ASO Threat Analyst Manager | Remote
Overland Park, Johnson County, Kansas, 66213, USA
Listed on 2026-10-11
-
Business
Security Management & Operations
This is a second shift position working Tuesday-Friday from 12PM-11PM Eastern Time. The ASO Threat Analyst Manager is a tactical, hands-on operational leader responsible for daily frontline execution across our global 24/7/365 Agentic Security Operations (ASO) team. You will lead a high-performing team of threat analysts triaging, investigating, and containing threats across a multi-tenant client base, operating directly alongside automated and agentic AI workflows.
While grounded in daily queue management and incident handling, you maintain a strategic perspective on service health. You will actively connect daily frontline operations with Detection Engineering, SOAR Engineering, and Threat Hunting, while partnering closely with Client Success to tackle chronic operational friction and noisy client environments. You will need situational awareness during tense client interactions to de-escalate friction and drive practical, collaborative solutions.
you'll make an impact
Tactical Operations & Queue Governance:
Own daily shift execution, queue hygiene, and alert velocity to meet strict client SLAs and SLOs across our ASO service delivery model. Supervise the human-in-the-loop operational interface, validating agentic AI triage outputs, enriched telemetry, and automated investigations for analytical rigor and accuracy. Conduct regular ticket audits and investigation spot-checks to ensure high-fidelity analysis, defensible evidence gathering, and crisp client-facing notes.
Act as the primary operational escalation point, stepping in as tactical incident lead during critical (P1/P0) security events and client crises. Run disciplined shift handoffs, identify operational bottlenecks, and balance analyst workload across the floor. Lead tactical After-Action Reviews (AARs) to identify process breakdowns and immediate remediation steps. Engineering & Hunting Feedback Loops:
Direct and mentor the Threat Analysis team, specifically Senior Threat Analysts, to own the working-level handoffs with Detection Engineering, SOAR Engineering, and Threat Hunting. Provide quality control and governance over analyst feedback, ensuring tuning requests, automation ideas, and hunt referrals make technical sense, address root causes, and align with operational standards. Engage directly with engineering and hunting leads only when escalations occur, blockers arise, or cross-team prioritization is needed.
Define clear next steps, action items, and accountability loops across all teams to ensure feedback items are tracked to completion rather than lost in transition. Consultative Client & Partner Engagement:
Read the room effectively during high-pressure client calls, gauging stakeholder temperament, adjusting communication style dynamically, and actively de-escalating tense situations. Partner tactically with Client Success Managers (CSMs) on at-risk or noisy accounts to review repeat alerts, agent health issues, and policy misconfigurations. Lead client-facing incident discussions with a calm, consultative posture, turning recurring operational friction into actionable security recommendations rather than repeatedly handling the same false alarms.
Team Coaching & Performance:
Mentor analysts on the floor through real-time investigation guidance, scenario walk-throughs, and technical quality reviews. Guide analysts in working effectively with autonomous and agentic tools, ensuring team members build strong critical-thinking and investigative skills rather than blindly trusting automated outputs. Manage shift schedules, coverage models, and on-call rotations to prevent analyst burnout in a high-tempo environment. Coach frontline analysts toward technical career milestones in threat hunting, detection…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).