Senior Manager - Cybersecurity Operations

Castelion Corporation

$120K — $160K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in cybersecurity with emphasis on defensive operations
  • 2+ years in a leadership role
  • Proven experience in defense or critical infrastructure sectors
  • Experience with regulated environments like DoD and NIST
  • Expertise in threat hunting and incident response
  • Hands-on with enterprise security tools like SIEM and EDR
  • Strong scripting abilities in Python, PowerShell, or Bash

Responsibilities

  • Contribute to the evolution of SOC for effective threat management
  • Direct and lead proactive threat hunting operations
  • Oversee incident response for security-related events
  • Create and uphold defensive playbooks and operational procedures
  • Collaborate to validate and strengthen defensive measures
  • Implement defense-in-depth strategies conforming to industry standards
  • Evaluate and integrate advanced security technologies

Benefits

  • Long-term equity sharing in company growth
  • Four weeks of paid time off and ten paid holidays
  • 100% employee-covered health insurance with strong family options
  • Paid parental leave to support family needs
  • Monthly fitness stipend to encourage physical health
  • Onsite EV charging for employee convenience
  • Catered meals and fully stocked kitchen for employee satisfaction
Full Job Description
About the job Senior Manager - Cybersecurity Operations

Senior Manager - Cybersecurity Operations

We are seeking an experienced Senior Manager - Cybersecurity Operations to join our cybersecurity operations team at Castelion. This critical role will lead defensive security operations, incident response, and threat monitoring, protecting our information systems, intellectual property, product development security, and critical infrastructure from common threat vectors as well as advanced persistent threats (APTs) and nation-state actors.

The ideal candidate will envision security to remain a business enabler and not a blocker, have deep expertise in defensive security operations, SOC leadership, proactive threat hunting, SIEM & SOAR, and incident response within highly regulated environments. Brings a practical, and up-to-date relevant technical understanding of protocols, encryption levels, patch levels, policy & procedure, etc., that are secure in the modern cybersecurity landscape.

Responsibilities:
  • Contribute to and mature our Security Operations Center (SOC) activities and ensure effective threat detection and response
  • Direct threat hunting operations to proactively identify and neutralize threats before impact
  • Lead incident response efforts for security events affecting all our information systems
  • Develop and maintain defensive playbooks, runbooks, and standard operating procedures
  • Coordinate with additional internal teams to conduct exercises that validate defensive posture
  • Design and implement defense-in-depth strategies aligned with NIST, DoD, and intelligence community frameworks
  • Evaluate and deploy advanced security technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms)
  • Create and maintain security architecture documentation and network defense diagrams
  • Contribute to security roadmap planning
  • Establish and maintain threat intelligence program aligned to aerospace and defense sector threats
  • Analyze threat actor tactics, techniques, and procedures (TTPs) using MITRE ATT&CK framework
  • Produce threat intelligence reports and briefings for technical and executive audiences
  • Collaborate with government agencies and industry partners on threat information sharing
  • Track emerging threats and vulnerabilities relevant to defense systems and aerospace technology
  • Contribute to compliance with NIST 800-171, CMMC, ITAR, DFARS, and other applicable regulations
  • Support security audits, assessments, accreditation activities, and regular penetration testing
  • Partner with IT operations, engineering, and program management teams on security initiatives
  • Coordinate with government customers and oversight bodies on security matters
  • Function as a primary stakeholder and subject matter expert for changes to cyber controls and policies

Required Qualifications:
  • 7+ years of hands-on experience in cybersecurity, with a focus in defensive operations
  • 2+ years in a leadership or team lead capacity
  • Proven experience operating in defense, aerospace, engineering, intelligence, government, or critical infrastructure sectors
  • Experience in regulated environments (DoD, CMMC, NIST 800-171, ISO 27001, etc.)
  • Demonstrated expertise in security monitoring, threat hunting, and incident response
  • Demonstrated understanding of advanced persistent threat (APT) tactics and techniques
  • Hands-on experience with enterprise security tools (SIEM, EDR, IDS/IPS, firewalls, proxies)
  • Expert knowledge of network protocols, security architecture, and system hardening
  • Expert proficiency as both a configurator and a consumer of security information and event management (SIEM) platforms
  • Strong understanding of Windows and Linux security and forensics
  • Experience with endpoint detection and response (EDR) solutions (CrowdStrike, Carbon Black, Defender, SentinelOne, etc.)
  • Proficiency with scripting and automation (Python, PowerShell, Bash)
  • Knowledge of cloud security (AWS, Azure, GovCloud)
  • Understanding of malware analysis, reverse engineering techniques, and penetration testing
  • Experience with threat intelligence platforms and indicator management
  • Deep understanding of security principles, threats, and frameworks (e.g., cyber kill chain, MITRE ATT&CK, NIST, CIS Controls).
  • Strong documentation, troubleshooting, and communication skills.
  • Ability to thrive in fast-paced, high-pressure environments with competing priorities.
  • Analytical mindset with strong problem-solving abilities
  • Commitment to staying current with evolving threat landscape

Preferred Qualifications:
  • Active Security+, CISSP, GIAC, GSOC, GCIA, GCIH, GCFA, CISA, CEH, or similar senior-level certifications
  • Eligibility to keep and maintain a U.S. security clearance.

What We're Looking For:
  • A proactive security professional who sees audits and compliance as opportunities to build better systems - not just check boxes.
  • A disciplined thinker who can balance security, business needs, and regulatory constraints.
  • A calm, solutions-oriented team member who leads by example during assessments, incidents, or high-pressure reviews.
  • A clear communicator who knows how to educate non-technical stakeholders without watering things down.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

Benefits And Perks

All full-time employees are granted meaningful long-term equity, sharing in the company's significant growth trajectory. We offer four (4) weeks of paid time off, ten (10) company-paid holidays, and comprehensive health benefits - including 100% employee-covered medical and strong dependent coverage, along with dental and vision plans. We also provide paid parental leave to support growing families, a $100 monthly fitness stipend to promote health and performance, and onsite EV charging for convenience. In addition, employees enjoy perks like catered meals, company-covered food during high-demand periods, and a fully stocked kitchen to stay fueled throughout the day.

Similar Jobs

More Jobs at Castelion Corporation

More Information Technology Jobs

Find similar Senior Manager - Cybersecurity Operations jobs: