
Manager, MSIAM SOC Engineering
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California.
• Lead, mentor, and oversee a team of SOC and Detection Engineers.
• Foster career development, enhance team retention, and ensure operational excellence.
• Provide hands-on technical guidance by assessing architectures, writing Python code, and designing intricate automation playbooks.
• Investigate emerging threats, platform capabilities, and security frameworks.
• Identify, scope, and prioritize content packs, integrations, and automation projects.
• Manage end-to-end detection and playbook development processes.
• Maintain accountability for KPIs such as SLA adherence, detection quality, deployment speed, and customer satisfaction.
• Collaborate with Unit 42 research teams and Cortex Engineering to convert threat research into deployable XSIAM capabilities and platform enhancements.
• Uphold standards for staging, testing, soft implementation, and ongoing tuning.
• Act as a senior technical escalation point for high-priority client engagements and architecture evaluations.
• Over 3 years of experience directly managing security engineering or SOC teams in an enterprise or managed services context.
• More than 5 years of experience with Detection Engineering, SIEM, SOAR, and EDR/XDR platforms.
• Strong hands-on coding skills, particularly in Python.
• Practical experience with Detection-as-Code (DaC).
• Familiarity with CI/CD pipelines for playbook deployment.
• Experience with stringent software development lifecycles within a SOC environment.
• Deep understanding of APT attack lifecycles, encompassing initial access, lateral movement, data exfiltration, and persistence methods.
• Ability to design complex correlation logic and automated workflows.
• Proven track record of driving engineering execution in line with defined SLAs and quality standards.
• Outstanding collaborative and stakeholder communication abilities.
• Preferred: experience utilizing AI, LLMs, or Machine Learning in Security Operations.
• Preferred: experience in Incident Response or Threat Hunting.
• Preferred: familiarity with Cortex XSIAM or Cortex XSOAR.
• Preferred: knowledge of MITRE ATT&CK framework.
• Must be able to work without immigration sponsorship; the employer will not sponsor work visas.
• Restricted stock units may be included.
• Bonus opportunities may be available.
• Employee benefits are provided (specific benefits not listed).
• Reasonable accommodations are available for qualified individuals with disabilities or special needs.
Axians Somnitec AG
Mercury Insurance
CCM Tecnologia
EBS-IT
Get handpicked remote jobs straight to your inbox weekly.