Senior Manager, Cybersecurity Operations
Listed on 2026-08-08
-
IT/Tech
Cybersecurity, Security Management & Operations
The NFL Cybersecurity Operations team is responsible for safeguarding the organization's digital assets by ensuring the confidentiality, integrity, and availability of critical data, systems, and services. Through continuous monitoring, rapid incident response, and proactive threat management, the team defends the enterprise against an evolving cyber threat landscape.
We are seeking a Senior Manager, Cybersecurity Operations to lead the NFL's Cybersecurity Operations Center (CSOC). This leader will oversee the Cybersecurity Operations program and drive the continued evolution of our 24x7x365 security operations capability, transforming it from a primarily reactive, alert-driven function into a proactive, intelligence-led, and highly automated cyber defense program.
Reporting as a key leader within the cybersecurity organization, this individual will help define and execute the strategic vision for the "CSOC of the Future," where they will shape the operating model, technology strategy, and roadmap by leveraging automation, orchestration, agentic AI, advanced analytics, and emerging security capabilities to strengthen cyber resilience, enhance threat detection and response, and improve operational effectiveness across the enterprise.
Responsibilities- Lead the day-to-day operations and strategic direction of the 24/7/365 Cybersecurity Operations Center (CSOC).
- Lead incident response activities for high-priority cybersecurity events and oversee post-incident reviews and continuous improvement.
- Expand proactive threat hunting using threat intelligence, behavioral analytics, and AI-assisted investigations.
- Working closely with IT infrastructure, cloud, engineering, risk, and business leaders, this individual will help to define and deliver the future state of cybersecurity operations, ensuring the organization can rapidly detect, investigate, and respond to threats while maximizing productivity and reducing operational complexity.
- Collaborate with third-party security providers and managed security service providers (MSSP) s to optimize service delivery and operational effectiveness.
- Support major business events and critical operations by ensuring continuous monitoring and rapid incident response capabilities.
- Develop and execute the strategic roadmap for a modern Cybersecurity Operations Center built on automation, orchestration, AI, and agentic AI.
- Define the future operating model for security operations, balancing human expertise with autonomous security capabilities.
- Champion continuous modernization initiatives that improve resilience, scalability, and analyst effectiveness.
- Develop and execute the roadmap for a modern, AI-enabled SOC focused on automation, orchestration, and continuous operational improvement.
- Develop playbooks and orchestrated workflows using SOAR technologies to improve consistency, speed, and scalability.
- Leverage agentic AI and machine learning to automate repetitive analyst tasks, improve triage accuracy, alert enrichment, response actions, accelerate investigations, and enable autonomous response where appropriate.
- Identify opportunities to eliminate operational inefficiencies through intelligent automation and workflow optimization.
- Sponsor development of automation playbooks and integrations across the cybersecurity technology stack.
- Lead, mentor, and develop a high-performing cybersecurity operations team while fostering innovation and continuous learning.
- Lead Security Operations, Detection Engineering, Incident Response, Threat Hunting, and Security Automation teams.
- Establish KPIs that measure operational maturity, automation effectiveness, analyst productivity, detection quality, and response performance.
- Drive continuous improvement in Mean Time to Detect (MTTD), Mean Time to Respond (MTTR), alert fidelity, and analyst capacity through technology optimization.
- Drive integration and optimization of SIEM, SOAR, XDR, EDR, Threat Intelligence, Vulnerability Management, Identity Security, Cloud Security, Email Security, and Network Security
- Build detection engineering capabilities that continuously improves visibility across the enterprise including cloud, endpoints, network, email, and SaaS environments.
- Evaluate emerging cybersecurity technologies and recommend investments that improve operational capability and efficiency.
- Present cybersecurity operational maturity, modernization progress, and risk metrics to executive leadership through dashboards and operational reporting communicating cyber risk, operational performance, and program maturity.
- Partner with cybersecurity architecture, security engineering and IT teams to operationalize new security technologies and maximize value through integration and automation. Work with Information Security Office leadership team and other stakeholders to develop multi-year investment strategies for cybersecurity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).