Manager, Security Operations

Forward FinancingBoston, MA
$172,000 - $237,000Remote

About The Position

As Manager, Security Operations, you will defend our infrastructure, SaaS, and endpoints by hiring, growing, and developing a team of high-quality security engineers. You will collaborate closely with cross-functional technical teams, AppSec, and executive stakeholders to advance our AI security strategy and build robust detection controls. You will be the point person to lead incident response as senior Incident Commander, drive cybersecurity risk assessments, and maintain a seamless, hardened security posture against real-world adversaries.

Requirements

  • 7 or more years in detection engineering, security operations, or incident response, including team leadership.
  • Deep familiarity with adversary TTPs (MITRE ATT&CK), event correlation, and high-signal detection design.
  • Hands-on experience with EDR/SIEM platforms and detection-as-code practices.
  • Incident command experience: triage, containment, forensics, and stakeholder communication under pressure.
  • Experience securing SaaS environments and endpoint fleets — configuration management, access governance, and vulnerability/patch management.
  • Ability to communicate risk and priorities crisply to engineers and executives.
  • Cloud control-plane monitoring and identity threat detection (AWS).
  • Scripting/automation in Python, Ruby, or Go.
  • Typically has a Bachelor's Degree in Computer Science or equivalent technical degree, or equivalent industry experience.
  • Experience with SaaS security posture management (SSPM) or CASB tooling.

Nice To Haves

  • Experience with Gen-AI triage or LLM-as-Judge patterns in production.
  • CISSP and/or CISM certification
  • Red-team exposure — you think like an attacker.

Responsibilities

  • Hire, grow, and develop a team of high-quality security engineers to defend our endpoints, SaaS estate, and infrastructure against real-world adversaries.
  • Own the security of our corporate systems (SaaS applications and endpoints) including configuration hardening and vulnerability/patch oversight.
  • Lead security operations and incident response, acting as senior Incident Commander for the Security Incident Response Team (SIRT).
  • Own and tune our detection and response funnel and our CrowdStrike detection platform.
  • Build and maintain detection coverage across endpoint, SaaS, and identity signals; audit/usage logs, egress-proxy traffic, DLP events, and access trails.
  • Partner with other teams to build controls to contain external exposure: network allowlists, egress proxy, and proxy-level DLP.
  • Partner with AppSec on detection opportunities surfaced by pentesting.
  • Set quality and coverage standards for detection and response and own reporting on these metrics
  • Conduct ongoing enterprise-wide cybersecurity risk assessments across infrastructure, endpoints, applications and business processes
  • Own AI security as a zero-to-one build: build upon our existing detection tooling/response processes and execute our hiring plan to build the specialized team needed to keep pace with Forward's AI deployment

Benefits

  • medical
  • dental
  • vision
  • commuter benefits
  • a flexible time-off policy
  • paid parental leave
  • 401k match for US employees
  • wellness reimbursement
  • volunteering days
  • annual professional development budget
  • charitable donation match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service