×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Sr SOC and IR Manager; Remote or On Site

Remote / Online - Candidates ideally in
Stratford, Fairfield County, Connecticut, 06614, USA
Listing for: 102 Crane Company
Remote/Work from Home position
Listed on 2026-10-04
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 140000 - 180000 USD Yearly USD 140000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Sr SOC and IR Manager (Remote or On Site)

Do you enjoy building and leading high-performing teams while staying close to the work? Are you energized by transforming security operations, modernizing detection and response, driving automation, and partnering across the business to raise readiness? We are looking for a hands-on leader to help shape and run our SOC and incident response program ne is seeking a Senior Manager, Security Operations & Incident Response to lead our Security Operations Center and Incident Response (IR) program.

This role helps to define the operating model, people leadership, and continuous improvement of our detection and response capabilities, partnering across Global Information Security, IT, and business teams to deliver security outcomes globally. This position reports to the CISO. In this role, you will lead our global incident response program, related processes and technologies, and the US and international SOC teams.

This is a hands-on leadership role: you will coach and develop analysts, strengthen investigation and response standards, and help evolve our security operations across endpoint, network, cloud, SaaS, and identity telemetry using automation and modern workflows to increase speed, consistency, and quality. As a manager with global responsibilities for SOC and IR, you will bring a steady, practical approach under pressure and the ability to lead incident coordination across technical and non-technical stakeholders.

You will be comfortable serving as an incident commander, making time-sensitive decisions, setting priorities, and guiding teams through investigation, containment, recovery, and follow-up improvements while communicating clearly with leadership throughout.

Responsibilities and Duties:
  • Lead and continuously improve the SOC and incident response program, including operating model, standard work, and outcomes.
  • Serve as incident commander for high-severity investigations, coordinating cross-functional response and driving clear decisions, timelines, and communications.
  • Lead and develop a distributed team of analysts/engineers; build a strong culture of learning, quality, and operational excellence.
  • Own detection and response capability across endpoint, network, cloud, SaaS, and identity telemetry; improve signal quality and reduce noise through tuning and engineering.
  • Define, maintain, and test playbooks/runbooks and escalation paths, drive readiness through exercises and continuous improvement.
  • Drive automation and orchestration (SOAR) to streamline triage and response, integrate systems, and reduce manual effort.
  • Guide thoughtful adoption of AI-assisted workflows to accelerate investigations and reporting, with appropriate validation, governance, and analyst enablement.
  • Manage SOC tooling, service partnerships, and performance; ensure clear expectations, measurable SLAs, and continuous value delivery.
  • Develop and maintain program metrics, KPIs, and executive-ready reporting; track effectiveness and drive improvements in speed, quality, and consistency.
  • Partner with Legal, Privacy, HR, GRC, Risk Management, and IT to align response processes, documentation, and communication practices.
  • Evaluate, plan, and implement security operations improvements and supporting solutions; keep practices aligned with evolving standards and best practices.
Qualifications and

Competencies:
  • Experience managing, leading, and developing remote/distributed teams with diverse backgrounds and skill levels.
  • Demonstrated success designing and running SOC and incident response processes across traditional enterprise environments and modern cloud/SaaS services.
  • Strong, current knowledge of security operations tradecraft: alert triage, investigation, containment/recovery coordination, post-incident reviews, and continuous improvement.
  • Expertise with security telemetry and analytics: SIEM engineering, log normalization, detection content development, alert tuning, and correlation across endpoint/network/cloud/identity sources.
  • Working knowledge of security automation/orchestration (SOAR) and integration patterns (APIs, webhooks, scripting) to reduce toil and improve response consistency.
  • Strong fundamentals in Windows and Linux administration, networking, and modern enterprise services; able to go deep when needed and translate technical details for stakeholders.
  • Solid understanding of identity and access controls (SSO, MFA, conditional access concepts) and the role of identity telemetry in detection and response.
  • Ability to lead high-severity…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary