Security Operations Manager

Aya HealthcareSan Diego, CA
16h

About The Position

Join Aya Healthcare, winner of multiple Top Workplace awards! We are seeking a Manager, Security Operations to lead and modernize our enterprise security operations function, with accountability for incident response, detection engineering, automation, operational metrics, and continuous improvement. This role owns the day‑to-day execution and evolution of security operations using ServiceNow Security Incident Response (SIR) as the system of record and partners closely with internal teams, managed service providers, and nearshore/offshore resources. This is a builder‑focused leadership role for someone who thrives on ownership and momentum. Aya is actively maturing its security operations capabilities—moving from reactive alert handling toward measurable, scalable, and automated SecOps outcomes. You’ll have the mandate to design modern SIR playbooks, improve signal quality, automate response, and scale operations across a blended delivery model while clearly demonstrating impact through MTTx metrics. Who We Are: We’re a $8+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform. At Aya, we’re obsessed with creating exceptional experiences for our clients, clinicians, and employees. In fact, we put employee satisfaction above all else. Our team members are responsible for incomparable customer experience and we know that happy employees are critical to maintaining happy clients. We foster an entrepreneurial, high-energy, low-bureaucracy culture and value innovative thinking and creative problem-solving. We embrace diversity in thought and backgrounds unified by a commitment to high achievement. When you join Aya, you’ll be surrounded by teammates who care about you as an individual and leaders who will help you grow both personally and professionally.

Requirements

  • 5+ years of experience in Security Operations, Incident Response, or SOC‑related roles.
  • 2+ years of direct experience managing and operating ServiceNow Security Incident Response (SIR), including workflow ownership and playbook design.
  • Demonstrated experience designing or operating incident response automation and playbooks within SIR or SOAR‑like platforms.
  • Hands‑on experience integrating EDR platforms (e.g., Microsoft Defender and/or CrowdStrike Falcon) with ServiceNow SIR.
  • Strong experience operating and managing EDR and SIEM solutions in an enterprise environment.
  • Strong hands‑on experience with Microsoft Azure security solutions, including capabilities available through Microsoft E5 subscriptions.
  • Demonstrated experience managing and improving MTTx metrics (e.g., MTTD, MTTR) to drive operational change.
  • Proven experience leading security operations teams, including internal staff and external service providers.
  • Strong incident leadership, communication, and decision‑making skills with the ability to influence across teams.

Responsibilities

  • Own the execution and continuous improvement of Aya Healthcare’s enterprise Security Operations program.
  • Lead a blended security operations model combining internal analysts, nearshore/offshore resources, and managed service providers.
  • Establish clear operating models, escalation paths, staffing coverage expectations, and accountability across all SecOps resources.
  • Serve as the primary owner of ServiceNow Security Incident Response (SIR) workflows, data models, and operating procedures.
  • Design, implement, and continuously improve SIR playbooks to automate triage, enrichment, containment, and response actions.
  • Drive automation that reduces manual analyst effort and improves MTTD, MTTR, and MTTC through standardized playbook execution.
  • Ensure incidents are consistently triaged, investigated, documented, and remediated using ServiceNow SIR.
  • Oversee detection and response capabilities across EDR and SIEM platforms, ensuring high‑quality signal ingestion and routing into SIR.
  • Operate confidently across Microsoft Azure security capabilities available through Microsoft E5 environments (e.g., Defender, Sentinel).
  • Define, track, and improve MTTx metrics, using data to prioritize automation and process improvements.
  • Lead post‑incident reviews and ensure lessons learned translate into improved detections, playbooks, and response procedures.
  • Manage, coach, and develop security operations personnel while fostering a high‑energy, accountable team culture.
  • Act as a trusted escalation point during security incidents and clearly communicate operational risk and response status to leadership.

Benefits

  • Free premium medical, dental, life and vision insurance
  • Generous 401(k) match
  • Aya also offers other benefits to those that are eligible and where required by applicable law, including reimbursements and discretionary bonuses
  • Aya provides paid sick leave in accordance with all applicable state, federal, and local laws. Aya’s general sick leave policy is that employees accrue one hour of paid sick leave for every 30 hours worked. However, to the extent any provisions of the statement above conflict with any applicable paid sick leave laws, the applicable paid sick leave laws are controlling
  • Celebrations! We hit our goals and reward ourselves.
  • Company-sponsored virtual events, happy hours and team-building activities are always on the horizon — plus, you get a special treat on your birthday!
  • Unlimited DTO — we believe in time off!
  • Virtual yoga, meditation or boot camp classes offered daily
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service