2 дня назад
MDR Manager (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
MDR Manager (Cybersecurity): Leading 24/7 security operations for multi-tenant MSP environments with an accent on incident response, SOC performance, analyst development, and detection quality. Focus on managing Tier 3 investigations, threat hunting across EDR and ITDR telemetry, and using AI agents, BigQuery, SQL, and KQL to triage high-volume security data.
Location: Home Office - US
Company
develops an all-in-one cybersecurity platform for small and medium-sized businesses.
What you will do
- Lead 24/7 MDR coverage, analyst tiering, escalation paths, on-call operations, and response SLAs.
- Report SOC KPIs including MTTD, MTTR, detection efficacy, false-positive rate, case aging, and customer satisfaction.
- Manage alert and incident QA, reduce false positives, and maintain runbooks, playbooks, and SOC standards.
- Coach and mentor MDR Analysts through onboarding, performance feedback, training, tabletop exercises, and post-incident reviews.
- Serve as the technical lead and final escalation point for complex Tier 3 incidents, including advanced malware, MFA fatigue, token theft, and active breaches.
- Correlate EDR, ITDR, and email-security alerts; conduct MITRE ATT&CK-aligned threat hunts and partner with MSPs, product, threat research, and engineering.
Requirements
- 5+ years of experience in SOC, MDR, or incident response handling complex attacks, including 2+ years as a Team Lead, Shift Lead, or senior professional.
- Hands-on expertise with EDR platforms such as SentinelOne, CrowdStrike, and Defender for Endpoint.
- Experience with ITDR across Microsoft 365 and Google Workspace.
- Experience with BigQuery, Snowflake, Splunk, Elastic, or equivalent, plus fluency in SQL, KQL, or SPL.
- Experience with MITRE ATT&CK-aligned detection, proactive threat hunting, AI-driven triage, automated playbooks, or agentic SecOps platforms.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience; strong technical communication skills.
Nice to have
- CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH, GCIA, GCFA, CISSP, or equivalent DoD 8570 / 8140 IAT Level II certification.
Culture & Benefits
- Home-office work from the United States.
- Hands-on leadership within a growing cybersecurity product company.
- Collaboration with MSPs and product, threat research, and engineering teams.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Manager, Incident Response (Cybersecurity)
132 410 - 165 510$
2 дня назад
Security Analyst - MDR (Cybersecurity)
4 часа назад
Staff Security Operations Engineer (Cybersecurity)
128 000 - 200 000$
2 дня назад
Senior Incident Response Analyst (Cybersecurity)
2 дня назад
Security Engineer (Cybersecurity)
2 дня назад
Manager Security Engineer
120 000 - 130 000$