SOC Manager

United Data Technologies

$110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field; master's preferred.
  • 7+ years in security operations with 3+ years in SOC leadership or management.
  • Experience managing SOC teams in a fast-paced, multi-client environment.
  • Familiarity with managed SIEM and EDR models is preferred.
  • Manager-level security certifications (CISSP or CISM) are strongly preferred.

Responsibilities

  • Lead daily operations of a 24x7 SOC for effective threat monitoring and response.
  • Supervise and mentor SOC team members, ensuring accountability and growth.
  • Own and maintain escalation protocols within the SOC chain of command.
  • Refine incident-response playbooks and ensure SOP adherence.
  • Oversee incident management including detection, triage, and containment.

Benefits

  • Medical, dental, vision, life and disability coverage effective from the 1st of the month.
  • Health savings and flexible savings accounts for added financial support.
  • 401(k) plan with company match to assist in retirement savings.
  • 7 annual holidays plus unlimited paid time off options for work-life balance.
  • Inclusive and collaborative work environment fostering personal and professional growth.
Full Job Description
This position is hybrid, located in Miramar, FL

SOC Manager

The SOC (Security Operations Center) Manager is responsible for the strategic and day-to-day operational management of UDT's 24x7x365 SOC, ensuring effective monitoring, detection, investigation, and response to cyber threats across client and internal environments. The SOC Manager leads a team of SOC Supervisors, Analysts (Levels 1, 2, and 3), and dispatchers, providing the leadership, structure, and process discipline required to maintain a reliable and continuously improving managed-security operation.

This role holds operational ownership of UDT's managed detection and response (MxDR) delivery. It sits between the per-account Service Delivery Managers (SDMs) and senior leadership within the escalation chain, and is accountable for ensuring that SOC operations run on documented playbooks and defined on-call rotations rather than on individual knowledge or availability.

The SOC Manager collaborates closely with UDT's Help Desk; Governance, Risk and Compliance (GRC) Team; Professional Services Cyber Security Team, which commands major-incident response; the NOC, which executes infrastructure containment; and UDT's delivery partners and SIEM/SOAR platform providers, ensuring all security operations align with client SLAs, contractual obligations, and regulatory requirements.

UDT is seeking an experienced, hands-on security operations leader to assume operational ownership of the SOC. The successful candidate will demonstrate:
  • Direct technical engagement. Comfortable working within the toolset (Huntress, Google Chronicle, CrowdStrike, ConnectWise) - producing reports, extracting metrics, and authoring playbooks personally. This is a working management position rather than a purely supervisory one.
  • The ability to operate independently. A record of taking ownership of an objective and executing it with limited day-to-day direction.
  • An improvement orientation. Experience assessing an established operation objectively, applying industry best practices, and strengthening operational discipline.
  • Customer-facing composure. Skill in conflict resolution and in conducting client conversations with professionalism and credibility.
  • Audience-appropriate communication. Able to engage in technical depth with analysts, engineers, and partners, and to present the same material to executive and client audiences in business terms. Strong written and verbal English is required, including the ability to independently produce clear, professional correspondence and reports.

Responsibilities:

SOC Operations Management:
  • Lead and manage the daily operations of the 24x7x365 SOC, ensuring timely detection, triage, investigation, and response to security events across all delivery paths.
  • Supervise and develop the SOC team - Supervisors, Analysts (Levels 1, 2, and 3), and the dispatcher pool - providing direction, coaching, and accountability.
  • Own the escalation matrix and serve as the standing intermediate tier within the UDT escalation chain (SDM to SOC Manager to senior leadership), ensuring escalations follow a defined path.
  • Maintain and refine incident-response playbooks, standard operating procedures (SOPs), runbooks, and escalation protocols so that response procedures are documented, repeatable, and independent of any individual.
  • Ensure the SOC operates in accordance with UDT security policies, contractual scope, and client SLAs.

