> Markdown version of [/jobs/ext/1349892-manager-cyber-fusion-center](https://www.wearedevelopers.com/jobs/ext/1349892-manager-cyber-fusion-center). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager Cyber Fusion Center - **Company:** Pharmacy Data Management, Inc. - **Location:** Poland, OH, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Artificial Intelligence, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Identity and Access Management, Information Technology Operations, Intrusion Detection and Prevention, Network Protocols, Security Information and Event Management, Software Vulnerability Management, Scripting, Software Security, Mitre Att&ck, Mttr, Cyber Threat Analysis, Information Technology, Purple Team (Cyber Security), Cyber Warfare - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=830ff68f6a1d6c7d ## About the Role * Bachelor's degree in computer science, cybersecurity, or a related technical field required or equivalent combination of education and experience. * 8-10 years of progressive experience in cybersecurity with significant experience in incident response, SOC operations, security engineering, or cyber defense leadership required. * Proven experience designing, implementing, or operating SOC and experience in SIEM, SOAR required. * Strong hands-on and strategic knowledge of security operations platforms, endpoint detection and response, identity security, vulnerability management, and cloud security required. * Experience leading major incident response efforts, coordinating technical and business stakeholders, and managing executive communications during cyber events required. * Strong understanding of network protocols, secure system design, logging solutions, and endpoint security required. * Proficient in various scripting languages to automate repetitive tasks and streamline security operations required. * Experience with industry standards and frameworks (e.g., NIST IR, NIST RMF, MITRE, CIS) required. * Security certifications such as CISSP and CISM are preferred. AI Usage & Candidate Authenticity: AI tools may be used for resume formatting or drafting application materials; however, submitting content that misrepresents your experience, including copied job descriptions or unverifiable work history, is not acceptable. Candidates must be prepared to clearly and confidently speak to all experience listed. PDMI may request work samples, portfolio links, or other forms of validation during the process. Use of AI tools during interviews or assessments, unless explicitly permitted, will result in disqualification. All offers are contingent upon successful completion of a pre-employment background check, including employment and education verification, as well as a 4-panel drug screen. ## Description * Lead the strategy, design, implementation, operation and continuous improvement of a Cyber Fusion Center including Security Operations Center (SOC) aligned to business risk and enterprise security objectives. * Oversee SOC operations across internal teams and external providers, including MSSPs, and AI-enabled SOC platforms. * Serve as the primary leader for cybersecurity incident response, including preparation, detection, triage, containment, eradication, recovery, and post-incident review. * Lead or coordinate response to high-severity cybersecurity incidents, data breaches, and crisis events; stand up and run CSIRT activities when needed. * Develop, maintain, and test the incident response plan, escalation procedures, and cybersecurity playbooks using frameworks such as MITRE ATT&CK and other industry best practices. * Ensure SOC alerts and triage workflows are mapped, prioritized, and tuned using the MITRE ATT&CK framework, cyber threat intelligence, and risks it brings to PDMI. * Drive operational excellence in monitoring, detection engineering, threat triage, and response workflows to reduce false positives and improve speed and quality of response. * Partner with vulnerability management, security engineering, infrastructure, architecture, product security, risk management, legal, IT operations, and product engineering & owners to improve detection, response, and remediation outcomes. * Lead security input into enterprise initiatives involving Microsoft Defender EDR, Entra ID / Active Directory, Penetration Testing, Red & Purple team exercise, Email Security, CSPM/Cloud Security, KnowBe4 and broader security telemetry integration. * Establish and track operational metrics and KPIs such as alert fidelity, MTTD, MTTR, incident trends, log ingestion coverage gaps, and control effectiveness. * Manage third-party incident response retainers, forensic partners, and external service providers to ensure readiness and effective support during incidents. * Plan and facilitate cybersecurity tabletop exercises and simulations with technical teams, executives, and business stakeholders to validate readiness and strengthen decision-making. * Provide clear, concise updates to leadership during incidents and communicate cyber risk, trends, and improvement priorities to executive team. ## Related Videos - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Oops! Stories of supply chain shenanigans](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 166: Sycophancy, Zip bombs and AI Native Development](https://www.wearedevelopers.com/magazine/585-dev-digest-166-sycophancy-zip-bombs-and-ai-native-development) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)