MDR Manager

Guardz

$110K — $130K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in SOC, MDR, or Incident Response handling complex attacks, with at least 2 years in a leadership role.
  • Hands-on expertise with EDR solutions such as SentinelOne, CrowdStrike, or Defender for Endpoint.
  • Proficiency with ITDR solutions for identity threat management across platforms like M365 and Google Workspace.
  • Experience with data analytics tools like Google BigQuery, Snowflake, or Splunk and fluency in SQL, KQL, or SPL.
  • Proven ability in MITRE ATT&CK-aligned detection and proactive threat hunting techniques.
  • Strong communication skills for conveying technical issues to diverse audiences.
  • Bachelor's in Cybersecurity, Computer Science, Information Technology, or equivalent experience.

Responsibilities

  • Own 24/7 shift coverage, ensuring efficient alert routing and escalation without monitoring gaps.
  • Manage response SLAs, reporting on key SOC KPIs to leadership including response times and detection efficacy.
  • Conduct quality assurance on closed alerts, reduce false positives, and uphold SOC standards through maintained documentation.
  • Lead, mentor, and develop MDR Analysts with ongoing training, performance feedback, and incident reviews.
  • Serve as the technical lead for Tier 3 threats, documenting and managing complex incident lifecycles.
  • Correlate alerts through various security platforms and execute proactive threat hunts using frameworks such as MITRE ATT&CK.
  • Utilize advanced tools and query languages to triage incidents rapidly and accurately, enhancing incident response processes.
  • Collaborate with MSPs during significant incidents, integrating findings to strengthen detection capabilities.

Benefits

  • Professional development opportunities including training and certifications.
  • Flexible work arrangements to support a healthy work-life balance.
  • Access to the latest cybersecurity tools and technologies.
  • A supportive team culture focused on collaboration and growth.
  • Health and wellness programs to assist employees in maintaining well-being.
Full Job Description
We are looking for an experienced MDR Manager to lead our Security Operations team. The ideal candidate combines strong technical expertise with operational leadership and enjoys developing analysts, improving processes, and managing complex security incidents across multi-tenant MSP environments.

As a hands-on leader, you will oversee day-to-day MDR operations, including coverage, SLAs, quality, escalation tiers, and analyst development. You will also serve as the final escalation point for Tier 3 threats and lead the team through the most complex investigations.

Responsibilities:
  • Own 24/7 shift coverage, tiering, and escalation paths so every alert reaches the right analyst and there are no gaps in monitoring or escalation. Participate in an on-call rotation with the team.
  • Own response SLAs (time-to-triage, time-to-notify, MTTR) and report SOC KPIs (MTTD, MTTR, detection efficacy, false-positive rate, case aging, customer satisfaction) to leadership.
  • Run QA on closed alerts and incidents, drive down false positives, and maintain the team's runbooks, playbooks, and SOC standards.
  • Lead, coach, and mentor MDR Analysts: regular 1:1s, performance feedback, onboarding, and the T1-to-T3 training path. Run tabletop exercises and post-incident reviews.
  • Act as technical lead and final escalation point for T3 incidents (advanced malware, identity threats like MFA fatigue and token theft, active breaches), leading the full lifecycle with defensible documentation.
  • Correlate alerts across EDR (SentinelOne, Defender for Endpoint), ITDR (M365, Google Workspace), and email security, and run proactive threat hunts aligned to MITRE ATT&CK.
  • Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed.
  • Partner with MSPs on major incidents and posture reviews, and feed findings back into detection with product, threat research, and engineering.

Requirements:
  • 5+ years in SOC, MDR, or Incident Response handling complex attacks, including 2+ years as a Team Lead, Shift Lead, or senior.
  • Hands-on expertise with EDR (SentinelOne, CrowdStrike, Defender for Endpoint) and ITDR (identity threat management across M365 and Google Workspace).
  • Hands-on experience with Google BigQuery, Snowflake, Splunk, Elastic, or equivalent, and fluency in a query language such as SQL, KQL, or SPL.
  • Experience with MITRE ATT&CK-aligned detection, proactive threat hunting, and AI-driven triage engines, automated playbooks, or agentic SecOps platforms.
  • Excellent communication skills, able to make high-risk technical findings clear to both technical and non-technical audiences.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience.
  • Preferred: CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH / GCIA / GCFA, or CISSP (or equivalent DoD 8570 / 8140 IAT Level II).

Similar Jobs

More Jobs at Guardz

More Information Technology Jobs

Find similar MDR Manager jobs: