows administration
Linux administration
Executive communications

Education

Degree in a related field
CISSP / CISM / GIAC certification

Tools

SOAR platforms
SIEM tools

Job description

Do you enjoy building and leading high-performing teams while staying close to the work? Are you energized by transforming security operations, modernizing detection and response, driving automation, and partnering across the business to raise readiness? We are looking for a hands-on leader to help shape and run our SOC and incident response program at scale. Crane is seeking a Senior Manager, Security Operations & Incident Response to lead our Security Operations Center and Incident Response (IR) program. This role helps to define the operating model, people leadership, and continuous improvement of our detection and response capabilities, partnering across Global Information Security, IT, and business teams to deliver security outcomes globally. This position reports to the CISO. In this role, you will lead our global incident response program, related processes and technologies, and the US and international SOC teams. This is a hands-on leadership role: you will coach and develop analysts, strengthen investigation and response standards, and help evolve our security operations across endpoint, network, cloud, SaaS, and identity telemetry using automation and modern workflows to increase speed, consistency, and quality. As a manager with global responsibilities for SOC and IR, you will bring a steady, practical approach under pressure and the ability to lead incident coordination across technical and non-technical stakeholders. You will be comfortable serving as an incident commander, making time-sensitive decisions, setting priorities, and guiding teams through investigation, containment, recovery, and follow-up improvements while communicating clearly with leadership throughout.

Responsibilities and Duties:
  • Lead and continuously improve the SOC and incident response program, including operating model, standard work, and outcomes.
  • Serve as incident commander for high-severity investigations, coordinating cross-functional response and driving clear decisions, timelines, and communications.
  • Lead and develop a distributed team of analysts/engineers; build a strong culture of learning, quality, and operational excellence.
  • Own detection and response capability across endpoint, network, cloud, SaaS, and identity telemetry; improve signal quality and reduce noise through tuning and engineering.
  • Define, maintain, and test playbooks/runbooks and escalation paths, drive readiness through exercises and continuous improvement.
  • Drive automation and orchestration (SOAR) to streamline triage and response, integrate systems, and reduce manual effort.
  • Guide thoughtful adoption of AI-assisted workflows to accelerate investigations and reporting, with appropriate validation, governance, and analyst enablement.
  • Manage SOC tooling, service partnerships, and performance; ensure clear expectations, measurable SLAs, and continuous value delivery.
  • Develop and maintain program metrics, KPIs, and executive-ready reporting; track effectiveness and drive improvements in speed, quality, and consistency.
  • Partner with Legal, Privacy, HR, GRC, Risk Management, and IT to align response processes, documentation, and communication practices.
  • Evaluate, plan, and implement security operations improvements and supporting solutions; keep practices aligned with evolving standards and best practices.
Qualifications and Competencies:
  • Experience managing, leading, and developing remote/distributed teams with diverse backgrounds and skill levels.
  • Demonstrated success designing and running SOC and incident response processes across traditional enterprise environments and modern cloud/SaaS services.
  • Strong, current knowledge of security operations tradecraft: alert triage, investigation, containment/recovery coordination, post-incident reviews, and continuous improvement.
  • Expertise with security telemetry and analytics: SIEM engineering, log normalization, detection content development, alert tuning, and correlation across endpoint/network/cloud/identity sources.
  • Working knowledge of security automation/orchestration (SOAR) and integration patterns (APIs, webhooks, scripting) to reduce toil and improve response consistency.
  • Strong fundamentals in Windows and Linux administration, networking, and modern enterprise services; able to go deep when needed and translate technical details for stakeholders.
  • Solid understanding of identity and access controls (SSO, MFA, conditional access concepts) and the role of identity telemetry in detection and response.
  • Ability to lead high-severity investigations with calm, clarity, and strong judgment; comfortable serving as incident commander and coordinating across teams.
  • Excellent written and verbal communication skills, including executive-ready status updates, post-incident reporting, and roadmap/strategy presentations.
  • Familiarity with relevant privacy, regulatory, and eDiscovery considerations for incident response (documentation, evidence handling, and reporting workflows).
  • Strong project leadership skills with a track record of delivering measurable improvements.
  • Flexibility to support incident response needs outside of standard business hours, as required.
  • Ability to travel both domestically and internationally (est. no more than 10%).
  • Supportive leader: highly motivated, self-directed, collaborative, and perpetually curious.
  • Commitment to ongoing security learning and professional development (training and certifications).
Required:
  • 7+ years relevant professional experience in security operations and incident response.
  • 3+ years managing or leading others in a security operations/incident response context.
Preferred:
  • Degree in a related field or equivalent practical experience.
  • Advanced professional security certifications (e.g., CISSP, CISM, GIAC or similar).

