
Manager II, Security Operations
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Minnesota.
• Lead the Security Operations within the Cyber Engineering & Defense team.
• Directly oversee the Cyber Defense engineers and analysts.
• Manage an 8-person L1/L2 SOC contractor pod following a managed-services approach.
• Take responsibility for SOC operational performance, including alert triage MTTD/MTTR, true-positive rate, ticket throughput, and time-to-containment.
• Act as the incident commander for Severity 1 and escalated security incidents.
• Oversee severity determination, cross-functional and executive communications, and resolution pathways.
• Hold operational accountability for AI agents within the SOC and the detection-and-response pipeline.
• Establish escalation thresholds, human-in-the-loop checkpoints, and quality controls for outputs.
• Manage the relationship with the MSP/contractor, focusing on onboarding, performance, retention, and escalation quality.
• Translate the Cyber Defense strategy into a practical SecOps roadmap.
• Oversee the SecOps Jira project and quarterly sequencing.
• Ensure the quality of Cyber Defense tools, including SIEM detection content, source health, CrowdStrike administration, NG-SIEM migration, and SOAR runbooks.
• Maintain a healthy 24x7 on-call rotation across both FTE and contractor coverage.
• Provide daily management, coaching, weekly one-on-ones, and career development for Cyber Defense personnel.
• Collaborate with Agentic Cyber Engineering to define, develop, and deliver agentic systems.
• Minimum of 8 years in security operations, detection engineering, or incident response.
• Proven experience in maturing Cyber capabilities and driving organizational transformation.
• Demonstrated experience in Sev1 incident command with cross-functional engineering and executive communications.
• Strong track record of managing a multi-quarter security program from start to finish, including roadmap, execution, and measurable risk reduction.
• Experience in managing MSP/MSSP relationships at scale, including renewal economics, scope adjustments, and consolidation decisions.
• Familiarity with EDR, SIEM, SOAR, and ticketing tools.
• Proficient with tools such as CrowdStrike, NG-SIEM/Panther/Splunk/Sentinel, Tines/Torq/Phantom, and Jira.
• Proven ability to coach engineers, run effective one-on-ones, and provide clear performance feedback.
• Preferred 3+ years of direct people management experience, including hiring, performance management, and career development.
• Direct experience with CrowdStrike Falcon, Panther, Tines, AWS, EKS, and Atlassian is preferred.
• Familiarity with supply chain attack patterns and CI/CD security is preferred.
• Experience working with distributed or offshore SOC teams is preferred.
• Experience in directing or overseeing AI agents in an operational service-delivery context is preferred.
• Knowledge of agentic frameworks and orchestration such as LangGraph or agent tool-use pipelines is preferred.
• Industry certifications like GIAC GCIH/GCIA/GCDA, OSCP, or CISSP are preferred.
• Health insurance
• Dental insurance
• Vision insurance
• Disability insurance
• Life insurance
• Paid time-off
• 401(k)
• Health and flexible spending accounts
• Stock purchase plan
• Hybrid work with remote flexibility
• Opportunities for in-person collaboration
Pax8
EDB
Get handpicked remote jobs straight to your inbox weekly.