
Manager, Security Operations
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Recruit, cultivate, and enhance a team of security engineers focused on protecting endpoints, SaaS, and infrastructure.
• Manage security for corporate SaaS applications and endpoints, which includes configuration hardening and oversight of vulnerabilities and patches.
• Direct security operations and incident response as the senior Incident Commander for the Security Incident Response Team.
• Oversee and fine-tune the detection and response processes along with the CrowdStrike detection platform.
• Develop and sustain detection coverage across endpoints, SaaS, identity, audit and usage logs, egress-proxy traffic, DLP events, and access trails.
• Collaborate with teams to establish controls that reduce external exposure, such as network allowlists, egress proxy, and proxy-level DLP.
• Work alongside AppSec to seize detection opportunities unveiled by penetration testing.
• Establish standards for detection and response quality and coverage, and report on related metrics.
• Perform enterprise-wide cybersecurity risk assessments across infrastructure, endpoints, applications, and business processes.
• Develop Forward’s AI security capabilities from the existing detection and response tools, including executing the hiring strategy for a specialized team.
• A minimum of 7 years in detection engineering, security operations, or incident response, with experience in team leadership.
• Extensive knowledge of adversary TTPs and MITRE ATT&CK framework.
• Proven experience with event correlation and designing high-signal detection.
• Practical experience with EDR/SIEM platforms and detection-as-code methodologies.
• Experience in incident command encompassing triage, containment, forensics, and communication with stakeholders under pressure.
• Familiarity with securing SaaS environments and endpoint fleets, including configuration management, access governance, and vulnerability/patch management.
• Ability to articulate risk and priorities effectively to engineers and executives.
• Experience with cloud control-plane monitoring and identity threat detection within AWS.
• Proficiency in scripting and automation using Python, Ruby, or Go.
• A Bachelor’s Degree in Computer Science or a related technical field, or equivalent industry experience.
• Familiarity with SSPM or CASB tools.
• CISSP and/or CISM certification is preferred.
• Experience with red-team activities is advantageous.
• Familiarity with Gen-AI triage or LLM-as-Judge patterns in production is a plus.
• Flexible hours
• Flexible work location, including options for working from home or the office
• Medical insurance
• Dental insurance
• Vision insurance
• Commuter benefits
• Flexible time-off policy
• Paid parental leave
• 401(k) matching for employees in the US
• Wellness reimbursement
• Volunteering days
• Annual budget for professional development
• Charitable donation matching
• Opportunities for virtual and in-person team events and colleague engagement activities
Zepto
Forward Financing
Included Health
phia, LLC
Get handpicked remote jobs straight to your inbox weekly.