Info Security Blue Team Manager

Utah Community Credit Union (UCCU)Provo, UT
Onsite

About The Position

The Blue Team Manager is responsible and accountable for the full defensive security lifecycle at UCCU: detection engineering, continuous monitoring, incident response, and cyber recovery. This role leads the team that protects member data and credit union operations day to day, owns UCCU's logging and monitoring program, and serves as the primary operational commander during active security incidents. The Blue Team Manager also owns UCCU's response and recovery capabilities under NIST CSF 2.0 (RS and RC functions), including NCUA incident notification, stakeholder communications, BCP/DR coordination for cyber events, and post-incident regulatory follow-up, ensuring that every incident is closed with documented lessons learned and that the program measurably improves over time.

Requirements

  • Bachelor's degree in information security, computer science, cybersecurity, or a related field is preferred; equivalent professional experience will be considered in lieu of a degree.
  • 8 or more years of progressive experience in security operations, incident response, detection engineering, SOC, blue team, or threat hunting, with at least 3 years in a lead or management role.
  • Demonstrated experience leading incident response operations, including serving as incident commander during significant events.
  • Demonstrated experience authoring detections, building parsing/normalization, and performing threat hunts.
  • Proven execution of IR playbooks and recovery activities, including cross-functional and external coordination.
  • Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, or equivalent), EDR, and SOAR tooling.
  • Experience managing or coordinating with an outsourced SOC or MSSP.
  • Experience with digital forensics, malware analysis, and evidence chain of custody.
  • Experience managing work through ticketing and project management platforms (ServiceNow, Jira, monday.com, or equivalent).
  • Deep working knowledge of MITRE ATT&CK and its application to detection engineering, threat hunting, and purple team planning.
  • Strong understanding of NIST CSF 2.0 Detect, Respond, and Recover functions, and the NIST SP 800-53 control families relevant to Blue Team operations, and their practical application in a regulated financial institution.
  • Defensive security expertise across Windows, Linux, and macOS.
  • Working knowledge of network protocols and packet/flow analysis.
  • Familiarity with cloud logging and controls.
  • Ability to make sound, time-pressured decisions during active incidents and communicate them clearly to leadership.
  • Ability to write and interpret queries in at least one SIEM query language (SPL, KQL, or similar).
  • Familiarity with log management concepts: source onboarding, field normalization, ingestion health monitoring, and retention policy enforcement.
  • Strong written and verbal communication skills; able to produce examiner-ready documentation and brief senior leadership clearly and concisely, including clear and direct conversations with the CEO, executives, and upper management during a crisis.
  • Comfort using ticketing and project management tools as a daily leadership discipline.
  • Probabilistic reasoning: ability to assess likelihood of attacker activity, weigh incomplete evidence, and communicate confidence levels appropriately to leadership and examiners.
  • Precision in reviewing logs, alerts, and configurations to avoid false positives or missed threats.
  • Adaptability to evolving threats, new tools, and changing priorities; keeps up with emerging threats, new attack techniques, and defensive technologies.
  • Ability to stay calm and focused during high-pressure incidents.
  • Handles sensitive data responsibly and maintains trustworthiness in all actions.
  • Ability to develop and mentor staff, set measurable expectations, and build a high-performing team culture.
  • Frequent talking, especially where one must convey detailed or important instructions or ideas accurately, loudly, or quickly; average hearing sufficient for normal conversation; repetitive motion of the wrists, hands, and/or fingers; average visual acuity necessary to prepare or inspect documents or a computer screen; and sedentary physical strength, sitting most of the time and exerting up to 10 lbs. of force occasionally.
  • Probabilistic reasoning: estimates likelihood of attack success, scenario weighting, and Bayesian updating as new evidence emerges during investigations.
  • High-stakes decision making under time pressure and incomplete information during active incidents.
  • Ability to hold multiple concurrent investigations and team management responsibilities without loss of accuracy or judgment.
  • Sustained analytical focus during complex, multi-day incident investigations.
  • Reasoning ability: interpret large volumes of log and alert data, identify anomalies, and determine root causes; anticipate attacker tactics and design defensive measures proactively; detect subtle indicators of compromise across diverse data sources; prioritize response actions based on business impact and threat severity.
  • Mathematics ability: use averages, standard deviation, and variance to detect anomalies; compute event rates (e.g., failed logins per second), throughput, and error percentages; read and interpret charts, dashboards, and KPIs; perform simple ROI or risk-reduction calculations for security improvements.
  • Language ability: write clear incident reports, playbooks, and detection logic documentation; translate technical findings into concise, business-friendly language for leadership; understand and apply security policies, regulatory requirements, and compliance language; communicate effectively during incident response calls and cross-team coordination; create knowledge base articles and contribute to team learning.

