
ASO Threat Analyst Manager
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Florida, +4 more states.
• Take ownership of daily shift execution, maintain queue hygiene, and manage alert velocity to adhere to client SLAs and SLOs.
• Oversee the human-in-the-loop operational interface and validate outputs from agentic AI triage, enriched telemetry, and automated investigations.
• Perform ticket audits and conduct spot-check investigations for high-fidelity analysis, defensible evidence, and client-facing documentation.
• Act as the primary point of escalation during critical P1/P0 security incidents and client crises.
• Manage shift handoffs, identify operational bottlenecks, and balance the workload among analysts.
• Lead tactical After-Action Reviews to uncover process inefficiencies and outline remediation steps.
• Direct and mentor Senior Threat Analysts while facilitating handoffs with Detection Engineering, SOAR Engineering, and Threat Hunting teams.
• Oversee analyst feedback, tuning requests, automation proposals, and hunt referrals.
• Monitor cross-team action items and ensure accountability until completion.
• De-escalate challenging client interactions and lead discussions on incidents with clients.
• Collaborate with Client Success Managers on accounts that are at risk or experiencing high noise levels.
• Provide real-time investigation guidance, scenario walkthroughs, and technical quality reviews to analysts.
• Assist analysts in utilizing autonomous and agentic tools while fostering critical thinking and investigative capabilities.
• Manage shift schedules, coverage models, and on-call rotations effectively.
• Guide analysts towards achieving technical career milestones in threat hunting, detection engineering, and advanced incident response.
• 6 to 8+ years of experience in Information Security, with a robust technical background in threat analysis, network traffic analysis, or systems administration.
• 3+ years of experience within an active SOC, MDR, or MSSP environment.
• 1 to 2+ years in a tactical lead, supervisory, or senior escalation role.
• Proven experience in de-escalating challenging client interactions and guiding conversations toward constructive outcomes.
• Capability to coach senior technical staff, delegate operational tasks, and maintain quality control and cross-team alignment.
• Hands-on experience with AI-assisted triage, SOAR playbooks, or agentic security workflows.
• Proficiency in managing live incident triage and queue dynamics under pressure in a multi-tenant services model.
• Familiarity with modern EDR/XDR and SIEM tools, including Google SecOps, CrowdStrike, SentinelOne, Microsoft Defender/Sentinel, or Splunk.
• Practical knowledge of the MITRE ATT&CK framework and common adversary techniques.
• Strong verbal and written communication skills, adaptable to various audiences.
• Bachelor's degree in a technical discipline or equivalent hands-on operational experience.
• Direct experience in collaborating with Detection Engineering and SOAR automation pipelines.
• Understanding of ITIL-aligned ticketing workflows, such as ServiceNow or Jira.
• Active technical certifications such as GCIH, GCIA, CySA+, or vendor-specific platform certifications.
• A company dedicated to our inclusive values through our Employee Resource Groups.
• Emphasis on work/life balance.
• Access to professional training resources.
• Opportunities for creative problem-solving and tackling unique, complex projects.
• Volunteer opportunities through “Optiv Chips In.”
• The necessary tools and technology to work productively from home or remotely (where applicable).
Motorola Solutions
Gartner
LouisianaNOW.Jobs
Get handpicked remote jobs straight to your inbox weekly.