
MDR Manager
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in Florida.
β’ Manage 24/7 shift coverage, escalation paths, and tiering while participating in an on-call rotation.
β’ Take ownership of response SLAs and report SOC KPIs to executive leadership.
β’ Perform quality assurance on resolved alerts and incidents, minimize false positives, and maintain runbooks, playbooks, and SOC standards.
β’ Lead, coach, and mentor MDR Analysts through one-on-one sessions, feedback, onboarding, and T1-to-T3 training.
β’ Facilitate tabletop exercises and conduct post-incident reviews.
β’ Act as the technical lead and final escalation point for Tier 3 incidents, guiding complex investigations through their full lifecycle while ensuring defensible documentation.
β’ Correlate alerts from EDR, ITDR, and email security systems.
β’ Execute proactive threat hunts in alignment with MITRE ATT&CK.
β’ Utilize Guardz AI agents, Google BigQuery, SQL, and KQL to triage and investigate high-volume logs.
β’ Collaborate with MSPs on significant incidents and posture reviews.
β’ Contribute incident findings to enhance detection capabilities in partnership with product, threat research, and engineering teams.
β’ Over 5 years of experience in SOC, MDR, or Incident Response managing complex attacks, including at least 2 years in a Team Lead, Shift Lead, or senior role.
β’ Proficient hands-on experience with EDR solutions, including SentinelOne, CrowdStrike, and Defender for Endpoint.
β’ Practical experience with ITDR across Microsoft 365 and Google Workspace.
β’ Familiarity with tools such as Google BigQuery, Snowflake, Splunk, Elastic, or similar platforms.
β’ Proficiency in SQL, KQL, SPL, or other equivalent query languages.
β’ Knowledge of MITRE ATT&CK-aligned detection and proactive threat hunting methodologies.
β’ Experience with AI-driven triage engines, automated playbooks, or agentic SecOps platforms.
β’ Strong communication skills to effectively engage with both technical and non-technical audiences.
β’ Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related hands-on experience.
β’ Preferred certifications include CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH, GCIA, GCFA, or CISSP.
β’ Comprehensive health, dental, and vision insurance.
β’ Flexible work hours and remote work options.
β’ Opportunities for professional development and certifications.
β’ Collaborative and innovative work environment.
Sunbelt Rentals, Inc.
The Cigna Group
U.S. Bank
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.