Senior Manager – Cybersecurity Operations
Listed on 2026-07-26
-
IT/Tech
Cybersecurity, Security Management & Operations, Network Security, Information Security & Data Protection
Senior Manager – Cybersecurity Operations
Castelion is moving incredibly fast to develop and deliver advanced defense systems at a time when execution matters more than ever. We believe focus and technical excellence are decisive advantages - and we are building a team that can deliver real capability, not just concepts.
This is a rare opportunity to join at an early stage, where your work will directly shape critical systems, influence major technical decisions, and have immediate, real-world impact.
We are seeking an experienced Senior Manager – Cybersecurity Operations to join our cybersecurity operations team s critical role will lead defensive security operations, incident response, and threat monitoring, protecting our information systems, intellectual property, product development security, and critical infrastructure from common threat vectors as well as advanced persistent threats (APTs) and nation-state actors.
The ideal candidate will envision security to remain a business enabler and not a blocker, have deep expertise in defensive security operations, SOC leadership, proactive threat hunting, SIEM & SOAR, and incident response within highly regulated environments. Brings a practical, and up-to-date relevant technical understanding of protocols, encryption levels, patch levels, policy & procedure, etc., that are secure in the modern cybersecurity landscape.
Responsibilities:- Contribute to and mature our Security Operations Center (SOC) activities and ensure effective threat detection and response
- Direct threat hunting operations to proactively identify and neutralize threats before impact
- Lead incident response efforts for security events affecting all our information systems
- Develop and maintain defensive playbooks, runbooks, and standard operating procedures
- Coordinate with additional internal teams to conduct exercises that validate defensive posture
- Design and implement defense-in-depth strategies aligned with NIST, DoD, and intelligence community frameworks
- Evaluate and deploy advanced security technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms)
- Create and maintain security architecture documentation and network defense diagrams
- Contribute to security roadmap planning
- Establish and maintain threat intelligence program aligned to aerospace and defense sector threats
- Analyze threat actor tactics, techniques, and procedures (TTPs) using MITRE ATT&CK framework
- Produce threat intelligence reports and briefings for technical and executive audiences
- Collaborate with government agencies and industry partners on threat information sharing
- Track emerging threats and vulnerabilities relevant to defense systems and aerospace technology
- Contribute to compliance with NIST 800-171, CMMC, ITAR, DFARS, and other applicable regulations
- Support security audits, assessments, accreditation activities, and regular penetration testing
- Partner with IT operations, engineering, and program management teams on security initiatives
- Coordinate with government customers and oversight bodies on security matters
- Function as a primary stakeholder and subject matter expert for changes to cyber controls and policies
- 7+ years of hands-on experience in cybersecurity, with a focus in defensive operations
- 2+ years in a leadership or team lead capacity
- Proven experience operating in defense, aerospace, engineering, intelligence, government, or critical infrastructure sectors
- Experience in regulated environments (DoD, CMMC, NIST 800-171, ISO 27001, etc.)
- Demonstrated expertise in security monitoring, threat hunting, and incident response
- Demonstrated understanding of advanced persistent threat (APT) tactics and techniques
- Hands-on experience with enterprise security tools (SIEM, EDR, IDS/IPS, firewalls, proxies)
- Expert knowledge of network protocols, security architecture, and system hardening
- Expert proficiency as both a configurator and a consumer of security information and event management (SIEM) platforms
- Strong understanding of Windows and Linux security and forensics
- Experience with endpoint detection and response (EDR) solutions (Crowd Strike, Carbon Black, Defender, Sentinel One, etc.)
- Proficiency with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).