Coca-Cola

Manager, Cyber OT SecOps

Coca-Cola$124K — $148K *
Manufacturing & Automotive
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6-10 years of cybersecurity experience with a focus on OT/ICS security operations.
  • Experience leading SOC functions for OT/ICS monitoring and incident response.
  • Familiarity with OT monitoring platforms like Claroty and Microsoft Defender for IoT.
  • Knowledge of industrial control systems architectures and the Purdue Model.
  • Understanding of cybersecurity frameworks relevant to OT, such as NIST CSF and ISA/IEC 62443.
  • Able to provide operational guidance to MSSPs or distributed SOC teams.
  • Strong communication skills to convey technical risks to diverse stakeholders.

Responsibilities

  • Own OT security monitoring and detection capabilities within the SOC.
  • Design and tune OT-specific detection rules for various monitoring platforms.
  • Evaluate and enhance detection coverage for OT-specific threats.
  • Collaborate with OT Cybersecurity teams for effective monitoring tool deployment.
  • Lead investigation and response to OT security incidents with a focus on safety and uptime.
  • Develop and maintain incident response playbooks tailored for OT environments.
  • Build relationships with plant leadership to understand operational challenges and improve SOC procedures.

Benefits

  • Full range of medical and financial benefits based on position.
  • Opportunities for professional development and training.
  • Support for travel to manufacturing sites for relationship building and assessments.
Full Job Description
Job Description Summary:

Manager, Cyber OT SecOps

Overview

The Manager, Cyber OT SecOps is The Coca-Cola Company's operational leader for monitoring, detecting, and responding to cyber threats targeting the industrial control systems and manufacturing technology that keep Coca-Cola production running. This role sits within Cybersecurity Operations and owns the SOC-side of OT security - ensuring that threats to plant floor systems are detected, triaged, investigated, and resolved with the speed and manufacturing context required to protect production, safety, and product quality.

Reporting to the Senior Director, Cybersecurity Operations, this is an individual-contributor role that also provides day-to-day operational leadership of the managed security service provider (MSSP) SOC analysts supporting OT environments. The Manager builds deep relationships with plant teams to understand how manufacturing operations work, designs detection playbooks calibrated to OT realities, and partners with the OT Cybersecurity engineering team to ensure the right monitoring and detection mechanisms are in place. The role bridges the gap between traditional IT-centric SOC operations and the unique requirements of operational technology environments.

Key Responsibilities

OT Security Monitoring & Detection

  • Own the OT security monitoring and detection capability within the SOC, ensuring comprehensive visibility into threats targeting industrial control systems, SCADA, HMIs, PLCs, historians, and manufacturing networks.


  • Design, tune, and maintain OT-specific detection rules, alerts, and use cases across OT monitoring platforms (such as Claroty or Microsoft Defender for IoT), EDR, network monitoring (such as Palo Alto), and SIEM.


  • Continuously evaluate and improve detection coverage for OT-relevant threats, including unauthorized access, network anomalies, configuration changes, and lateral movement between IT and OT environments.


  • Partner with the OT Cybersecurity engineering team to ensure monitoring tools are properly deployed, configured, and maintained across manufacturing sites.


OT Incident Triage & Response

  • Lead the triage, investigation, and response to security events and incidents in OT environments, providing manufacturing context and ensuring response actions account for safety, uptime, and operational continuity.


  • Develop and maintain OT-specific incident response playbooks, escalation procedures, and communication templates in partnership with SOC leadership and plant teams.


  • Coordinate with IT SOC, Incident Response, and OT engineering teams during cross-domain incidents that span IT and OT boundaries.


  • Conduct post-incident reviews and drive lessons learned into improved detection, response, and prevention capabilities.


Plant Partnerships & OT Context

  • Build and maintain trusted relationships with plant leadership, plant engineers, and operations teams to understand manufacturing processes, control system architectures, and operational constraints.


  • Translate plant floor operational knowledge into SOC detection playbooks and triage procedures that reduce false positives and improve response relevance.


  • Educate SOC analysts and MSSP team members on OT-specific concepts, protocols, and operational considerations.


  • Support plant visits and site assessments to evaluate monitoring effectiveness and identify coverage gaps.


MSSP SOC Team Leadership

  • Provide day-to-day operational direction to MSSP SOC analysts supporting OT monitoring, setting priorities, reviewing alert quality, and maintaining service-level expectations.


  • Define standard operating procedures, detection playbooks, and training materials for the MSSP team specific to OT environments.


  • Monitor MSSP performance and drive continuous improvement in OT alert handling, triage accuracy, and escalation quality.


Reporting & Continuous Improvement

  • Provide clear, executive-framed reporting to Cybersecurity Operations leadership on OT security monitoring posture, incident trends, detection coverage, and key risks.


  • Track and report on OT SOC metrics, including alert volume, triage times, detection coverage, and incident outcomes.


  • Continuously improve OT monitoring capabilities, detection logic, and SOC processes based on evolving threats, plant feedback, and lessons learned.


  • Support new plant projects, expansions, and technology changes with monitoring requirements and detection design.


Qualifications

  • Minimum 6-10 years of progressive cybersecurity experience, with significant focus on security operations and hands-on experience with OT/ICS cybersecurity in manufacturing, industrial, or critical infrastructure environments.


  • Demonstrated experience operating or leading SOC functions with OT/ICS monitoring responsibilities, including alert triage, incident investigation, and escalation.


  • Hands-on familiarity with OT monitoring and detection platforms such as Claroty, Microsoft Defender for IoT, or similar, as well as traditional security tools (EDR, SIEM, network monitoring).


  • Working knowledge of industrial control systems (PLC, HMI, SCADA, historians, DCS) and manufacturing network architectures, including the Purdue Model.


  • Familiarity with cybersecurity frameworks applicable to OT environments, including NIST CSF, NIST SP 800-82, and ISA/IEC 62443.


  • Experience providing operational direction to managed service providers or distributed SOC teams.


  • Strong understanding of IT/OT convergence challenges and the ability to operate effectively at the boundary between IT security operations and plant floor operations.


  • Excellent communication skills, with the ability to translate OT security risks and incidents into clear language for plant leaders, SOC leadership, and senior executives.


  • Relevant certifications such as GICSP, GRID, CISSP, CISM, or GCIH are preferred.


  • Willingness to travel to manufacturing sites to build plant relationships and evaluate monitoring effectiveness.


Education

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related field required.


  • Master's degree or relevant professional certification (GICSP, CISSP, CISM, or equivalent) highly desirable.


Reporting Relationship

Reports to the Senior Director, Cybersecurity Operations, within the Chief Information Security Office (CISO) organization.

No direct reports. Provides day-to-day operational leadership of MSSP SOC analysts supporting OT environments.

Location

Atlanta, GA (Global Headquarters)

Travel

Estimated up to 20% travel, primarily to Coca-Cola manufacturing sites across North America, with occasional travel to other Company facilities and industry events.

Skills:

Pay Range:
United States of America: 124,600 USD - 148,200 USD

Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.

Annual Incentive Reference Value Percentage:
15

Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.

Location(s):
United States of America

City/Cities:
Atlanta

Travel Required:
00% - 25%

Relocation Provided:
No

Job Posting End Date:
August 14, 2026

Similar Jobs

More Jobs at Coca-Cola

More Manufacturing & Automotive Jobs

Find similar Manager, Cyber OT SecOps jobs: