Security Operations Manager
Listed on 2026-02-16
-
IT/Tech
Security Manager, Cybersecurity, Cloud Computing
Join Aya Healthcare, winner of multiple Top Workplace awards!
We are seeking a Manager, Security Operations to lead and modernize our enterprise security operations function, with accountability for incident response, detection engineering, automation, operational metrics, and continuous improvement. This role owns the daytoday execution and evolution of security operations using Service Now Security Incident Response (SIR) as the system of record and partners closely with internal teams, managed service providers, and nearshore/offshore resources.
This is a builder focused leadership role for someone who thrives on ownership and momentum. Aya is actively maturing its security operations capabilities-moving from reactive alert handling toward measurable, scalable, and automated Sec Ops outcomes. You'll have the mandate to design modern SIR playbooks, improve signal quality, automate response, and scale operations across a blended delivery model while clearly demonstrating impact through MTTx metrics.
Who We Are:We're a $8+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform.
At Aya, we're obsessed with creating exceptional experiences for our clients, clinicians, and employees. In fact, we put employee satisfaction above all else. Our team members are responsible for incomparable customer experience and we know that happy employees are critical to maintaining happy clients. We foster an entrepreneurial, high-energy, low-bureaucracy culture and value innovative thinking and creative problem-solving. We embrace diversity in thought and backgrounds unified by a commitment to high achievement.
When you join Aya, you'll be surrounded by teammates who care about you as an individual and leaders who will help you grow both personally and professionally.
- You will report to the VP, Information Security
. - Own the execution and continuous improvement of Aya Healthcare's enterprise Security Operations program.
- Lead a blended security operations model combining internal analysts, nearshore/offshore resources, and managed service providers.
- Establish clear operating models, escalation paths, staffing coverage expectations, and accountability across all Sec Ops resources.
- Serve as the primary owner of Service Now Security Incident Response (SIR) workflows, data models, and operating procedures.
- Design, implement, and continuously improve SIR playbooks to automate triage, enrichment, containment, and response actions.
- Drive automation that reduces manual analyst effort and improves MTTD, MTTR, and MTTC through standardized playbook execution.
- Ensure incidents are consistently triaged, investigated, documented, and remediated using Service Now SIR.
- Oversee detection and response capabilities across EDR and SIEM platforms
, ensuring high-quality signal ingestion and routing into SIR. - Operate confidently across Microsoft Azure security capabilities available through Microsoft E5 environments (e.g., Defender, Sentinel).
- Define, track, and improve MTTx metrics
, using data to prioritize automation and process improvements. - Lead postincident reviews and ensure lessons learned translate into improved detections, playbooks, and response procedures.
- Manage, coach, and develop security operations personnel while fostering a high-energy, accountable team culture.
- Act as a trusted escalation point during security incidents and clearly communicate operational risk and response status to leadership.
- 5+ years of experience in Security Operations, Incident Response, or SOC related roles.
- 2+ years of direct experience managing and operating Service Now Security Incident Response (SIR), including workflow ownership and playbook design.
- Demonstrated experience designing or operating incident response automation and playbooks within SIR or SOARlike platforms.
- Hands-on experience integrating EDR platforms (e.g., Microsoft Defender and/or Crowd Strike Falcon) with Service Now SIR.
- Strong experience operating and managing EDR and SIEM solutions in an enterprise environment.
- Strong hands-on experience with Microsoft Azure security solutions
, including capabilities available through Microsoft E5 subscriptions
. - Demonstrated experience managing and improving MTTx metrics (e.g., MTTD, MTTR) to drive operational change.
- Proven experience leading security operations teams, including internal staff and external service providers.
- Strong incident leadership, communication, and decision-making skills with the ability to influence across teams.
- Security Operations Ownership: Endtoend accountability for Sec Ops outcomes, not just alert handling or vendor oversight.
- Service Now SIR & Automation (Critical): Proven…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).