> Markdown version of [/jobs/ext/2587830-soc-manager-cyber-threat-fusion-centers](https://www.wearedevelopers.com/jobs/ext/2587830-soc-manager-cyber-threat-fusion-centers). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # SOC Manager - Cyber Threat Fusion Centers - **Company:** Wells Fargo - **Location:** Charlotte, NC, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Data Loss, Digital Forensics, Intrusion Detection and Prevention, Network Intrusion Detection Systems, Phishing, Security Information and Event Management, GitHub Copilot, Mitre Att&ck, Malware, Cyber Threat Analysis, Cybercrime, Cyber Warfare, Security Orchestration, Automation & Response - **Published:** August 19, 2026 - **Apply:** https://www.juju.com/job/00000000gnus9j ## About the Role + 5+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education + 2+ years of Leadership experience + 5+ years of cybersecurity, security operations, incident response, threat hunting, digital forensics, or related information security experience. + 2+ years of leadership or management experience within a Security Operations Center (SOC), Cyber Defense Center, Fusion Center, or Incident Response organization. Desired Qualifications: + Experience leading high-performing operational teams in a 24x7 or mission-critical environment. + Experience serving in an Incident Commander, Incident Handler, Action Officer, or Major Incident Management role during significant cybersecurity events. + Proven ability to coordinate cross-functional response efforts across cyber defense, infrastructure, application, risk, legal, and business stakeholders. + Experience developing and mentoring analysts, team leads, and incident responders. + Experience investigating and responding to malware, phishing, insider threat, credential compromise, ransomware, data loss, cloud security, and network intrusion incidents. + Strong understanding of cybersecurity detection and response methodologies, threat intelligence, threat hunting, and adversary tactics, techniques, and procedures (TTPs). + Experience conducting root cause analysis, incident containment, eradication, recovery, and post-incident reviews. + Knowledge of MITRE ATT&CK, Cyber Kill Chain, NIST Incident Response Framework, and security operations best practices. + Experience with one or more of the following technologies: Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), Endpoint Detection and Response (EDR), Network Detection and Response (NDR), Threat Intelligence Platform (TIP), Case Management Tools, and Cloud Security Platforms. ## Description Wells Fargo is seeking an experienced Cybersecurity Professional to lead one of its Cyber Threat Fusion Teams that is responsible for monitoring and responding to cyber threats. The Information Security Engineering Manager will lead a Cyber Threat Fusion Center team responsible for the detection, triage, investigation, escalation, and response of cybersecurity threats impacting Wells Fargo. This leader will oversee a high-volume operational environment during peak periods of cyber activity, ensuring timely response to security incidents, adherence to operational standards, and achievement of service delivery objectives. The manager will provide leadership during security incidents, coordinate cross-functional response activities, drive continuous improvement initiatives, and develop a highly skilled team of cybersecurity professionals. The role requires strong technical expertise, operational leadership, incident management experience, and the ability to influence stakeholders across cybersecurity, technology, risk, and business organizations. In this role, you will: + Manage a team of cybersecurity analysts and incident responders responsible for the monitoring, triage, investigation, escalation, and response of cybersecurity threats and security incidents. + Lead daily Security Operations Center (SOC) activities to ensure timely detection, containment, mitigation, and resolution of cybersecurity events impacting the organization. + Partner with cybersecurity, technology, risk, and business stakeholders to ensure alignment with information security policies, standards, and operational objectives. + Provide subject matter expertise on security operations, cyber threat detection, incident response, threat hunting, and emerging cyber threats and adversary tactics. + Oversee the review, analysis, and correlation of security alerts, threat intelligence, and security telemetry to identify malicious activity and emerging risks. + Direct and coordinate cybersecurity incident response activities for high-severity and complex security events, ensuring appropriate escalation, communication, and resolution. + Serve as an incident commander or senior response leader during major cybersecurity incidents, coordinating cross-functional response efforts and executive communications. + Lead post-incident reviews and lessons-learned activities to identify root causes, improve detection and response capabilities, and reduce future risk. + Ensure operational effectiveness of security monitoring, incident response, threat management, and escalation processes through continuous improvement initiatives and performance measurement. + Drive the development, maintenance, and optimization of security operations procedures, response playbooks, workflows, and operational documentation. + Collaborate with cybersecurity engineering and platform teams to enhance the effectiveness of SOC technologies, detection capabilities, and automation initiatives. + Monitor operational metrics and service-level objectives to ensure timely incident handling, response quality, workload management, and overall team performance. + Build strong partnerships with senior leaders, business partners, and cybersecurity stakeholders to communicate risks, operational trends, and incident response activities. + Manage allocation of personnel and operational resources to ensure appropriate staffing, readiness, and coverage during peak periods of cyber activity. + Mentor, develop, and coach cybersecurity professionals, fostering technical growth, leadership development, and a culture of operational excellence. + Lead recruiting, hiring, succession planning, and talent management activities to build and retain a high-performing cybersecurity operations team. + Promote a culture of accountability, collaboration, continuous learning, and operational resilience across the Cyber Threat Fusion Center. + Demonstrate proficiency in using AI-assisted development and analysis tools (e.g., GitHub Copilot and approved code-centric agents) ## Related Videos - [Getting under the skin: The Social Engineering techniques](https://www.wearedevelopers.com/videos/38-getting-under-the-skin-the-social-engineering-techniques) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)