Coverage, Shift Discipline, and On-Call:
  • Establish and own a defined, rotating, documented on-call tier so that after-hours and weekend escalation follows a published rotation.
  • Establish a formal shift-handoff process at each shift overlap - a structured written and verbal pass of open incidents, watch items, pending customer callbacks, and in-flight investigations, logged in ConnectWise - to maintain continuity across the shift overlaps (Shifts 1, 2, and 3) and at the UDT-partner boundary.
  • Define and enforce after-hours coverage standards, ensuring overnight and dispatcher coverage follows documented response procedures rather than automated notification alone.

Incident Detection and Response:
    • Oversee all phases of incident management - detection, triage, investigation, containment, and post-incident review - across UDT's detection stack:
    • Huntress (Managed EDR/MDR/ITDR - Ransomware Canaries, Persistent Footholds)
    • Google Chronicle (SIEM, SOAR, and threat-intelligence plane)
    • CrowdStrike (alternate endpoint MDR engine), Microsoft Defender (managed endpoint telemetry), Datto SIRIS (backup and disaster recovery), and KnowBe4 (security awareness)
  • Act as the senior point of escalation for high-severity incidents, coordinating the SOC, NOC, PS Cyber, the customer, and, where engaged, legal and executive leadership.
  • Operate within UDT's defined control boundaries:
  • Infrastructure containment follows a SOC-to-NOC handoff - the SOC raises the ticket and the NOC executes - managed to avoid delay at the handoff.
  • Major-incident response command resides with PS Cyber. The SOC detects, confirms true-positive status and indicators of compromise, and provides support.
  • Support the adoption of pre-authorized emergency incident-response authorization so that containment of a confirmed breach is not delayed pending contractual approval.
  • Ensure breach-notification requirements - for example, contractual 24-hour written notification for regulated accounts - are tracked and met, escalating legal determinations to counsel.

Partner and Vendor Operational Governance:
  • Assume operational ownership of UDT's co-delivery and managed-SIEM partner relationships, including participation in partner quarterly business reviews with a UDT-maintained coverage, escalation, miss-rate, and SLA scorecard, and governance of the UDT-partner handoff.
  • Manage the operational fit of SOC subcontractors and partners with respect to coverage, shift, and escalation. Cost decisions route to Finance.
  • Evaluate detection and response tooling for operational effectiveness and recommend stack changes to SecOps.

Detection Coverage and Tuning Quality:
  • Build and maintain a single, UDT-owned, validated MITRE ATT&CK coverage baseline spanning the Huntress and Chronicle paths, including customer-tenant Sentinel, mapped to ingested log sources, with gaps ranked and tracked.
  • Maintain a detection-tuning and false-positive backlog feeding the SIEM/SOAR platform and governing tool-direct alert volume. Detection quality is addressed through tuning; alert suppression is not an acceptable substitute.
  • Partner with the SIEM/SOAR platform's detection-engineering function - parser and UDM mapping, use-case authoring, and detection scoring - so that UDT's coverage view consumes those outputs rather than duplicating them.

SLAs, Metrics, and Reporting:
  • Maintain outcome-based SLAs and SLOs. MTTA, MTTD, and MTTR are measured against the defined, severity-based classification-completion clock, including the 60-day Service Alignment Phase and documented pause states.
  • Own the monthly Customer Service Review (CSR) and quarterly business review (QBR) cadence: coverage assessment, MITRE use-case coverage, alert breakdown, and gap reporting via UDT HUB, ARMED, and Smart Analytics.
  • Report metrics that accurately reflect risk reduction and response performance, including known gaps.

Team Development and Mentorship:
  • Provide leadership, mentorship, and career development for the SOC team; conduct performance reviews and identify training and certification paths.
  • Partner with Human Resources on role standards and professional development plans to build out the Level 1 to Level 2 to Level 3 analyst progression and senior-bench depth. Indicative certification path: Security+, CrowdStrike Falcon, BTL1, MITRE ATT&CK, and CySA+, advancing toward CISSP, CISM, or GCIH for senior roles.

