Threat Management Leader: SOC, IR & Intelligence

RXinsider LTD.

Naperville (IL)

On-site

USD 168,000 - 253,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Ecolab seeks a Senior Director of Threat Management to lead an enterprise-wide threat detection and response program. You will oversee SOC, CTI, detection engineering, and incident response, driving improvements in MTTD and MTTR across a global Fortune 500 environment.

You will lead a 24x7 monitored operation, mature threat intelligence integration, and partner with platform engineering to ensure robust tooling and telemetry. Strong leadership and governance skills are essential.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or related discipline; equivalent experience may be considered.
  • 12+ years of progressive experience in cybersecurity, security operations, threat detection, incident response, or threat intelligence.
  • 5+ years of leadership experience managing multi-team security operations or threat functions at Senior Manager or Director level.
  • Demonstrated success leading detection and response programs across SOC operations, detection engineering, threat intelligence, and incident response.
  • Experience managing 15+ person organizations including managers, analysts, and engineers with varied technical specializations.
  • Experience leading major incident response and driving measurable improvement in detection coverage and response times.
  • Experience building or standing up new detection, intelligence, or response capabilities, teams, or services.

Responsibilities

  • Define enterprise threat detection and response strategy, roadmap, and operating model aligned to cybersecurity, risk, and business objectives.
  • Mature the threat management program through governance, playbooks, standards, metrics, and leadership reporting.
  • Present detection and response posture, incident trends, risks, and investment needs to leadership and executives.
  • Establish and monitor KPIs such as MTTD, MTTR, detection coverage, and alert quality.
  • Lead prioritization decisions across SOC, threat intelligence, detection engineering, and IR functions.
  • Lead 24x7 SOC operations for monitoring, triage, and initial investigation.
  • Own detection content lifecycle within the SIEM and data onboarding/retention requirements.
  • Drive improvements in alert quality, triage efficiency, and analyst workflow.
  • Establish tiered operating models, shift coverage, escalation paths for 24x7 readiness.
  • Oversee SOC performance metrics and service levels.
  • Lead detection engineering to build, tune, and maintain detection content.
  • Drive detection-as-code with version control, testing, and MITRE ATT&CK mapping.
  • Prioritize detection development using threat intel, red team findings, and learnings.
  • Establish metrics for detection coverage, efficacy, and false positives.
  • Partner with engineering and platform teams to ensure high-quality telemetry for detection pipelines.
  • Lead the Cyber Threat Intelligence function for strategic, operational, and tactical intelligence.
  • Operationalize threat intelligence with indicator enrichment and threat actor tracking.
  • Deliver executive threat briefings translating threat into business risk.
  • Establish threat hunting programs to search for adversary activity proactively.
  • Manage intelligence sources and integration into SIEM, SOAR, and detection workflows.
  • Own enterprise incident response process across detection, triage, containment, eradication, recovery, and review.
  • Lead major incident coordination and drive cross-functional response.
  • Establish incident response playbooks, runbooks, and tabletop exercises.

Skills

Cybersecurity leadership
SOC management
Threat detection
Incident response
Strategic thinking
Executive communication
Task prioritization

Education

Bachelor’s degree in CS/Cybersecurity/IT/Engineering

Tools

SIEM
SOAR
log management
Elasticsearch
Splunk
MITRE ATT&CK
Threat intelligence platforms

Job description

Ecolab seeks a Senior Director of Threat Management to lead an enterprise-wide threat detection and response program. You will oversee SOC, CTI, detection engineering, and incident response, driving improvements in MTTD and MTTR across a global Fortune 500 environment.

You will lead a 24x7 monitored operation, mature threat intelligence integration, and partner with platform engineering to ensure robust tooling and telemetry. Strong leadership and governance skills are essential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of Global Threat Detection & Response
Director of Global Threat Detection & Response

ECOLAB • Naperville (IL)

On-site
USD 168,400 - 252,600
Bonus potential
Long-term incentives
Director of Security Engineering & CTEM
Director of Security Engineering & CTEM

ECOLAB • Naperville (IL)

On-site
USD 137,400 - 206,200
Cyber Threat Management Lead | SOC & Incident Response
Cyber Threat Management Lead | SOC & Incident Response

WPS Data Logistics, Inc. • Madison (WI), Northern (KY)

Hybrid
USD 140,000 - 180,000
Security Operations Leader: Detection, IR & Platform Engineering
Security Operations Leader: Detection, IR & Platform Engineering

Envista Holdings Corporation • Brea (CA)

On-site
USD 156,000 - 191,000
Annual bonus
Medical benefits
401K match
+1
CTI Lead Analyst: Threat Intel & Incident Response
CTI Lead Analyst: Threat Intel & Incident Response

3M HEALTHCARE • Indianapolis (IN)

Remote
USD 162,000 - 269,000
Company-sponsored benefits
Vacation benefits
Medical, dental, vision benefits
+1
Cyber Threat Intel & SOC Leader
Cyber Threat Intel & SOC Leader

Williams-Sonoma, Inc. • San Francisco (CA)

On-site
USD 170,000 - 202,000
401(k) plan and investment options
Paid vacation & holidays
Health, dental, vision benefits
+2
Senior Enterprise Security Operations & Detection Lead
Senior Enterprise Security Operations & Detection Lead

Jobtailor • Brea (CA)

On-site
USD 170,000 - 250,000
Senior CTIR Engineer: Threat Intel & Incident Response
Senior CTIR Engineer: Threat Intel & Incident Response

Xplor • Atlanta (GA)

On-site
USD 120,000 - 180,000
Paid parental leave
Diversity & Inclusion initiatives
Mental health support
+3
Threat Intel & Testing Manager
Threat Intel & Testing Manager

PRI Technology • Austin (TX)

On-site
USD 110,000 - 140,000
Senior SOC Lead: Threat Hunting & IR (Remote)
Senior SOC Lead: Threat Hunting & IR (Remote)

SPS Commerce • Minneapolis (MN)

Hybrid
USD 108,000 - 140,000