US Person as defined under EAR PART 772 AND ITAR 120.15.

This description has been designed to indicate the general nature and level of work being performed by employees within this classification. It is not designed to be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.

Crane Company. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, gender, sexual orientation, general identity, national origin, disability or veteran status.

At Crane, we believe that attracting and retaining the highest quality people is the best insurance of success. Our goal is to recruit talented people and train them within a culture that calls for performance with trust and respect. Join us. The unique backgrounds and differences of our associates make us stronger, more capable, and more successful.

Beyond an associate’s base compensation, we reward and reinforce wellbeing with a compelling package of both cash and non-cash benefits, including comprehensive health, wellness incentives, assistance with retirement savings, paid time off, paid holidays, and tuition reimbursement — as well as performance-based bonus programs for certain positions.

  • comprehensive health
  • wellness incentives
  • assistance with retirement savings
  • paid time off
  • paid holidays
  • tuition reimbursement
  • performance-based bonus programs for certain positions

Crane prioritizes career development for our associates. All associates receive an annual development plan that includes a mixture of on-the-job coaching and formal training experiences to support individual development needs. We firmly believe in associate growth that supports career progression and we will proactively support your ongoing career development.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

102 Crane Company • Stamford (CT)

Remote
USD 140,000 - 180,000
SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

Crane Company • Stamford (CT)

On-site
USD 90,000 - 130,000
Global Security Engineer Offensive Operations (Remote or Onsite)
Global Security Engineer Offensive Operations (Remote or Onsite)

102 Crane Company • Stamford (CT)

Remote
USD 120,000 - 180,000
IT Site Operations Lead
IT Site Operations Lead

744 Crane ChemPharma & Energy Corp • Cincinnati (OH)

On-site
USD 110,000 - 150,000
Global Network Security Engineer (Remote)
Global Network Security Engineer (Remote)

102 Crane Company • Stamford (CT)

Hybrid
USD 130,000 - 180,000
Cyber Defense Detection and Automation Engineer
Cyber Defense Detection and Automation Engineer

Crane NXT, Co. • Northern (KY)

On-site
USD 100,000 - 180,000
Cyber Defense Detection and Automation Engineer
Cyber Defense Detection and Automation Engineer

Crane NXT • United States

On-site
USD 120,000 - 150,000
Global Security Operations Center Analyst (Physical Security)
Global Security Operations Center Analyst (Physical Security)

Crane Worldwide Logistics • Houston (TX)

On-site
USD 65,000 - 95,000
Quarterly Incentive Plan
Paid Time Off (PT0)
Medical, Dental and Vision benefits
+5
IT Internal Auditor - Remote
IT Internal Auditor - Remote

102 Crane Company • Stamford (CT)

Remote
USD 90,000 - 130,000
Health benefits
Paid time off
Tuition reimbursement
Global Security Operations Center Supervisor
Global Security Operations Center Supervisor

Crane Worldwide Logistics LLC • Houston (TX)

On-site
USD 85,000 - 115,000
Quarterly Incentive Plan
Paid Time Off 17 days/year
Medical, Dental and Vision
+5