MDR Manager

GuardzMiami, FL
Onsite

About The Position

Guardz is seeking an experienced MDR Manager to lead their Security Operations team. This role requires a blend of strong technical expertise, operational leadership, and a passion for developing analysts, refining processes, and managing complex security incidents within multi-tenant MSP environments. The manager will be responsible for the day-to-day operations of the MDR team, ensuring coverage, adherence to SLAs, quality of service, effective escalation tiers, and the professional growth of the analysts. This is a hands-on leadership position where the manager will also act as the primary escalation point for Tier 3 threats and guide the team through the most challenging investigations.

Requirements

  • 5+ years in SOC, MDR, or Incident Response experience, with a focus on handling complex attacks.
  • 2+ years of experience in a Team Lead, Shift Lead, or senior role.
  • Hands-on expertise with EDR solutions such as SentinelOne, CrowdStrike, or Defender for Endpoint.
  • Hands-on expertise with ITDR, including identity threat management across M365 and Google Workspace.
  • Hands-on experience with data platforms like Google BigQuery, Snowflake, Splunk, or Elastic.
  • Fluency in a query language such as SQL, KQL, or SPL.
  • Experience with MITRE ATT&CK-aligned detection, proactive threat hunting, and AI-driven triage engines, automated playbooks, or agentic SecOps platforms.
  • Excellent communication skills, with the ability to clearly articulate high-risk technical findings to both technical and non-technical audiences.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience.

Nice To Haves

  • CompTIA Security+
  • CompTIA CySA+
  • Microsoft SC-200
  • GIAC GCIH / GCIA / GCFA
  • CISSP (or equivalent DoD 8570 / 8140 IAT Level II)

Responsibilities

  • Own 24/7 shift coverage, tiering, and escalation paths to ensure all alerts are handled appropriately without gaps in monitoring or escalation.
  • Participate in an on-call rotation with the team.
  • Own response SLAs (time-to-triage, time-to-notify, MTTR) and report SOC KPIs (MTTD, MTTR, detection efficacy, false-positive rate, case aging, customer satisfaction) to leadership.
  • Conduct QA on closed alerts and incidents, work to reduce false positives, and maintain team runbooks, playbooks, and SOC standards.
  • Lead, coach, and mentor MDR Analysts, including regular 1:1s, performance feedback, onboarding, and managing the T1-to-T3 training path.
  • Conduct tabletop exercises and post-incident reviews.
  • Act as the technical lead and final escalation point for T3 incidents, including advanced malware, identity threats (MFA fatigue, token theft), and active breaches, managing the full lifecycle with thorough documentation.
  • Correlate alerts across EDR (SentinelOne, Defender for Endpoint), ITDR (M365, Google Workspace), and email security.
  • Conduct proactive threat hunts aligned with MITRE ATT&CK.
  • Utilize Guardz AI agents, Google BigQuery, and query languages (SQL, KQL) for triage, high-volume log analysis, and incident scope confirmation.
  • Collaborate with MSPs on major incidents and posture reviews, and integrate findings into detection strategies with product, threat research, and engineering teams.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service