OnTrac

Senior Manager of IT & Cyber Security

OnTrac$156K — $234K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field
  • 10+ years of progressive cybersecurity experience
  • 5+ years of leadership experience managing Security Operations or SOC teams
  • Experience developing cybersecurity operational metrics and performance dashboards
  • Proven success with SIEM, EDR, and automated response capabilities
  • Experience managing 24x7 staffing models and vendor relationships
  • Preferred certifications such as CISSP, CISM, and cloud security certifications

Responsibilities

  • Lead daily SOC monitoring, alert triage, and incident response
  • Ensure organizational workforce planning to meet security operations needs
  • Build and mature incident response procedures and documentation
  • Coordinate high-severity incident response across various leadership roles
  • Develop detection engineering and proactive threat-hunting programs
  • Establish and report on performance metrics and dashboards
  • Optimize security processes and implement automation and AI technologies

Benefits

  • Medical, dental, and vision insurance
  • Life and disability coverage
  • 401(k) with company match
  • Flex vacation and accruals based on tenure
  • Paid sick leave and holidays
  • Paid pregnancy and parental bonding leave
  • Wellness and employee assistance programs
Full Job Description
Location: Remote - This position may be performed remotely in states where the company is authorized to employ individuals.

Compensation: The expected starting base pay range for this position is $156,000 - $195,000, with full potential base salary range over a successful candidate's tenure in the position of $156,000 - $234,000. Actual compensation will be determined based on experience, skills, internal equity, and other job-related factors.

This position may also be eligible for bonus, commission, or other incentive compensation in accordance with the terms of the applicable plan of up to a 20% Bonus Target.

Employment Logistics:

The Senior Manager, CSIRT / Security Operations Center (SOC) leads and matures the organization's cyber defense capabilities through operational excellence in security monitoring, cyber incident response, crisis management, threat intelligence, threat hunting, detection engineering, security validation, cloud and identity security operations, and security automation. This role provides strategic and operational leadership for Security Operations personnel and oversees the people, processes, technologies, budget, vendor relationships, and performance measures required to effectively detect, analyze, contain, eradicate, recover from, and learn from cybersecurity threats. The Senior Manager also ensures sustainable 24x7 coverage while driving the responsible adoption of automation and AI-enabled security operations.

Unpacking the Benefits:

Employees are eligible for a comprehensive benefits package which may include:

  • Medical, dental, and vision insurance
  • Life and short- and long-term disability coverage
  • 401(k) retirement savings plan with company match
  • Flex vacation in states other than CA, CO, IL, MA, MT, and NE, with accruals up to 96 hours for first year of employment with tenure-based increases up to 160 hours
  • Two (2) floating holidays per year
  • Paid sick leave*
  • Six (6) paid company holidays
  • Two (2) weeks paid pregnancy disability leave, four (4) weeks paid parental bonding leave
  • Additional wellness and employee assistance programs


Benefits eligibility and offerings are subject to the terms and conditions of the applicable plans and company policies.

The Must-Haves:
  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field
  • Master's degree preferred, but not required
  • 10+ years of progressive cybersecurity experience
  • 5+ years of leadership experience managing Security Operations, Incident Response, Cyber Defense, or SOC teams
  • Demonstrated experience building and maturing SOC capabilities, incident response programs, and detection engineering functions
  • Experience developing cybersecurity operational metrics, executive reporting, and performance dashboards, including MTTD, MTTR, KPIs, and KRIs
  • Proven success implementing SIEM, EDR, SOAR, and automated or AI-assisted response capabilities
  • Experience managing 24x7 staffing models, budgets, and third-party security vendors or MSSPs
  • Preferred certifications include CISSP, CISM, GIAC GCIH, GIAC GCIA, and GMON
  • Cloud security certifications such as Azure Security Engineer Associate or Microsoft Cybersecurity Architect Expert preferred
  • It is the responsibility of every position to understand and adhere to the security guidelines outlined in OnTrac's Acceptable Use policy and to conduct their activities accordingly.


