Talent.com
Cybersecurity Security Operations Center Manager

Cybersecurity Security Operations Center Manager

The Sherwin-Williams CompanyCleveland, Ohio, United States
job_description.job_card.variable_hours_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

The Cybersecurity Security Operations Center (CSOC) Manager's core function is to provide leadership and oversee the administration of the CSOC, including security engineers and security analysts. The CSOC is responsible for monitoring and alerting on cybersecurity events, ensuring the maintenance of the current and future technologies, and continually analyzing threat data to find ways to improve the organization's security posture. This position requires both the ability to tactically focus on immediate threats at hand as identified in alerts and intelligence as well as strategically remain focused on Initiatives tasked by senior leadership. Candidates must be highly analytical, technically competent, and have an ability to provide focus and calm during incident response scenarios. The ability to lead groups or move forward initiatives is essential. In addition, the ability to plan for future team needs requires staying informed of current events in technology platforms and the Cybersecurity industry.

Operational Management

  • Manage team employees reporting directly to you. Responsibilities include preparing midyear and annual staff evaluations and addressing both opportunities for growth (such as promotions) or improvement (such as employee performance improvement plans) as performances warrant.
  • Manage the on-call rotation and time off for the SOC
  • Providing regular training sessions and mentorship opportunities to facilitate knowledge-sharing within the team.
  • Hiring new staff members or contracting outside services to supplement your team's capabilities when needed.
  • Responsible for vendor management - existing and future contractual relationships with technology and service providers. This includes working to address support issues, contract renewals / discrepancies, bi-weekly meetings, Quarterly Business Reviews, etc.
  • Track tool performance / utilization to measure return on investment and support future evaluation / rationalization needs.
  • Responsible for identifying tool / service evaluation opportunities. Working closely with the Security Threat Architect.
  • Responsible for day-to-day CSOC budget management
  • Lead your team and communicate with management during incident response (IR) to ensure timely notification and containment occur. Responsibilities include ensuring communicating, documenting IR progress, and following through with post-mortem reviews.
  • Ensure CSOC meets regulatory compliance of both internal and external auditors by adherence to policies and procedures. Ensure version control of SOC alerts as well as least privilege access to logs and investigation data.
  • Ensure synchronization and collaboration between the CSOC and Cyber Threat Intelligence team.
  • Work with other departments to identify the root causes of security incidents and develop strategies to mitigate these risks.

Strategy & Planning

  • Work with employees on Individual Development plans. Interface with management and Human Resources to ensure plans meet business needs and provide measurable advancement steps to employee promotion and realization of career goals.
  • Responsible for building and briefing at the monthly Governance Board meetings for existing or future spend as appropriate.
  • Responsible for planning and prioritizing annual spend for CSOC in support of Operational Plan Development and advising upper management on budget forecasting.
  • Improve incident response times, reduce false positives and other extraneous alerts, and enhancing threat detection capabilities.
  • Work with CSOC and architecture in determining technology and resource requirements.
  • Participate in engagement with other service families and departments in addressing CSOC logging and monitoring needs. Engage with same groups in developing Enterprise logging and monitoring strategies and solutions.
  • Stay abreast of business and technological developments to properly prepare CSOC future posture.
  • Acquisition & Deployment

  • Work with upper management to understand budget availability to shape CSOC efforts.
  • Supervise team and / or perform compliance assessments to include Proof of Value (PoV) or Proof of Concept (PoC) for new program security tools.
  • Provide an accurate technical evaluation of the software application, system, or network, documenting the security posture, capabilities, and vulnerabilities against relevant information assurance policies.
  • Incidental Functions

  • Assist with other projects as required to contribute to efficiency and effectiveness of the organization.
  • Travel may be required but should not exceed 10% of work time.
  • Work outside the standard office 7.5-hour workday may be required with on-call availability.
  • This position is not eligible for sponsorship for work authorization now or in the future, including conversion to H1-B visa.

    Job duties include contact with other employees and access confidential and proprietary information and / or other items of value, and such access may be supervised or unsupervised. The Company therefore has determined that a review of criminal history is necessary to protect the business and its operations and reputation and is necessary to protect the safety of the Company's staff, employees, and business relationships.

