Job Summary The
Security Operations Center (SOC) Manager is a full-time leadership role responsible for building and leading a proactive, engineering-driven, and highly automated SOC that integrates threat hunting, detection engineering, threat intelligence, vulnerability management, cloud security, incident response, people leadership, security platforms, and managed detection and response services.
You will need to reside within 50 miles of our Corporate Headquarters in Scottsdale, AZ as this role has the option of hybrid or onsite. Duties and Responsibilities - Lead the transformation to an Agentic SOC by advancing automation, threat hunting, detection engineering, and threat intelligence; designing automated response workflows; and reducing repetitive analyst work and manual alert processing.
- Establish and mature a proactive threat hunting program to identify hidden and emerging threats, including telecom-sector threats targeting Consumer Cellular.
- Lead detection engineering to tune detections, identify coverage gaps, and create Consumer Cellular-specific detection rules
- Direct the production of telecom-focused threat intelligence reporting to inform detection, hunting, and response priorities
- Oversee SOC security platforms and integrations, including ReliaQuest GreyMatter, Upwind CNAPP, and Rapid7 InsightVM, to provide unified visibility across cloud, vulnerability, and detection data; manage the MDR partner against defined service levels and outcomes.
- Manage daily SOC operations by monitoring alert and ticket queues, assessing scope, urgency, impact, and vulnerabilities, maintaining awareness of major incidents, ensuring effective shift handoffs, resolving operational issues, and driving timely incident detection, response, and resolution.
- Hire, train, coach, and evaluate SOC staff; manage scheduling, onboarding, and professional development; and build the competencies needed to anticipate, manage, and mitigate security risk.
- Build internal engineering capability and retrain existing SOC personnel into automation-focused security engineers, reducing reliance on managed service providers.
- Maintain sufficient operational and engineering knowledge across supported security solutions and platforms to guide decisions, evaluate technical work, and provide effective leadership during incidents.
- Establish and maintain SOC operating procedures, strengthen post-incident feedback loops with the Incident Response team, and continuously improve detection and operational processes through lessons learned, innovation, and change.
- Establish a unified SOC operating model that connects vulnerability management, cloud security, detection engineering, and incident response; integrates alert sources; defines operational metrics; and provides quarterly security operations reporting to senior management.
- Develop and maintain crisis communication plans that support timely, transparent, and appropriately targeted notifications during security incidents.