Info Security Blue Team Manager
Listed on 2026-08-29
-
IT/Tech
Cybersecurity
Description
Ambition:
Become a vibrant $10B institution by 2033, fueled by talented, purposeful people.
Mission:
Help people improve their financial strength, achieve their dreams, and love where they bank.
The Blue Team Manager is responsible and accountable for the full defensive security lifecycle at UCCU: detection engineering, continuous monitoring, incident response, and cyber recovery. This role leads the team that protects member data and credit union operations day to day, owns UCCU’s logging and monitoring program, and serves as the primary operational commander during active security incidents. The Blue Team Manager also owns UCCU’s response and recovery capabilities under NIST CSF 2.0 (RS and RC functions), including NCUA incident notification, stakeholder communications, BCP/DR coordination for cyber events, and post-incident regulatory follow-up, ensuring that every incident is closed with documented lessons learned and that the program measurably improves over time.
DetectionEngineering and Continuous Monitoring
- Operate and mature the detection stack (SIEM, SOAR, EDR, NDR): define and maintain baselines, correlation rules, alert thresholds, detection use cases, and ATT&CK coverage; document and test all detection logic.
- Own the logging program: define what to log, where, and how; ensure reliable ingestion, field normalization, and retention in alignment with UCCU’s Records Retention Schedule; perform routine completeness reviews, onboard new log sources, and provide evidence for audits and examinations.
- Coordinate day-to-day with the outsourced SOC: manage the triage handoff process, review escalations, drive the false-positive and missed-detection feedback loop, and participate in regular SOC review calls.
- Run DLP and integrity controls to prevent exfiltration and validate software, firmware, and data integrity; coordinate with system owners for remediation of identified gaps.
- Operationalize cyber threat intelligence: feed threat data into risk determinations, detection content, and threat hunt hypotheses; maintain awareness of adversary TTPs relevant to financial institutions and credit unions.
- Direct and oversee threat hunting operations: assign hunt hypotheses, review findings, and translate outcomes into new or improved detection rules.
- Serve as incident commander during active security events: lead triage, scoping, forensic analysis, impact assessment, containment, mitigation, and eradication; make real-time decisions on response actions and resource deployment.
- Design incident investigation frameworks: define scope, establish investigative hypotheses, assign work streams to IR Analysts, and drive investigations to documented root cause conclusions.
- Provide structured, timely updates to the CISO and relevant stakeholders throughout active incidents, including current status, confirmed findings, open questions, and defined next steps.
- Ensure all incident documentation is complete and examiner-ready from initial detection through post-incident review (PIR); own the PIR process and integration of lessons learned into detection and process improvements.
- Manage all incident-related work in the team's designated ticketing system; ensure tickets reflect current status at every handoff and shift change.
- Oversee malware triage and digital forensics work performed by IR Analysts; maintain chain of custody for evidence that may support legal or regulatory action.
- Support UCCU's NCU
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).