SOC Manager

QnityElsmere, DE

About The Position

The SOC Manager is responsible for leading the organization's Security Operations Center, overseeing incident response, security monitoring, threat detection, MSSP management, and continuous improvement of security operations capabilities. This role requires a hands-on technical leader who can effectively manage people, processes, and technology while driving measurable security outcomes.

Requirements

  • 6+ years of progressive experience in Security Operations, Incident Response, Threat Detection, or Cybersecurity Operations.
  • 3+ years of leadership, supervisory, or technical lead experience within a SOC or incident response environment.
  • Demonstrated experience leading complex cybersecurity incident investigations.
  • Strong hands-on experience with Microsoft Sentinel, Microsoft Defender for Endpoint, and Kusto Query Language (KQL).
  • Experience managing security vendors, MSSPs, and operational service delivery.
  • Strong project management, organizational, and communication skills.
  • Independently lead major security incidents through containment, recovery, and post-incident analysis.
  • Develop and optimize security detections, threat hunting activities, and SIEM content.
  • Analyze security data and translate findings into actionable risk reduction strategies.
  • Manage competing operational priorities and drive projects to successful completion.
  • Experience in identifying, designing, and implementing automation solutions that improve Security Operations efficiency.
  • Experience leveraging SOAR platforms, scripting, APIs, workflow automation, or low-code/no-code technologies to eliminate repetitive manual tasks and streamline security processes.
  • Communicate effectively with technical teams, leadership, and business stakeholders.
  • Deliver measurable improvements in SOC effectiveness, operational efficiency, and security outcomes.

Nice To Haves

  • CISSP, GCIH, GCFA, GNFA, SC-200, SC-100, or equivalent certifications.
  • Experience with industrial, manufacturing, OT, or Microsoft Defender for IoT environments.

Responsibilities

  • Lead the investigation, containment, and resolution of cybersecurity incidents, serving as Incident Commander for high-severity events.
  • Manage day-to-day SOC operations, including oversight of external MSSP partners and service delivery performance.
  • Develop, tune, and maintain threat detection use cases and SIEM correlation rules aligned to industry frameworks such as MITRE ATT&CK.
  • Drive automation initiatives through SOAR technologies to improve operational efficiency and response times.
  • Lead threat hunting, forensic investigations, and root cause analysis activities.
  • Establish and report on key SOC performance metrics, including MTTD, MTTR, detection coverage, and incident trends.
  • Evaluate and implement AI-driven security capabilities to enhance detection and response processes.
  • Mentor analysts and provide technical leadership across the security operations function.

Benefits

  • comprehensive pay and benefits package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service