Nice To Haves

  • Experience with NCUA, FFIEC, or other financial institution regulatory reporting requirements for cybersecurity incidents is strongly preferred.
  • Familiarity with BCP/DR planning and cyber recovery coordination is preferred.
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Enterprise Defender (GCED) or GIAC Certified Forensic Analyst (GCFA)
  • GIAC Security Leadership (GSLC) or equivalent management-level security credential
  • CISSP
  • CompTIA CySA+ or Security+ (or equivalent)
  • MITRE ATT&CK Defender (MAD) certification

Responsibilities

  • Operate and mature the detection stack (SIEM, SOAR, EDR, NDR): define and maintain baselines, correlation rules, alert thresholds, detection use cases, and ATT&CK coverage; document and test all detection logic.
  • Own the logging program: define what to log, where, and how; ensure reliable ingestion, field normalization, and retention in alignment with UCCU's Records Retention Schedule; perform routine completeness reviews, onboard new log sources, and provide evidence for audits and examinations.
  • Coordinate day-to-day with the outsourced SOC: manage the triage handoff process, review escalations, drive the false-positive and missed-detection feedback loop, and participate in regular SOC review calls.
  • Run DLP and integrity controls to prevent exfiltration and validate software, firmware, and data integrity; coordinate with system owners for remediation of identified gaps.
  • Operationalize cyber threat intelligence: feed threat data into risk determinations, detection content, and threat hunt hypotheses; maintain awareness of adversary TTPs relevant to financial institutions and credit unions.
  • Direct and oversee threat hunting operations: assign hunt hypotheses, review findings, and translate outcomes into new or improved detection rules.
  • Serve as incident commander during active security events: lead triage, scoping, forensic analysis, impact assessment, containment, mitigation, and eradication; make real-time decisions on response actions and resource deployment.
  • Design incident investigation frameworks: define scope, establish investigative hypotheses, assign workstreams to IR Analysts, and drive investigations to documented root cause conclusions.
  • Provide structured, timely updates to the CISO and relevant stakeholders throughout active incidents, including current status, confirmed findings, open questions, and defined next steps.
  • Ensure all incident documentation is complete and examiner-ready from initial detection through post-incident review (PIR); own the PIR process and integration of lessons learned into detection and process improvements.
  • Manage all incident-related work in the team's designated ticketing system; ensure tickets reflect current status at every handoff and shift change.
  • Oversee malware triage and digital forensics work performed by IR Analysts; maintain chain of custody for evidence that may support legal or regulatory action.
  • Support UCCU's NCUA 72-hour cyber incident notification process in coordination with Compliance and Legal: assess incidents against reporting thresholds, prepare required documentation, and maintain records of all regulatory communications.
  • Coordinate member breach notification logistics with Compliance and Legal when applicable; ensure notifications meet content and timing requirements under applicable law.
  • Support crisis communications during active incidents: in coordination with the CISO, Marketing, and Compliance, ensure that internal and external messaging is accurate, timely, consistent, and does not create additional legal or reputational risk; maintain a running communications log throughout the incident lifecycle.
  • Manage voluntary external information sharing during incidents (e.g., FS-ISAC, law enforcement, peer institutions) in accordance with UCCU's incident response plans.
  • Provide accurate, timely situational awareness to the CISO throughout active incidents; support the CISO in serving as the primary InfoSec liaison to Legal, Compliance, and senior leadership.
  • Coordinate post-incident regulatory follow-up with the CISO: prepare supplemental documentation, respond to examiner inquiries, and track open regulatory items through to closure.
  • Maintain and execute cyber-specific recovery plans: lead the transition from containment to recovery, verify eradication, oversee system restoration, and confirm return to normal operations.
  • Coordinate with IT and business line owners on BCP/DR activities for cyber events: ensure that cyber recovery scenarios are embedded in UCCU's BCP/DR planning, tested annually, and updated after each significant incident.
  • Own post-incident member and stakeholder communication in coordination with Marketing and Compliance: ensure that recovery messaging is accurate, appropriately timed, and does not create additional legal or reputational risk.
  • Conduct post-recovery reviews with all involved parties; document recovery timeline, gaps in recovery capability, and improvements required; track remediation items to closure.
  • Maintain recovery capability metrics and report them to the CISO on a defined cadence.
  • Hire, develop, and evaluate Blue Team staff including IR Analysts; set clear performance expectations aligned to team KPIs and CSF 2.0 function coverage.
  • Manage team workload through established project management and ticketing platforms (e.g., monday.com, Jira, or equivalent); maintain visibility into all open incidents, projects, and improvement initiatives.
  • Drive a formal program improvement cycle: collect lessons learned from incidents, purple team exercises, and audits; convert findings into prioritized improvement tasks tracked through to completion.
  • Plan and execute purple team exercises in coordination with the Red Team; translate outcomes into detection improvements, updated playbooks, and updated training materials.
  • Author, maintain, and version-control runbooks, playbooks, and IR procedures; ensure documentation is in a state of ongoing examiner readiness.
  • Support CISO preparation for board and supervisory committee presentations related to Blue Team operations, incident metrics, and detection program maturity.

Benefits

  • Competitive base salary
  • Annual incentive opportunity tied to personal and organizational performance
  • Comprehensive benefits consistent with UCCU's commitment to its employees
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service