    Formal Education & Certification

  • Bachelor's Degree (or foreign equivalent) or in lieu of a degree, at least 12 years in experience in the field of Information Technology or Business (work experience or a combination of education and work experience in the field of Information Technology or Business)
  • Knowledge & Experience

  • 10+ years IT experience.
  • 8+ years IT security experience
  • 4+ years of leading and managing a team of direct reports
  • Minimum 1 year experience with cyber-security investigations and incident response.
  • Minimum 1+ years of experience in process analysis and improvement.
  • Background in metrics / reporting.
  • Experience identifying and implementing solutions to complex business problems.
  • Understanding of various operating systems (z / OS, Window, UNIX, Linux, AIX, etc.) with an emphasis on vulnerability assessment and hardening.
  • Ability to analyze reports by reviewing incident or threat frequency, severity, and duration data.
  • Preferred Experience

  • Experience in a Security Operations Center (SOC) or working with a Managed Security Service Provider (MSSP)
  • Supervisory and / or Management experience preferred.
  • Budget management
  • Vendor Management
  • Understand Log Management process and program
  • Certifications : Lean, CISSP, SANS GIAC, or CISM
  • Project Management concepts : use of JIRA, Planner, etc.
  • Delivery of Metrics demonstrating proof of value and key performance indicators
  • Understanding of CVSS, CVE, CWE, CPE, CCE, CWE, OVAL, SCAP and / or other standards.
  • Familiar with both IT and OT detect and respond functions
  • Familiar with email security tools such as Proofpoint, Abnormal Security, O365, etc.
  • Understanding of Threat Analysis and Threat Intelligence.
  • Experience with Security and Information and Event Monitoring (SIEM) products such as Sumo Logic, Splunk, etc.
  • Experience with Vulnerability Management products such as Qualys and WIZ.
  • Utilize key performance indicators to track analyst workloads as well as the efficiency of detection signatures / rules and associated monitoring technologies.
  • Benchmark and implement industry best practices to mitigate potential threats.
  • Support the preparation of appropriate reports and communicate status and results.
  • Familiarity with SOC-CMM
  • Personal Attributes

  • Strong analytical, evaluative, and problem-solving abilities.
  • Strong leadership skills
  • Ability to motivate in a team-oriented, collaborative environment.
  • Ability to set and manage priorities.
  • Strong written and oral communication skills.
  • Strong interpersonal skills.
  • Ability to present ideas in business-friendly and user-friendly language.
  • Self-motivated and directed.
  • Keen attention to detail.
  • Commitment to fostering a culture of inclusion and diversity
  • Hybrid on-site and remote work.
  • Minimal travel is required.
  • Work outside the standard office 7.5-hour workday may occasionally be required for on call coverage or overseeing after hours team investigations.
  • serp_jobs.job_alerts.create_a_job

    Operation Manager • Cleveland, Ohio, United States

    Job_description.internal_linking.related_jobs
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cybersecurity Team Lead

    Cybersecurity Team Lead

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Infrastructure Support Team Lead.Key Responsibilities Lead and manage technical teams focused on security infrastructure support in a hybrid environment ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Senior Manager of Information Security

    Senior Manager of Information Security

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Manager - Information Security - Threat Management.Key Responsibilities Lead daily security operations, including alerts, escalations, and ticketing Oversee thr...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Engineer

    Cybersecurity Engineer

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Engineer (Remote) to join their Cybersecurity team.Key Responsibilities Lead the integration of security into the SaaS environment and collaborate with En...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Senior Cybersecurity Engineer

    Senior Cybersecurity Engineer

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Senior Cybersecurity Engineer - Infrastructure Support.Key Responsibilities Design, install, maintain, and support Enterprise IT systems with a focus on security infras...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Analyst

    Cybersecurity Analyst

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Joint Cybersecurity Analyst to support the Federal Electronic Health Records Modernization office. Key Responsibilities Coordinate cyber operational processes across DoD...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Cybersecurity Incident Response Manager

