Senior Manager, Security Operations

Motive
$140,000 - $200,000Hybrid

About The Position

Motive is seeking a Senior Manager, Security Operations to establish and lead their Security Operations Center (SOC). This is a foundational leadership position where the successful candidate will be responsible for shaping the team, selecting tooling, defining the detection strategy, and establishing the operating model. The role reports to the CISO and encompasses the entire detection and response lifecycle, including detection engineering, 24/7 incident response, threat hunting, threat intelligence, security analytics, and endpoint/workload security. The scope covers Motive's entire infrastructure, including cloud environments, services, APIs, data platforms for various product lines (Fleet Management, Driver Safety, Spend Management, Workforce Management, AI Vision), connected devices, as well as enterprise systems like endpoints, identity, SaaS applications, network, email, and internal tools. A key aspect of this role is integrating these diverse environments into a unified detection and response capability with a single view of adversary activity. The primary goal is comprehensive coverage to detect all security incidents, emphasizing an AI-first, data-driven, and automation-centric approach from the outset, rather than a traditional tiered analyst model. The aim is to build a highly leveraged team focused on complex challenges rather than routine queue management.

Requirements

  • 8+ years in security operations, incident response, detection engineering, or threat intelligence.
  • 3+ years of experience leading teams.
  • Demonstrably hands-on experience writing detections, running investigations, leading incidents as commander, and building automation.
  • Experience building or substantially rebuilding a SOC function.
  • Credibility across both production/cloud security monitoring and corporate/enterprise security operations.
  • Deep experience with modern detection and response tooling (SIEM, security data platforms, EDR, SOAR or equivalent automation, cloud-native telemetry).
  • Strong detection engineering skills.
  • Strong background in cloud and container security monitoring (AWS and Kubernetes strongly preferred).
  • Solid grounding in identity-centric attack paths (SSO, OAuth, session compromise, MFA bypass, privilege escalation).
  • Proven incident command experience on significant incidents, including executive communication under pressure.
  • Concrete, demonstrated use of AI to run security operations (triage, enrichment, detection authoring, investigation support, reporting).
  • Experience building 24/7 coverage and leading globally distributed teams across multiple timezones.
  • Authorization to receive and access commodities and technologies controlled under U.S. Export Administration Regulations.

Nice To Haves

  • Experience in transportation, logistics, IoT and connected devices, or critical infrastructure is a plus.
  • Practical experience introducing production monitoring without destabilizing production.

Responsibilities

  • Establish and grow the SOC, including its operating model, coverage structure, runbooks, escalation paths, and hiring/career development for a globally distributed team.
  • Determine the 24/7 coverage model, which may include in-house follow-the-sun, MDR augmentation, or a hybrid approach.
  • Own Motive's detection strategy and coverage posture across both production and enterprise environments, treating detection content as code and mapping coverage against MITRE ATT&CK and Motive's threat model.
  • Expand detection capabilities into production and cloud workloads in collaboration with Platform Engineering, focusing on detections that span across corporate and cloud environments.
  • Oversee 24/7 incident response for both product and enterprise environments, acting as incident commander for major incidents and communicating with executives.
  • Manage the security telemetry and analytics platform, including collection, normalization, enrichment, retention, and cost.
  • Establish a structured, hypothesis-driven threat hunting program and a threat intelligence capability tailored to Motive's sector.
  • Own Endpoint Detection and Response (EDR) for the corporate fleet and, with Platform Engineering, runtime and workload protection for production environments.
  • Manage the operational aspects of phishing and social engineering defense, including detection, triage, takedown, and response to credential compromise.
  • Architect and implement the AI-first operating model for the SOC, focusing on automation for triage, enrichment, correlation, and investigation.

Benefits

  • health, pharmacy, optical and dental care benefits
  • paid time off
  • sick time off
  • short term and long term disability coverage
  • life insurance
  • 401k contribution
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service