Manager, IT - SOC , NY
Listed on 2026-06-09
-
IT/Tech
Cybersecurity, IT Project Manager
Location: New York
Company Overview
Created in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.
At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world’s most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG performance, lower risk, and improve productivity.
Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities.
The Manager, IT SOC is responsible for leading and developing a global Security Operations Center team, ensuring 24/7 security monitoring, effective incident response, and proactive vulnerability management across the organization. This role provides technical leadership, operational governance, and strategic direction to protect the company’s infrastructure, cloud environments, applications, and data from cyber threats. You will report to the Global IT Director and will manage a distributed team of SOC analysts based in the United States, France, and India, ensuring consistent processes, tooling, and service levels across regions.
WhatYou Will Do With Us
- Lead and manage the global SOC team (6 analysts across multiple time zones, relying also on our 24/7 global IT Service center in India).
- Ensure continuous monitoring of security events using SIEM, EDR/XDR, NDR, and cloud security tools.
- Define, maintain, and optimize SOC processes, playbooks, and runbooks.
- Ensure detection use cases are continuously improved to reduce false positives and increase detection coverage.
- Manage SOC KPIs and SLAs (MTTD, MTTR, alert volume, incident closure rates).
- Oversee security incident handling from triage to containment, eradication, and recovery.
- Act as escalation point for major security incidents and coordinate with IT, Infosec, Business, Legal, and Communications teams.
- Lead post‑incident reviews (lessons learned, root cause analysis) and implement remediation plans.
- Coordinate with external partners (MDR providers, forensics firms, law enforcement if required).
- Collaborate closely with Infosec on the vulnerability management lifecycle: scanning, prioritization, remediation tracking, and reporting.
- Work with infrastructure, cloud, and application teams to ensure timely patching and risk mitigation.
- Define vulnerability SLAs based on risk and business criticality.
- Help Infosec to provide risk‑based reporting to technology and business stakeholders.
- Contribute to security policies, standards, and operating procedures.
- Support audits, regulatory requirements, and frameworks (ISO 27001, NIST, SOC2, PCI DSS, GDPR, HIPAA, FEDRAMP, IRAP).
- Maintain documentation and evidence for security operations controls.
- Own SOC tooling strategy (SIEM, SOAR, vulnerability scanners, cloud security tools, etc.) and contribute to the other IT security solutions (EDR/XDR, Network & Cloud Security, Identity protection, etc.). Evaluate and implement new security technologies and integrations.
- Drive automation and orchestration to improve SOC efficiency and reduce manual workload.
- Contribute actively to the security logging quality (new technologies, review existing log sources and help to get them optimized and cleaned‑up).
- Manage and mentor SOC analysts across regions and time zones.
- Define shift models, on‑call rotations, and coverage strategy.
- Conduct performance reviews, training plans, and career development.
- Foster collaboration between US, France, and India teams to ensure consistent operations and engage actively with the overall IT & Infosec community.
- Produce executive‑level security operations reports and dashboards.
- Communicate risks, incidents, and trends to senior leadership (CISO, IT leadership, risk committees).
- Provide guidance to engineering and business teams on security best practices.
If you have the below experience and strengths this role…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).