    Cybersecurity Incident Response Manager

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Manager, Detection & Response.Key Responsibilities Oversee and guide the evolution of security incident response capabilities, including framework maturation and post-i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cybersecurity Manager

    Cybersecurity Manager

    Ohio Turnpike and Infrastructure CommissionBerea, OH, United States
    serp_jobs.job_card.full_time
    The Ohio Turnpike & Infrastructure Commission is seeking an experienced Cybersecurity Manager to work in the Technology Department at our Administration Building in Berea, Ohio.If you are intereste...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Licensed Mental Health Clinical Supervisor : Mobile Response and Stabilization Services (MRSS)

    Licensed Mental Health Clinical Supervisor : Mobile Response and Stabilization Services (MRSS)

    Applewood CentersAvon Lake, OH, US
    serp_jobs.job_card.full_time
    Under the supervision of the Mobile Response Stabilization Program Manager, the Licensed Shift Supervisor will take and assign crisis calls from the 24 / 7 hotline to have clinicians respond face to ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Security Infrastructure Team Lead

    Security Infrastructure Team Lead

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Infrastructure Support Team Lead to provide technical leadership and oversight for enterprise cybersecurity operations. Key Responsibilities : Lead and mentor a ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    IT Risk Manager

    IT Risk Manager

    Robert HalfCleveland, OH, US
    serp_jobs.job_card.full_time
    We are looking for an experienced IT Risk Manager to lead cybersecurity risk initiatives.The ideal candidate will develop strategies aligned with industry frameworks and foster collaboration across...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Operations Analyst

    Security Operations Analyst

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Security Operations Analyst.Key Responsibilities Monitor security tools and alerts to identify suspicious activity Investigate security incidents and coordinate respon...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    • serp_jobs.job_card.new
    Cybersecurity CDM Team Lead

    Cybersecurity CDM Team Lead

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Continuous Diagnostics and Mitigation (CDM) Team Lead.Key Responsibilities Lead and manage the Continuous Diagnostics and Mitigation (CDM) program to enhance agency sec...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_hours
    • serp_jobs.job_card.promoted
    Fulfillment Center Associate

    Fulfillment Center Associate

    FedExTwinsburg, OH, United States
    serp_jobs.job_card.full_time +1
    Come for a job and stay for a career! Federal Express Corporation (FEC) is part of the rapidly growing warehouse and transportation sector that helps keep America, and our economy, moving.Be part o...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Security Engineering Manager

    Security Engineering Manager

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Manager, Security Engineering.Key Responsibilities Lead and manage a team of security engineers focused on threat detection and infrastructure hardening Collaborate wi...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_30
    • serp_jobs.job_card.promoted
    Manager, Cyber Security Incident Response Manager

    Manager, Cyber Security Incident Response Manager

    AmTrust FinancialCleveland, OH, United States
    serp_jobs.job_card.full_time
    Manager, Cyber Security Incident Response Manager.The Cyber Security Incident Response Manager ensures the organization is prepared to detect, analyze, contain, and recover from cyber threats and i...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cybersecurity Event Analyst

    Cybersecurity Event Analyst

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Cybersecurity Event Analyst.Key Responsibilities Develop and mentor SOC L1 / L2 Information Security Analysts, ensuring adherence to processes and driving new detections ...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Cloud Operations Security Officer

    Cloud Operations Security Officer

    VirtualVocationsCleveland, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Business Information Security Officer, Cloud Operations.Key Responsibilities Serve as the trusted security advisor for Cloud Operations teams Develop and implement bus...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_variable_days
    • serp_jobs.job_card.promoted
    Lead IT Security Engineer

    Lead IT Security Engineer

    VirtualVocationsAkron, Ohio, United States
    serp_jobs.job_card.full_time
    A company is looking for a Lead IT Security Engineer.Key Responsibilities Manage and optimize the Splunk security environment for performance and efficiency Architect cybersecurity solutions and...serp_jobs.internal_linking.show_moreserp_jobs.last_updated.last_updated_1_day