Manager, Security Operations & Incident Response
When you work at Trex, you’re helping to grow and enhance a true original. You join a company that boldly launched an entire industry and still leads the way.
About the role
We are looking for a Manager, Security Operations & Incident Response to support our team by leading Trex’s day-to-day security operations, incident response program, managed security service partnerships, and operational governance of the endpoint, cloud, email, vulnerability management, and detection platforms. This role provides centralized leadership and accountability for security operations, ensuring that alert triage, incident response, vulnerability remediation, threat detection, and managed service performance are coordinated, measurable, and aligned with business risk.
Responsibilities
- Security Operations Management
- Lead 24x7 security operations delivered through the managed service model, including alert triage governance, escalation procedures, response expectations, service quality, and performance measurement against contractual SLAs.
- Provide oversight of the SOC operating model, ensuring internal teams, offshore resources, and managed service providers have clearly defined responsibilities, documented processes, and measurable outcomes.
- Direct the detection engineering roadmap across managed endpoint detection and response, cloud-native security information and event management, and extended detection and response platforms, ensuring detection content reflects Trex’s manufacturing environment, threat model, and technology architecture.
- Partner with cybersecurity, infrastructure, networking, endpoint, OT, and application teams to ensure security operations are integrated into broader IT service delivery and business operations.
- Incident Response
- Own the end-to-end incident response lifecycle, including preparation, detection, containment, eradication, recovery, lessons learned, and post-incident improvement activities.
- Lead executive-facing communications during high-severity security events, ensuring clear, timely, and business-appropriate updates are provided to leadership and key stakeholders.
- Maintain the on-call rotation, escalation model, and quarterly tabletop exercise cadence, including executive-level tabletop exercises with Legal, Finance, Communications, and other business stakeholders.
- Ensure Trex maintains readiness for SEC 4-day 8-K cyber incident reporting, including materiality determination workflows, coordination with Legal, Finance/CFO, Investor Relations, and post-incident disclosure preparation.
- Vulnerability Management and Platform Operations
- Own the vulnerability management program, including enterprise vulnerability scanning strategy, remediation governance, SLA tracking, exception handling, and coordination with IT Platforms, Servers, and application owners.
- Lead the application control and allowlisting deployment and tuning program in partnership with IT Platforms and End User Computing, including business change management, allowlisting governance, and false-positive resolution.
- Oversee operational security capabilities across secure web gateway, email security, endpoint detection and response, extended detection and response, security information and event management, vulnerability management, application control, and related security platforms.
- Support Zero Trust and secure access initiatives, including zero trust network access rollout, legacy remote access VPN decommission planning, and conditional access integration in environments using a third-party primary endpoint detection and response platform.
- Vendor and Managed Service Management
- Manage managed security service provider and managed detection and response vendor relationships, including service transitions, ongoing service governance, SLA management, escalation handling, and vendor performance reviews.
- Coordinate with internal stakeholders and vendors to ensure security platforms, managed services, and incident response retainers are aligned to Trex’s operational requirements and risk profile.
- Lead structured knowledge transfer of platform ownership from in-house senior staff to offshore managed service resources, including acceptance criteria, documentation, service expectations, and quarterly review milestones.
- Business Partnership and Compliance Support
- Work closely with IT Platforms and Servers, Engineering, Legal, Internal Audit, End User Computing, and other business partners on shared workstreams including segmentation, network access control modernization, conditional access, OT/ICS security, and security operations maturity.
- Support M&A cyber due diligence and post-close integration activities in partnership with the Security Architect and other IT leaders.
- Contribute to Trex’s NIST CSF maturity targets and help align security operations practices with NIST CSF, NIST 800-53, CIS Critical Security Controls, SOX ITGC expectations, and cybersecurity disclosure obligations.
- Leadership and Team Development
- Manage and develop a hybrid team of in-house and offshore security resources responsible for incident response, vulnerability management, cloud security, email security, platform operations, and managed SOC coordination.
- Provide coaching, prioritization, performance direction, and operational guidance to ensure the team can support current-state operations while maturing Trex’s security operations capability.
- Establish clear operating procedures, documentation expectations, accountability models, and review cadences to ensure work is repeatable, measurable, and sustainable as Trex scales.
Requirements
- Bachelor’s degree in computer science, Information Systems, Cybersecurity, or a related field, or equivalent combination of education and professional work experience.
- 7-10 years of progressive information security experience, including at least three years of direct people leadership in security operations, incident response, SOC management, or a closely related function.
Skills
- Demonstrated experience leading incident response for a mid-size or enterprise organization, including communication with executives and business stakeholders during high-severity events.
- Hands-on experience or strong operational oversight of a primary enterprise endpoint detection and response platform, with working knowledge of an extended detection and response or telemetry correlation platform operating alongside a third-party primary endpoint detection and response solution.
- Working experience with cloud-native security information and event management for correlation, detection engineering, and query-based analysis.
- Experience managing MSSP, MDR, or SOC service provider relationships, including SLA governance, transition planning, escalation management, and performance measurement.
- Experience working in a publicly traded, SOX-scoped, or audit-sensitive environment, with familiarity with cyber-related SEC disclosure expectations.
- One or more relevant professional certifications, or equivalent experience, such as CISSP, GCIH, GCIA, GCFA, or CISM.
Pay
Base Salary Range: $140,000-$175,000 annually. The salary range provided serves as a general guideline for potential compensation for this position. It reflects the base salary and does not account for other benefits or additional compensation opportunities that may apply. This role is also eligible for further compensation through an annual/sales bonus, in addition to the base salary. Individual base salaries are determined based on various factors, including relevant skills, qualifications, experience, and geographic location.
Benefits
- Time Off: Paid holidays and paid vacation.
- Health, Dental and Vision Insurance: Choose from a variety of options. Trex covers a generous share of the cost. Plus, you can earn lower rates through the wellness program.
- 401(k) With Company Match: Save for your retirement and Trex will match it dollar for dollar.
- Tuition Reimbursement: When you’re ready to get the degree, Trex will pick up part of the tab.
- Training and Education: Dozens of options to boost your performance – both online and on-site nearby.
- Stock Purchase Program: Invest in Trex at a discounted price.
- Employee Discount Program: Discount on Trex products.
- Career Advancement: Ongoing opportunities to grow your expertise and enhance your career.
About Trex
Over 30 years ago, our founders created the world's first high-performance, low-maintenance composite decking and outdoor living products. Today, Trex is the world’s #1 brand of sustainably made, wood-alternative decking and deck railing – all proudly manufactured in the U.S.A. As a publicly traded company [NYSE: TREX], Trex takes pride in being the largest recycler of plastic film in the country and caring for the communities and the planet where we live. We nurture meaningful connections, from local engagement and investment to eco-friendly products and sustainable manufacturing processes. At Trex, you’ll become part of a diverse yet unified team who sustain the trailblazing spirit and strengths that made Trex the industry leader—learning, adapting, solving, and succeeding.