Your Mission in Motion:

A summary of key responsibilities for the role is outlined below. Additional duties may be assigned as needed to support business objectives.
  • SOC leadership, structure & coverage: Lead daily SOC/ARC monitoring, alert triage, investigations, and incident response; manage analysts, shift leads, and incident handlers across all tiers; define Tier 1/2/3 responsibilities and escalation criteria; and establish a sustainable coverage model using follow-the-sun, dedicated shifts, or hybrid on-call rotations.
  • Workforce planning & operational readiness: Ensure qualified staffing and service coverage while developing organizational and workforce plans that support current and future security operations requirements.
  • Incident response & crisis management: Build and mature incident response procedures, runbooks, and playbooks; lead cyber incident response end-to-end; coordinate countermeasures and mitigating controls; and serve as the primary escalation point for complex investigations and significant incidents.
  • Incident communication, exercises & lessons learned: Coordinate high-severity incident response across IT, Legal, Communications/PR, and executive leadership; conduct post-incident reviews; lead technical and executive tabletop exercises, cyber simulations, and readiness drills; and track corrective, preventive, and remediation actions to closure.
  • Detection engineering, threat hunting & monitoring effectiveness: Develop the detection engineering and proactive threat-hunting programs; perform quality control of detection and alerting mechanisms; tune SIEM, EDR, and other security technologies to improve efficacy and reduce false positives; and align detection use cases with MITRE ATT&CK, threat intelligence, emerging threats, and organizational risks.
  • Metrics, dashboards & performance management: Establish and report MTTD, MTTR, MTTC, detection coverage, alert fidelity, incident volume, severity trends, and analyst productivity; create SOC/ARC KPIs and KRIs; and develop executive dashboards that communicate threat trends, operational performance, and program maturity.
  • Automation, AI & continuous improvement: Optimize security tools, processes, and SIEM/SOAR platforms to reduce analyst fatigue and accelerate response; implement AI/ML-supported triage, correlation, and investigation capabilities; define the appropriate division between automated action and human judgment; and monitor emerging agentic AI and autonomous response technologies.
  • Governance, risk & compliance: Align security operations and incident handling with applicable regulatory requirements and frameworks, including NIST CSF, NIST SP 800-61, MITRE ATT&CK, CIS Controls, ISO 27001, PCI-DSS, SOX, and HIPAA, and support related audits, assessments, and evidence-collection activities.
  • Budget, vendors & service performance: Manage the SOC operating budget across tools, staffing, and managed services; oversee MSSPs, MDR providers, incident response retainers, and security technology partners; and define and enforce vendor and contract SLAs.
  • Talent development & security culture: Recruit, coach, mentor, and develop security operations personnel at all levels; establish career paths, training programs, skills assessments, and succession plans; and foster accountability, collaboration, innovation, continuous learning, and high performance.


Paving your way to your success:

  • You lead the strategy and execution of major cybersecurity projects that affect multiple areas of the organization.
  • You set operational objectives, policies, procedures, and work plans while delegating responsibilities effectively across the team.
  • You develop, adapt, and implement policies that strengthen immediate security operations and may influence the broader organization.
  • You engage effectively with frontline and senior management on issues spanning multiple functions, departments, and customers.
  • You use strong persuasion and sound judgment to navigate sensitive, complex situations while maintaining productive relationships.


Posting Timeline:

This job posting is anticipated to remain open for at least 15 days from the date of posting

Disclosures:

*Washington state employees are eligible for up to 56 hours of paid sick leave annually.

The salary range above represents the national range for this position. The salary range may be inclusive of several career levels at OnTrac, and the actual base salary offered may vary depending on several factors including, but not limited to: Geographic location, candidate experience and qualifications, job-related skills and competencies, market alignment, and financial considerations.

Compensation decisions are made based on the specific circumstances of each hire to ensure fair and competitive pay.

If you are excited to be part of our team and grow with our OnTrac family, we invite you to apply!

About OnTrac

OnTrac is a courier and delivery service that specializes in overnight and time-critical deliveries. The company was founded in 1991 and has since grown to become one of the largest regional package delivery companies in the United States. OnTrac offers a range of services, including same-day delivery, next-day delivery, and two-day delivery, and serves customers in Arizona, California, Nevada, Oregon, Utah, and Washington. The company is committed to providing its customers with fast, reliable, and cost-effective delivery solutions, and has built a reputation for excellence in the industry.
Learn more about OnTrac
Size
3,000 employees
Industry

Similar Jobs

More Jobs at OnTrac

More Information Technology Jobs

Find similar Senior Manager of IT & Cyber Security jobs: