Full Job Description
The Security Operations Center Manager leads ARCO's day-to-day security monitoring, detection, and incident response activities. This role manages a team of Cybersecurity Analysts, oversees core security tools, and partners closely with Infrastructure, Applications, and GRC to maintain a strong, resilient security posture. This position is both strategic and hands-on, driving operational excellence, threat mitigation, and continuous improvement. As a senior member of the team, the role requires a strong ability to lead and mentor team members through the strategy directed by senior management. In addition to technical skills, the Services Manager is results-oriented and demonstrates effective problem-solving and communication skills.
A Day in the Life:
• Lead, mentor, and develop a team of Cybersecurity Analysts responsible for monitoring, triage, and incident response.
• Oversee daily SOC operations and ensure timely, effective handling of security alerts and requests.
• Automate repetitive tasks and implement process improvements to enhance efficiency.
• Maintain and update runbooks, SOPs, escalation workflows, and operational playbooks.
• Lead all security incident investigations, containment, and remediation activities.
• Conduct regular incident response exercises and postmortems, identifying root causes and tracking improvements.
• Stay current on emerging threats and assess ARCO's readiness to defend against them.
• Manage and optimize security tooling (SIEM, IDS/IPS, EDR, SIG, EPM, firewalls, threat intel platforms, etc.).
• Oversee vulnerability scanning, prioritization, and remediation with Infrastructure partners.
• Support patching, hardening, and secure configuration efforts across systems and networks.
• Guide engineering, deployment, and documentation of security tools.
• Support audits, evidence requests, and compliance requirements (NIST 800-171, CMMC, NIST CSF) in partnership with GRC.
• Develop metrics and dashboards that measure organizational risk and SOC performance.
• Communicate security risks and incident updates to leadership in clear business terms.
• Ensure required security awareness training and phishing simulations are delivered effectively.
• Participate in change management, project reviews, and technology planning discussions.
• Collaborate with Technology teams to identify security gaps and strengthen overall posture.
Necessary Qualifications:
• 7-10 years of cybersecurity operations/engineering experience, including monitoring and incident response.
• Experience leading people, developing talent, and managing high-performing teams.
• Hands-on experience with core security technologies (SIEM, IDS/IPS, EDR, SIG, EPM, firewalls, vulnerability management, threat intel, SOAR).
• Strong communication skills with the ability to translate technical issues into business risk.
• Proven ability to drive measurable improvements in SOC performance.
• Strong organizational skills with the ability to prioritize and delegate.
• Experience with Azure or AWS environments.
• Familiarity with industry frameworks (NIST 800-171, CMMC, NIST CSF).
• Preferred certifications: CISSP, CISM, SANS/GIAC, CySA+, or similar.
• Must be a U.S. Citizen.
• Travel: Up to 10%
What We Can Offer You:
• Industry-leading performance-based bonus program
• 100% company funded retirement contributions
• Traditional and Roth 401k
• Tuition reimbursement for associates
• Scholarship for associates' children up to $28,000 per child
• 1-month paid sabbatical after every five years of employment, plus $5,000 for travel
• 1-week paid volunteer leave each year
• 100% charitable match
• Medical, dental, and vision insurance coverage
• 100% paid 12-week maternity leave