Compliance and Stakeholder Engagement:
  • Ensure SOC activities align with applicable frameworks and regulations across the client base, including NIST, ISO 27001, CIS, MITRE ATT&CK, HIPAA, PCI-DSS, and GLBA for regulated accounts, and others as contracted.
  • Serve as a primary SOC point of contact for senior leadership and clients regarding SOC performance, the threat landscape, and incidents.

Other:
  • Enter time and all work - activities, service tickets, and project tickets - into the ConnectWise Manage PSA as it occurs.
  • This position is based at UDT's headquarters in Miramar, FL and follows a hybrid schedule; occasional travel to customer sites may be required.
  • Other duties related to the scope of the department and the business may be assigned.

Education and Experience:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field; master's degree preferred.
  • Seven or more years in security operations, including at least three years in a SOC leadership or management role.
  • Demonstrated experience managing SOC teams and directing high-severity incidents in a fast-paced, multi-client MSSP or MSP environment.
  • Experience operating a co-delivery or partner-fronted MDR model (managed SIEM and EDR delivered through partners) is strongly preferred.

Technical Skills:
  • Working fluency with a modern MDR stack: EDR and MDR platforms (Huntress, CrowdStrike, Microsoft Defender); SIEM and SOAR platforms (Google Chronicle, or comparable platforms such as Microsoft Sentinel or Splunk); and ticketing and PSA-driven escalation. Familiarity with ConnectWise Manage is a strong plus.
  • Strong command of incident management, threat intelligence, forensic fundamentals, and vulnerability-management processes.
  • Working knowledge of MITRE ATT&CK as a coverage-design and validation discipline.
  • Understanding of cybersecurity frameworks and regulatory regimes, including NIST, ISO 27001, HIPAA, PCI-DSS, and GLBA.

Certifications:
  • Manager-level security certification required or strongly preferred: CISSP or CISM.
  • Governance, risk, and audit credentials, one or more strongly preferred: CISA or CRISC.
  • Hands-on detection and incident-response credentials, one or more a plus: GCIH, GCIA, GIAC, or CEH.
  • Baseline expected: CompTIA Security+ or CySA+.
  • Operational excellence, a plus: ITIL Foundation and a process-improvement credential such as Lean Six Sigma (Green Belt or above).

Soft Skills:
  • Strong leadership and team-building skills, with the ability to motivate and develop a diverse, multi-tier SOC team.
  • Sound judgment under pressure during high-severity incidents.
  • Clear communication of complex technical matters to technical, non-technical, executive, and client audiences.
  • Strong organizational and prioritization skills in a 24x7, multi-client environment.

Required Knowledge, Skills, and Abilities:
  • Cross-functional leadership, with the ability to lead and achieve results with a strong customer orientation.
  • Strategic planning across a 6- to 12-month horizon, with the discipline to operationalize the plan.
  • Excellent written and verbal communication, including the ability to translate technical issues into business terms.
  • Self-directed, results-driven, detail-oriented, and accurate, with the ability to manage multiple priorities concurrently.
  • Proficiency with Microsoft Office and the ability to develop reports, recommendations, and executive and client presentations.

What UDT offers you

We offer a competitive compensation package where you'll be rewarded based on your performance and recognized for the value you bring to the organization. UDT's Total Rewards package includes medical, dental, vision, life and disability coverage as of the 1st of the month, health savings accounts, flexible savings accounts, 401(k) plan with company match, 7 annual holidays and unlimited paid time off options.

Join us and be part of an inclusive, energizing, and collaborative environment.

Similar Jobs

More Jobs at United Data Technologies

  • SOC Manager
    $110K — $130K *
    Miramar Beach, FL 32550 (Walton County)
    Information Technology
    In-Person
  • Service Desk Manager
    $75K — $95K *
    Miramar Beach, FL 32550 (Walton County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar SOC Manager jobs: