Info Security Blue Team Manager

Utah Community Credit Union

$110K — $130K *
Provo, UT 84604In-Person
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, computer science, cybersecurity, or related field preferred, or equivalent professional experience.
  • 8+ years in security operations, incident response, detection engineering, or threat hunting, including 3+ years in a leadership role.
  • Proven experience managing incident response operations and serving as incident commander.
  • Hands-on experience with SIEM, EDR, and SOAR tools; familiarity with regulatory requirements for financial institutions.
  • Experience coordinating with outsourced SOCs or MSSPs, and a strong understanding of digital forensics.

Responsibilities

  • Lead the full defensive security lifecycle, including incident detection and response.
  • Operate and improve detection engineering tools and logging programs, ensuring compliance and reliability.
  • Serve as incident commander during active security events, making critical decisions regarding response actions.
  • Design frameworks for incident investigation and document outcomes comprehensively.
  • Manage crisis communications and regulatory notifications during incidents, ensuring messaging is accurate and timely.

Benefits

  • 401(k) plan with matching contributions
  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Professional development opportunities
  • Flexible work arrangements and supportive team culture
Full Job Description
What You'll Do

The Blue Team Manager is responsible and accountable for the full defensive security lifecycle at UCCU: detection engineering, continuous monitoring, incident response, and cyber recovery. This role leads the team that protects member data and credit union operations day to day, owns UCCU's logging and monitoring program, and serves as the primary operational commander during active security incidents. The Blue Team Manager also owns UCCU's response and recovery capabilities under NIST CSF 2.0 (RS and RC functions), including NCUA incident notification, stakeholder communications, BCP/DR coordination for cyber events, and post-incident regulatory follow-up, ensuring that every incident is closed with documented lessons learned and that the program measurably improves over time.

Detection Engineering and Continuous Monitoring
• Operate and mature the detection stack (SIEM, SOAR, EDR, NDR): define and maintain baselines, correlation rules, alert thresholds, detection use cases, and ATT&CK coverage; document and test all detection logic.
• Own the logging program: define what to log, where, and how; ensure reliable ingestion, field normalization, and retention in alignment with UCCU's Records Retention Schedule; perform routine completeness reviews, onboard new log sources, and provide evidence for audits and examinations.
• Coordinate day-to-day with the outsourced SOC: manage the triage handoff process, review escalations, drive the false-positive and missed-detection feedback loop, and participate in regular SOC review calls.
• Run DLP and integrity controls to prevent exfiltration and validate software, firmware, and data integrity; coordinate with system owners for remediation of identified gaps.
• Operationalize cyber threat intelligence: feed threat data into risk determinations, detection content, and threat hunt hypotheses; maintain awareness of adversary TTPs relevant to financial institutions and credit unions.
• Direct and oversee threat hunting operations: assign hunt hypotheses, review findings, and translate outcomes into new or improved detection rules.

Incident Management and Response (CSF 2.0: RS.MA, RS.AN, RS.MI)
• Serve as incident commander during active security events: lead triage, scoping, forensic analysis, impact assessment, containment, mitigation, and eradication; make real-time decisions on response actions and resource deployment.
• Design incident investigation frameworks: define scope, establish investigative hypotheses, assign workstreams to IR Analysts, and drive investigations to documented root cause conclusions.
• Provide structured, timely updates to the CISO and relevant stakeholders throughout active incidents, including current status, confirmed findings, open questions, and defined next steps.
• Ensure all incident documentation is complete and examiner-ready from initial detection through post-incident review (PIR); own the PIR process and integration of lessons learned into detection and process improvements.
• Manage all incident-related work in the team's designated ticketing system; ensure tickets reflect current status at every handoff and shift change.
• Oversee malware triage and digital forensics work performed by IR Analysts; maintain chain of custody for evidence that may support legal or regulatory action.

Incident Response Reporting and Communication (CSF 2.0: RS.CO)
• Support UCCU's NCUA 72-hour cyber incident notification process in coordination with Compliance and Legal: assess incidents against reporting thresholds, prepare required documentation, and maintain records of all regulatory communications.
• Coordinate member breach notification logistics with Compliance and Legal when applicable; ensure notifications meet content and timing requirements under applicable law.
• Support crisis communications during active incidents: in coordination with the CISO, Marketing, and Compliance, ensure that internal and external messaging is accurate, timely, consistent, and does not create additional legal or reputational risk; maintain a running communications log throughout the incident lifecycle.
• Manage voluntary external information sharing during incidents (e.g., FS-ISAC, law enforcement, peer institutions) in accordance with UCCU's incident response plans.
• Provide accurate, timely situational awareness to the CISO throughout active incidents; support the CISO in serving as the primary InfoSec liaison to Legal, Compliance, and senior leadership.
• Coordinate post-incident regulatory follow-up with the CISO: prepare supplemental documentation, respond to examiner inquiries, and track open regulatory items through to closure.

Cyber Recovery and Business Continuity Coordination (CSF 2.0: RC.RP, RC.CO)
• Maintain and execute cyber-specific recovery plans: lead the transition from containment to recovery, verify eradication, oversee system restoration, and confirm return to normal operations.
• Coordinate with IT and business line owners on BCP/DR activities for cyber events: ensure that cyber recovery scenarios are embedded in UCCU's BCP/DR planning, tested annually, and updated after each significant incident.
• Own post-incident member and stakeholder communication in coordination with Marketing and Compliance: ensure that recovery messaging is accurate, appropriately timed, and does not create additional legal or reputational risk.
• Conduct post-recovery reviews with all involved parties; document recovery timeline, gaps in recovery capability, and improvements required; track remediation items to closure.
• Maintain recovery capability metrics and report them to the CISO on a defined cadence.

Team Leadership and Continuous Improvement
• Hire, develop, and evaluate Blue Team staff including IR Analysts; set clear performance expectations aligned to team KPIs and CSF 2.0 function coverage.
• Manage team workload through established project management and ticketing platforms (e.g., monday.com, Jira, or equivalent); maintain visibility into all open incidents, projects, and improvement initiatives.
• Drive a formal program improvement cycle: collect lessons learned from incidents, purple team exercises, and audits; convert findings into prioritized improvement tasks tracked through to completion.
• Plan and execute purple team exercises in coordination with the Red Team; translate outcomes into detection improvements, updated playbooks, and updated training materials.
• Author, maintain, and version-control runbooks, playbooks, and IR procedures; ensure documentation is in a state of ongoing examiner readiness.
• Support CISO preparation for board and supervisory committee presentations related to Blue Team operations, incident metrics, and detection program maturity.

Who You Are

Education
• Bachelor's degree in information security, computer science, cybersecurity, or a related field is preferred; equivalent professional experience will be considered in lieu of a degree.

Experience
• 8 or more years of progressive experience in security operations, incident response, detection engineering, SOC, blue team, or threat hunting, with at least 3 years in a lead or management role.
• Demonstrated experience leading incident response operations, including serving as incident commander during significant events.
• Demonstrated experience authoring detections, building parsing/normalization, and performing threat hunts.
• Proven execution of IR playbooks and recovery activities, including cross-functional and external coordination.
• Experience with NCUA, FFIEC, or other financial institution regulatory reporting requirements for cybersecurity incidents is strongly preferred.
• Hands-on experience with SIEM platforms (Splunk, Microsoft Sentinel, or equivalent), EDR, and SOAR tooling.
• Experience managing or coordinating with an outsourced SOC or MSSP.
• Experience with digital forensics, malware analysis, and evidence chain of custody.
• Experience managing work through ticketing and project management platforms (ServiceNow, Jira, monday.com, or equivalent).
• Familiarity with BCP/DR planning and cyber recovery coordination is preferred.

Certifications (Preferred)
• GIAC Certified Incident Handler (GCIH)
• GIAC Certified Enterprise Defender (GCED) or GIAC Certified Forensic Analyst (GCFA)
• GIAC Security Leadership (GSLC) or equivalent management-level security credential
• CISSP
• CompTIA CySA+ or Security+ (or equivalent)
• MITRE ATT&CK Defender (MAD) certification

Knowledge, Skills, and Abilities
• Deep working knowledge of MITRE ATT&CK and its application to detection engineering, threat hunting, and purple team planning.
• Strong understanding of NIST CSF 2.0 Detect, Respond, and Recover functions, and the NIST SP 800-53 control families relevant to Blue Team operations, and their practical application in a regulated financial institution.
• Defensive security expertise across Windows, Linux, and macOS.
• Working knowledge of network protocols and packet/flow analysis.
• Familiarity with cloud logging and controls.
• Ability to make sound, time-pressured decisions during active incidents and communicate them clearly to leadership.
• Ability to write and interpret queries in at least one SIEM query language (SPL, KQL, or similar).
• Familiarity with log management concepts: source onboarding, field normalization, ingestion health monitoring, and retention policy enforcement.
• Strong written and verbal communication skills; able to produce examiner-ready documentation and brief senior leadership clearly and concisely, including clear and direct conversations with the CEO, executives, and upper management during a crisis.
• Comfort using ticketing and project management tools as a daily leadership discipline.
• Probabilistic reasoning: ability to assess likelihood of attacker activity, weigh incomplete evidence, and communicate confidence levels appropriately to leadership and examiners.
• Precision in reviewing logs, alerts, and configurations to avoid false positives or missed threats.
• Adaptability to evolving threats, new tools, and changing priorities; keeps up with emerging threats, new attack techniques, and defensive technologies.
• Ability to stay calm and focused during high-pressure incidents.
• Handles sensitive data responsibly and maintains trustworthiness in all actions.
• Ability to develop and mentor staff, set measurable expectations, and build a high-performing team culture.

What Success Looks Like

Success in this role is measured against the following performance measurements:
• % of critical systems and applications with confirmed, healthy log ingestion into SIEM
• % of MITRE ATT&CK techniques with at least one validated detection
• Tr

Similar Jobs

More Jobs at Utah Community Credit Union

More Information Technology Jobs

Find similar Info Security Blue Team Manager jobs: