Manager / Sr. Manager, SecOps & Cyber Defense

BullishNew York, NY
$185,000 - $235,000Onsite

About The Position

We are seeking an experienced, hands-on Manager / Sr. Manager of SecOps & Cyber Defense to lead, scale, and actively drive our 24/7 security detection and response capabilities in the US, UK, & EMEA. In this dual-capability role, you will lead a lean, highly technical group of SOC analysts and incident responders while remaining deeply connected to the engineering work. You will sit in the hot seat during major incidents, build high-efficacy detection engineering pipelines across cloud and hybrid infrastructure, and continuously elevate our threat hunting and triage posture.

Requirements

  • 8+ years of dedicated, hands-on experience in SOC operations, threat detection, and security incident response.
  • 2+ years of direct people management or formal team leadership experience, preferably overseeing a geographically distributed workforce.
  • Deep operational expertise in investigating cloud-native threats (AWS, GCP, or Azure), container environments (Kubernetes, Docker), and modern SaaS infrastructure.
  • Advanced proficiency with modern SIEM platforms, EDR/XDR suites, log aggregators, and SOAR tools.
  • Strong scripting and automation skills in Python, Bash, or Go to automate triage tasks and query APIs.
  • Strong knowledge of network protocols, cloud architecture, identity systems (Okta, Azure AD), and digital forensics fundamentals.
  • Proven ability to stay calm, decisive, and communicative under pressure during high-severity security incidents.

Nice To Haves

  • Prior experience in Financial Services, FinTech, Digital Assets, or high-throughput trading environments operating under strict regulatory audit standards (SOC 2, ISO 27001, SEC/FINRA frameworks).
  • Relevant industry certifications such as GIAC (GCIH, GCFA, GNFA, GCDA), CISSP, or OSCP.

Responsibilities

  • Manage & Mentor: Lead and mentor a small, high-performing team of SOC Analysts and Incident Response engineers across multiple time zones.
  • On-Call & Escalations: Serve as the primary point of escalation for high-severity security incidents, managing the global operational shift structure and continuous coverage model.
  • Metrics & Maturity: Define and track key SOC operational metrics (MTTD, MTTR, false positive ratios, incident coverage against MITRE ATT&CK) to drive continuous improvement.
  • Cross-Functional Collaboration: Partner closely with Infrastructure, Cloud Platform, DevOps, Corporate IT, Legal, and Compliance teams during critical triage and investigation phases.
  • Incident Management: Drive end-to-end response for major security incidents—from initial detection, containment, and eradication to root-cause analysis and post-mortem reporting.
  • Detection Engineering: Design, write, and tune high-precision detection rules (SIEM, EDR, Cloud-native logs) to minimize noise and highlight sophisticated threat activity.
  • Forensics & Triage: Perform hands-on digital forensics (memory, disk, network artifact analysis) and reverse-engineer suspicious scripts/payloads when necessary.
  • Threat Research & Readiness: Conduct targeted research into emerging threat actor TTPs, zero-days, and cloud vulnerabilities to preemptively fortify detection capabilities and response playbooks.
  • Adversarial Testing & Exercises: Lead and participate in regular Red/Purple team operations and executive tabletop exercises to stress-test incident response readiness and validate control coverage.
  • Threat Hunting: Proactively hunt for undetected threat actor behavior using internal logs, intelligence feeds, and custom queries.
  • SOAR & Automation: Build and refine automated response playbooks using Python, API integrations, and SOAR tools to streamline repetitive analyst workflows.

Benefits

  • competitive compensation
  • discretionary annual target bonus
  • performance incentives
  • benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service