Назад
Company hidden
5 часов назад

Sr SOC and IR Manager (Remote or Onsite) (Cybersecurity)

Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr SOC and IR Manager (Cybersecurity): Leading and modernizing a global SOC and incident response program across endpoint, network, cloud, SaaS, and identity telemetry with an accent on detection engineering, incident coordination, and operational readiness. Focus on directing high-severity investigations, building automation and SOAR workflows, developing distributed teams, and improving measurable response outcomes.

Location: Stamford, Connecticut; remote or onsite. The role requires support outside standard business hours and up to 10% domestic and international travel. US Person status as defined under EAR Part 772 and ITAR 120.15 is required.

Company

Crane Aerospace & Electronics develops aerospace and electronic systems and operates a global information security function.

What you will do

  • Lead and continuously improve the global SOC and incident response operating model, standard work, and outcomes.
  • Serve as incident commander for high-severity investigations, coordinating technical and business stakeholders through containment, recovery, and follow-up improvements.
  • Lead and develop distributed SOC analysts and engineers while building a culture of learning, quality, and operational excellence.
  • Own detection and response capabilities across endpoint, network, cloud, SaaS, and identity telemetry, including detection tuning and threat hunting.
  • Drive SIEM, SOAR, automation, orchestration, and AI-assisted workflows to improve triage, investigations, reporting, and response consistency.
  • Maintain playbooks, readiness exercises, service expectations, KPIs, executive reporting, and partnerships with Legal, Privacy, HR, GRC, Risk Management, and IT.

Requirements

  • 7+ years of relevant professional experience in security operations and incident response.
  • 3+ years of experience managing or leading others in a security operations or incident response context.
  • Experience designing and running SOC and incident response processes across enterprise, cloud, and SaaS environments.
  • Expertise in SIEM engineering, log normalization, detection content, alert tuning, and correlation across endpoint, network, cloud, and identity sources.
  • Working knowledge of SOAR, APIs, webhooks, scripting, Windows and Linux administration, networking, identity controls, SSO, MFA, and conditional access.
  • Strong incident command, communication, project leadership, evidence-handling, privacy, regulatory, and eDiscovery skills.

Nice to have

  • Degree in a related field or equivalent practical experience.
  • Advanced security certifications such as CISSP, CISM, or GIAC.

Culture & Benefits

  • Hands-on leadership role with global responsibilities and opportunities to modernize security operations.
  • Support for ongoing security learning, training, certifications, and professional development.
  • Collaboration with global information security, IT, business, Legal, Privacy, HR, GRC, and Risk Management stakeholders.
  • Flexible support for remote or onsite work, with availability for incident response outside standard business hours.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →