CoinDesk

Manager / Sr. Manager, SecOps & Cyber Defense

CoinDesk$185K — $235K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of hands-on experience in SOC operations and security incident response.
  • 2+ years managing or leading a distributed team.
  • Expertise in cloud-native threats across AWS, GCP, or Azure.
  • Proficient with SIEM platforms, EDR/XDR systems, and SOAR tools.
  • Strong scripting skills in Python, Bash, or Go for automation.
  • Solid understanding of network protocols, cloud architecture, and digital forensics.
  • Ability to maintain composure during high-pressure security incidents.

Responsibilities

  • Manage and mentor a small team of SOC Analysts and Incident Responders across time zones.
  • Serve as the primary escalation point for high-severity security incidents.
  • Define and track operational metrics to drive SOC performance improvements.
  • Collaborate with various teams during critical incident phases.
  • Lead end-to-end response for major security incidents including post-mortem reporting.
  • Design and optimize detection rules to identify sophisticated threats.
  • Conduct threat research to enhance detection capabilities and response readiness.

Benefits

  • Competitive benefits package including health and wellness programs.
  • Opportunities for professional development and certifications.
  • Flexibility through a 4-day onsite work requirement in NYC.
  • Participation in Red/Purple team exercises for skill enhancement.
  • Access to advanced tools and technologies in cybersecurity.
Full Job Description

Reports to:

Head of Security Engineering

Position Overview

We are seeking an experienced, hands-on Manager / Sr. Manager of SecOps & Cyber Defense to lead, scale, and actively drive our 24/7 security detection and response capabilities in the US, UK, & EMEA.

In this dual-capability role, you will lead a lean, highly technical group of SOC analysts and incident responders while remaining deeply connected to the engineering work. You will sit in the hot seat during major incidents, build high-efficacy detection engineering pipelines across cloud and hybrid infrastructure, and continuously elevate our threat hunting and triage posture.

This role is based in NYC and will be required to work onsite at our office located in Chelsea a minimum of 4 days per week. The position reports to the Head of Security Engineering.

Responsibilities:

Leadership & Team Operations

  • Manage & Mentor:Lead and mentor a small, high-performing team of SOC Analysts and Incident Response engineers across multiple time zones.

  • On-Call & Escalations:Serve as the primary point of escalation for high-severity security incidents, managing the global operational shift structure and continuous coverage model.

  • Metrics & Maturity:Define and track key SOC operational metrics (MTTD, MTTR, false positive ratios, incident coverage against MITRE ATT&CK) to drive continuous improvement.

  • Cross-Functional Collaboration: Partner closely with Infrastructure, Cloud Platform, DevOps, Corporate IT, Legal, and Compliance teams during critical triage and investigation phases.

Technical Execution & Incident Response

  • Incident Management:Drive end-to-end response for major security incidents—from initial detection, containment, and eradication to root-cause analysis and post-mortem reporting.

  • Detection Engineering:Design, write, and tune high-precision detection rules (SIEM, EDR, Cloud-native logs) to minimize noise and highlight sophisticated threat activity.

  • Forensics & Triage:Perform hands-on digital forensics (memory, disk, network artifact analysis) and reverse-engineer suspicious scripts/payloads when necessary.

  • Threat Research & Readiness:Conduct targeted research into emerging threat actor TTPs, zero-days, and cloud vulnerabilities to preemptively fortify detection capabilities and response playbooks.

  • Adversarial Testing & Exercises:Lead and participate in regular Red/Purple team operations and executive tabletop exercises to stress-test incident response readiness and validate control coverage.

  • Threat Hunting:Proactively hunt for undetected threat actor behavior using internal logs, intelligence feeds, and custom queries.

  • SOAR & Automation:Build and refine automated response playbooks using Python, API integrations, and SOAR tools to streamline repetitive analyst workflows.

Experience & Qualifications:

  • 8+ years of dedicated, hands-on experience in SOC operations, threat detection, and security incident response.

  • 2+ years of direct people management or formal team leadership experience, preferably overseeing a geographically distributed workforce.

  • Deep operational expertise in investigating cloud-native threats (AWS, GCP, or Azure), container environments (Kubernetes, Docker), and modern SaaS infrastructure.

  • Advanced proficiency with modern SIEM platforms, EDR/XDR suites, log aggregators, and SOAR tools.

  • Strong scripting and automation skills in Python, Bash, or Go to automate triage tasks and query APIs.

  • Strong knowledge of network protocols, cloud architecture, identity systems (Okta, Azure AD), and digital forensics fundamentals.

  • Proven ability to stay calm, decisive, and communicative under pressure during high-severity security incidents.

Nice-to-Have:

  • Prior experience in Financial Services, FinTech, Digital Assets, or high-throughput trading environments operating under strict regulatory audit standards (SOC 2, ISO 27001, SEC/FINRA frameworks).

  • Relevant industry certifications such as GIAC (GCIH, GCFA, GNFA, GCDA), CISSP, or OSCP.

Bullish US LLC & CoinDesk Inc. are committed to offering competitive compensation and benefits. The anticipated base salary for this position is $185,000 - $235,000 + discretionary annual target bonus + performance incentives/benefits. Offered salary will be reflective of job related knowledge, skills and commensurate experience.

About CoinDesk

CoinDesk is a media company that covers news and analysis on the cryptocurrency and blockchain industries. The company was founded in 2013 by Shakil Khan. CoinDesk's website provides news, analysis, and data on cryptocurrencies, blockchain technology, and related topics. The company also hosts conferences and events related to the cryptocurrency and blockchain industries. CoinDesk's clients include investors, traders, and other professionals in the cryptocurrency and blockchain industries.
Learn more about CoinDesk
Size
50 employees
Industry
Founded
2013

Similar Jobs

More Jobs at CoinDesk

  • CoinDesk
    Program Manager
    $200K — $250K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person
  • CoinDesk
    Senior Accountant
    $135K — $150K *
    New York, NY 10025 (New York County)
    Finance & Insurance
    In-Person

More Information Technology Jobs

Find similar Manager / Sr. Manager, SecOps & Cyber Defense jobs: