
Senior Manager, Security Operations
Posted 12 hours ago

Posted 12 hours ago
This is a fully remote position, open to applicants in United States.
• Lead, develop, and expand Motive's Security Operations Center.
• Define the SOC operational model, coverage framework, runbooks, escalation procedures, recruitment, and professional growth.
• Determine the 24/7 coverage approach, incorporating in-house follow-the-sun, MDR augmentation, or hybrid solutions.
• Oversee detection strategy and coverage within product/production and enterprise/corporate environments.
• Align detection coverage with MITRE ATT&CK and Motive's threat model.
• Enhance detection capabilities within production and cloud workloads alongside Platform Engineering.
• Manage 24/7 incident response and act as incident commander during critical incidents.
• Supervise security telemetry and analytics collection, including normalization, enrichment, retention, and cost management.
• Evaluate MTTD, MTTR, detection coverage, alert accuracy, and automation rates.
• Develop threat hunting and threat intelligence functions.
• Manage EDR across the corporate fleet and runtime/workload protection for production environments.
• Direct operational phishing and social engineering defenses, including triage, takedown, and credential-compromise responses.
• Design and implement an AI-first SOC operational model emphasizing triage, enrichment, correlation, and automated investigations.
• Over 8 years of experience in security operations, incident response, detection engineering, or threat intelligence.
• At least 3 years of experience in team leadership.
• Proven ability to personally create detections, conduct investigations, lead incidents as commander, and implement automation recently.
• Experience in establishing or significantly revamping a SOC function.
• Familiarity with production and cloud security monitoring, as well as corporate and enterprise security operations.
• Extensive experience with SIEM and security data platforms, EDR, SOAR or comparable automation, and cloud-native telemetry.
• Strong skills in detection engineering.
• Solid background in monitoring cloud and container security.
• Proficiency in AWS and Kubernetes is highly preferred.
• Comprehensive understanding of SSO, OAuth, session compromise, MFA bypass, and privilege escalation across SaaS and cloud environments.
• Proven incident command experience during significant events, including effective communication with executives under pressure.
• Demonstrated application of AI within security operations.
• Experience in establishing 24/7 coverage and leading globally distributed teams across various time zones.
• Experience in sectors such as transportation, logistics, IoT, connected devices, or critical infrastructure is advantageous.
• Applicants must be authorized to access commodities and technologies governed by U.S. Export Administration Regulations.
• Employees must be authorized to gain access to Motive products and technology.
• Comprehensive health, pharmacy, optical, and dental care benefits.
• Paid time off.
• Sick leave.
• Short-term and long-term disability coverage.
• Life insurance.
• 401(k) contribution.
• Restricted stock units may be included in total compensation for specific roles.
• Some interviews or new-hire training sessions may take place in person at one of Motive's global offices.
Axians Somnitec AG
ASAAS
Reinsurance Group of America, Incorporated
Kryptus SA
Get handpicked remote jobs straight to your inbox weekly.