5 часов назад
Sr SOC and IR Manager (Remote or Onsite) (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr SOC and IR Manager (Cybersecurity): Leading and modernizing a global SOC and incident response program across endpoint, network, cloud, SaaS, and identity telemetry with an accent on detection engineering, incident coordination, and operational readiness. Focus on directing high-severity investigations, building automation and SOAR workflows, developing distributed teams, and improving measurable response outcomes.
Location: Stamford, Connecticut; remote or onsite. The role requires support outside standard business hours and up to 10% domestic and international travel. US Person status as defined under EAR Part 772 and ITAR 120.15 is required.
Company
Crane Aerospace & Electronics develops aerospace and electronic systems and operates a global information security function.
What you will do
- Lead and continuously improve the global SOC and incident response operating model, standard work, and outcomes.
- Serve as incident commander for high-severity investigations, coordinating technical and business stakeholders through containment, recovery, and follow-up improvements.
- Lead and develop distributed SOC analysts and engineers while building a culture of learning, quality, and operational excellence.
- Own detection and response capabilities across endpoint, network, cloud, SaaS, and identity telemetry, including detection tuning and threat hunting.
- Drive SIEM, SOAR, automation, orchestration, and AI-assisted workflows to improve triage, investigations, reporting, and response consistency.
- Maintain playbooks, readiness exercises, service expectations, KPIs, executive reporting, and partnerships with Legal, Privacy, HR, GRC, Risk Management, and IT.
Requirements
- 7+ years of relevant professional experience in security operations and incident response.
- 3+ years of experience managing or leading others in a security operations or incident response context.
- Experience designing and running SOC and incident response processes across enterprise, cloud, and SaaS environments.
- Expertise in SIEM engineering, log normalization, detection content, alert tuning, and correlation across endpoint, network, cloud, and identity sources.
- Working knowledge of SOAR, APIs, webhooks, scripting, Windows and Linux administration, networking, identity controls, SSO, MFA, and conditional access.
- Strong incident command, communication, project leadership, evidence-handling, privacy, regulatory, and eDiscovery skills.
Nice to have
- Degree in a related field or equivalent practical experience.
- Advanced security certifications such as CISSP, CISM, or GIAC.
Culture & Benefits
- Hands-on leadership role with global responsibilities and opportunities to modernize security operations.
- Support for ongoing security learning, training, certifications, and professional development.
- Collaboration with global information security, IT, business, Legal, Privacy, HR, GRC, and Risk Management stakeholders.
- Flexible support for remote or onsite work, with availability for incident response outside standard business hours.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
SOC Analyst (Cybersecurity)
123 850 - 161 000$
5 дней назад
Principal Cybersecurity Engineer (US Federal)
184 800 - 277 200$
5 дней назад
Cybersecurity Engineer - US Federal
130 200 - 195 400$
5 дней назад
Senior SOC Analyst (Cybersecurity)
23 часа назад
Security Services Specialist (Cybersecurity)
110 000 - 160 000$
4 дня назад