The Security Operations Manager leads a multi-discipline security team covering application security, threat detection, vulnerability management, red/purple team activities, and security automation, with a heavy emphasis on detection, readiness, and real-world risk reduction. The role is at the intersection of secure development, threat detection, and operational maturity within a large, multi-cloud online banking environment. Large-bank experience is preferred. What the Manager Owns: * People leadership for a multi-discipline cyber team (6 to 12 direct reports) * Threat detection * Penetration testing readiness and follow-through * Red / blue / purple team integration * Reducing enterprise attack surface Key Responsibilities: Leadership & Team Management: * Manage and develop a team of security professionals across vulnerability management, threat detection & threat intelligence, red/purple team disciplines, and security automation * Act as the escalation point for high-risk or high-impact cyber issues Application Security: * Oversee SAST, DAST, SCA, manual testing, and penetration testing programs * Drive shift-left AppSec - IDE scanning, CI/CD integration, and secure coding practices * Reduce testing cycles and downstream findings by improving early detection * Operate tool-agnostic (e.g., Veracode, Invicti, Burp) * Ensure AppSec supports modern cloud-native and DevOps environments * Build trusted relationships with Shadow IT owners, and progressively align with security tooling, testing, and IT security practices. Threat Detection & Purple Teaming: * Own detection-focused security outcomes, not just vulnerability reporting * Work closely with SOC and IR teams to improve detection signals * Use pen-test and red-team insights to strengthen blue-team defenses * Apply purple-team thinking to close gaps between offense and defense Penetration Testing & Offensive Readiness: * Ensure strong internal and third-party penetration testing coverage * Validate that findings are meaningful, prioritized, and remediated * Use offensive testing to drive real defensive improvements Vulnerability & Configuration Risk Reduction: * Oversee vulnerability and configuration management programs * Maintain hardening standards, baselines, and remediation tracking * Reduce enterprise attack surface across cloud, applications, and infrastructure * Integrate AppSec, pen-test, and vulnerability data into risk-based prioritization Environment & Scope: * Multi-cloud environment * High-availability online banking systems * Highly regulated financial services setting * Heavy collaboration with engineering, cloud, risk, and executive leaders
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Manager
Education Level
No Education Listed