Sr SOC and IR Manager (Remote or On Site)

Crane Co.

Stamford (CT)

Hybrid

USD 130,000 - 160,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Crane Co. is looking for a Senior SOC and IR Manager to lead their Security Operations Center and Incident Response program. This remote or on-site position is crucial for driving improvements in security capabilities and managing a distributed team of analysts. Responsibilities include developing SOC processes, serving as incident commander during significant issues, and enhancing team's operational effectiveness. Strong leadership, communication, and technical skills in security operations are necessary for success.

Qualifications

  • Experience managing and developing remote teams.
  • Strong knowledge of alert triage, investigation, and incident coordination.
  • Expertise in producing executive-ready reports and presentations.

Responsibilities

  • Lead and improve the SOC and incident response program.
  • Serve as incident commander for high-severity investigations.
  • Develop and maintain metrics and reporting for the program.

Skills

Security operations tradecraft
Leadership and team development
Incident response processes
Security telemetry and analytics
Collaboration and communication
Automation/orchestration knowledge

Tools

SIEM
SOAR

Job description

Sr SOC and IR Manager (Remote or On Site) page is loaded## Sr SOC and IR Manager (Remote or On Site)remote type: Remotelocations: Stamford, Connecticuttime type: Full timeposted on: Posted Todayjob requisition id: JR101633Crane is seeking a Senior Manager, Security Operations & Incident Response to lead our Security Operations Center and Incident Response (IR) program. This role helps to define the operating model, people leadership, and continuous improvement of our detection and response capabilities, partnering across Global Information Security, IT, and business teams to deliver security outcomes globally. This position reports to the CISO.In this role, you will lead our global incident response program, related processes and technologies, and the US and international SOC teams. This is a hands-on leadership role: you will coach and develop analysts, strengthen investigation and response standards, and help evolve our security operations across endpoint, network, cloud, SaaS, and identity telemetry using automation and modern workflows to increase speed, consistency, and quality.As a manager with global responsibilities for SOC and IR, you will bring a steady, practical approach under pressure and the ability to lead incident coordination across technical and non-technical stakeholders. You will be comfortable serving as an incident commander, making time-sensitive decisions, setting priorities, and guiding teams through investigation, containment, recovery, and follow-up improvements while communicating clearly with leadership throughout.**Core Function****:**This role is responsible for leading our global SOC and the tools, processes, and people that enable effective detection and response. You will set direction for a modern SOC operating model, help mature response playbooks and standard work, and drive improvements in signal quality, analyst experience, and measurable outcomes.In this capacity, you will lead the delivery of processes and standard work for the global security operations function. This includes detection engineering and tuning, playbook/runbook development, informed monitoring, and high-quality investigations across endpoint, network, cloud, SaaS, and identity sources. This is a very hands-on position: you will participate in threat hunting, guide deep-dive investigations, and ensure service levels, operational hygiene, and team outcomes are consistently met.You will direct our use of SIEM, SOAR, and related platforms that power security operations, including integrations with identity, cloud, endpoint, and collaboration ecosystems. You will champion automation and orchestration to streamline triage and response, while thoughtfully adopting automation/AI workflows to accelerate analysis and decision-making with appropriate oversight.As the ideal candidate, you must have solid track record of results in successful security incident management and have prior experience in implementing automation to gain efficiencies, reduce errors, and increase capacity of an enterprise incident response program.You must have a strong desire to mature blue team tradecraft, to lead and mentor others, provide vision and strategic input, and to further your own development along the way.This role carries the expectation to be a subject matter expert in security operations and incident response readiness. You will define and lead all phases of preparation, identification, containment, eradication, and recovery, and will influence overall Global Information Security program direction and approach. You will help develop and implement security operations processes, standard work, and policy-aligned procedures, and will be responsible for maintaining operational metrics, KPIs, and executive-ready reporting to measure effectiveness and drive continuous improvement.You will work closely with the CISO, business leadership, Global InfoSec