Manager, Security Operations Centre (SOC)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+28 more
Job description
BlueVoyant is seeking a Manager, Security Operations Center (SOC) to lead a growing SOC organization of roughly 60 employees, playing a critical role in protecting client relationships and driving retention. This is a client-facing leadership role responsible for shaping how customers experience the SOC - from escalation handling through the metrics and reporting that inform leadership decisions. The role carries strong potential for growth into a higher-level leadership position as the team and business scale, making it a great fit for an ambitious leader who wants to build and shape a growing organization. What You’ll Do:
- Lead, develop, and manage a team of Team Leads, Trainers, and Security Analysts, providing strategic direction, coaching, and performance management
- Assume full responsibility and accountability for ensuring all SOC customers receive world-class service
- Own the management of customer escalations, with the primary goal of client retention, partnering closely with Client Success on remediation plans and client communication
- Provide oversight and management of Team Leads and the wider Analyst team, ensuring consistent quality and performance across the SOC
- Lead post-incident review meetings to capture lessons learned following the resolution of critical events
- Ensure key Security Operations actions incorporate relevant customer impact considerations by engaging key stakeholders and communicating known/suspected implications of technical decisions
- Validate that Security Operations activities adequately address customer requirements across all MSS services
- Oversee operations in deterring, identifying, monitoring, investigating, and analyzing network intrusions
- Supervise complex event investigation and incident declaration, ensuring events are properly identified, analyzed, and escalated to incidents
- Ensure the team’s incident investigation, handling, response, and documentation meet quality and SLA standards
- Assist in the advancement of security policies, procedures, and automation
- Develop incident response reporting and policy updates as needed
- Partner cross-functionally with Client Success, Content Engineering, Threat Hunt, and Product leadership to drive service improvements and represent the SOC’s priorities
- Develop and maintain SOC performance metrics, delivering regular reporting on team performance, incident trends, and customer outcomes to leadership
- Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure continued business as usual
- Maintain a strong awareness of the current threat landscape
Requirements
- Experience working within a global organization, partnering with distributed teams across multiple regions and time zones
- Prior experience managing managers or team leads, with direct accountability for team performance and development
- Ability to handle high-pressure situations in a productive and professional manner
- Ability to work directly with customers to understand requirements for and feedback on security services, including managing escalations to protect client relationships
- Advanced written and verbal communication skills, with the ability to present complex technical topics in clear and easy-to-understand language
- Strong teamwork and interpersonal skills, including the ability to work effectively with a globally distributed team
- Able and willing to work in a 24/7/365 environment
Technical Expertise:
- Knowledge of and experience with the Microsoft Security Stack (Defender, Sentinel etc)
- Knowledge of and experience with intrusion detection/prevention systems and SIEM software
- Advanced knowledge and understanding of network protocols and devices
- Advanced experience with Mac OS, Windows, and Unix systems
- Ability to analyze event logs and recognize signs of cyber intrusions/attacks
- Strong knowledge of: SIEM, Packet Analysis, SSL Decryption, Malware Detection, HIDS/NIDS, Network Monitoring Tools, Case Management System, Knowledge Base, Web Security Gateway, Email Security, Data Loss Prevention, Anti-Virus, Network Access Control, Encryption, and Vulnerability Identification
Nice to Have:
- Experience partnering with or managing teams based in the Philippines
- Experience in network/host vulnerability analysis, intrusion analysis, digital forensics, penetration testing, or related areas
- 8+ years of hands-on SOC/TOC/NOC experience
- Certifications such as GCIA, GCIH, GCFA, GCFE, CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, or MCSE
- Familiarity with tools such as IDA Pro, PEiD, PEview, Procmon, Snort, Bro, Kali Linux, Metasploit, NMAP, and Nessus
- Familiarity with GPO, Landesk, or other IT infrastructure tools
- Understanding of and/or experience with one or more programming languages: .NET, PHP, Perl, Python, Java, Ruby, C, C++
Education: Bachelor’s degree in Information Security, Computer Science, or another technology / engineering-related field preferred. Candidates with proven experience in security/network operations will also be considered., Are you able and willing to commute to the College Park, MD office 2-3 days per week?* Do you have prior experience managing managers or Team Leads, with direct accountability for their performance and development? Have you led a team of 40+ employees, such as within a Security Operations Center, NOC, or similar 24/7 technical environment?* Do you have experience managing customer escalations, with a focus on client retention?* Do you have knowledge of and experience with intrusion detection/prevention systems and SIEM software?* Are you able and willing to work in a 24/7/365 environment (including outside standard business hours as needed)?* Do you have experience partnering with distributed teams across multiple regions and time zones?
Benefits & conditions
- Work alongside experienced SOC and cybersecurity leaders, including former government cyber professionals and industry veterans
- Gain exposure to complex customer environments and a wide range of MSS services across industries
- Join a global, mission-driven cybersecurity company defending organizations worldwide with cutting-edge data, technology, and expertise
- Competitive compensation and a comprehensive benefits package, with support for wellbeing, development, and career growth
About the company
BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.
Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.
Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats..
All employees must be authorized to work in the United States of America. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.
Disclaimer: Please note that pursuant to contractual requirements and applicable law, for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?
Is Software Engineering Over-Saturated?