management, and IT leaders to strengthen incident preparedness and operational excellence. You will partner with Legal, Privacy, HR, and GRC to align response processes, evidence handling, and communications practices, and you will help plan and run exercises to keep teams ready. You will be expected to communicate effectively at all levels of the organization, be detail-oriented, and be focused on outcomes and measurable program goals. You must enjoy continuous improvement and have a genuine passion for security operations.This is an opportunity to make a visible impact on a global program alongside a team that values curiosity, craftsmanship, and collaboration. If you enjoy building capabilities, mentoring talent, and modernizing how security operations works day to day, you will find meaningful work and the support to keep growing at a strong and growing organization.**Responsibilities and Duties:*** Lead and continuously improve the SOC and incident response program, including operating model, standard work, and outcomes.* Serve as incident commander for high-severity investigations, coordinating cross-functional response and driving clear decisions, timelines, and communications.* Lead and develop a distributed team of analysts/engineers; build a strong culture of learning, quality, and operational excellence.* Own detection and response capability across endpoint, network, cloud, SaaS, and identity telemetry; improve signal quality and reduce noise through tuning and engineering.* Define, maintain, and test playbooks/runbooks and escalation paths, drive readiness through exercises and continuous improvement.* Drive automation and orchestration (SOAR) to streamline triage and response, integrate systems, and reduce manual effort.* Guide thoughtful adoption of AI-assisted workflows to accelerate investigations and reporting, with appropriate validation, governance, and analyst enablement.* Manage SOC tooling, service partnerships, and performance; ensure clear expectations, measurable SLAs, and continuous value delivery.* Develop and maintain program metrics, KPIs, and executive-ready reporting; track effectiveness and drive improvements in speed, quality, and consistency.* Partner with Legal, Privacy, HR, GRC, Risk Management, and IT to align response processes, documentation, and communication practices.* Evaluate, plan, and implement security operations improvements and supporting solutions; keep practices aligned with evolving standards and best practices.**Qualifications and Competencies:*** Experience managing, leading, and developing remote/distributed teams with diverse backgrounds and skill levels.* Demonstrated success designing and running SOC and incident response processes across traditional enterprise environments and modern cloud/SaaS services.* Strong, current knowledge of security operations tradecraft: alert triage, investigation, containment/recovery coordination, post-incident reviews, and continuous improvement.* Expertise with security telemetry and analytics: SIEM engineering, log normalization, detection content development, alert tuning, and correlation across endpoint/network/cloud/identity sources.* Working knowledge of security automation/orchestration (SOAR) and integration patterns (APIs, webhooks, scripting) to reduce toil and improve response consistency.* Strong fundamentals in Windows and Linux administration, networking, and modern enterprise services; able to go deep when needed and translate technical details for stakeholders.* Solid understanding of identity and access controls (SSO, MFA, conditional access concepts) and the role of identity telemetry in detection and response.* Ability to lead high-severity investigations with calm, clarity, and strong judgment; comfortable serving as incident commander and coordinating across teams.* Excellent written and verbal communication skills, including executive-ready status updates, post-incident reporting, and roadmap/strategy presentations.* Familiarity with
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead SOC IR Engineer - Remote/Hybrid
Lead SOC IR Engineer - Remote/Hybrid

Pearl Consulting Group • United States

Hybrid
USD 120,000 - 180,000
Senior Security Operations & Incident Response Engineer
Senior Security Operations & Incident Response Engineer

SCIGON • Chicago (IL)

On-site
USD 113,000 - 150,000
SOC Lead (Remote or Onsite)
SOC Lead (Remote or Onsite)

Crane Company • Stamford (CT)

On-site
USD 90,000 - 130,000
Security Operations Lead
Security Operations Lead

Jobtailor • Pennsylvania

On-site
USD 120,000 - 160,000
Engineer - SOC & IR
Engineer - SOC & IR

Pearl Consulting Group • United States

On-site
USD 120,000 - 180,000
SOC Manager
SOC Manager

HW3 • Jacksonville (FL)

On-site
USD 120,000 - 180,000
Incident Response Manager
Incident Response Manager

Sygnia, Inc. • United States

Hybrid
USD 140,000 - 180,000
Sr. SOC Analyst
Sr. SOC Analyst

HW3 • Village of Great Neck (NY)

On-site
USD 130,000 - 170,000
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

Remote
USD 120,000 - 150,000
Security Operations Center Manager
Security Operations Center Manager

Fidelity National Financial • Jacksonville (FL)

On-site
USD 140,000 - 180,000