Jobs · OTHR

MDR Manager

Guardz · Miami, FL · Yesterday
RemoteRemoteOTHR$85/hrFull-time

About the role

Guardz, established in 2022, is a rapidly growing cybersecurity company with $85M in funding and a team of 120 professionals. We aim to create a safer digital environment for small and medium businesses worldwide through our comprehensive all-in-one platform. As an MDR Manager, you will lead our Security Operations team, combining technical expertise with operational leadership to develop analysts, improve processes, and manage complex security incidents in multi-tenant MSP environments.

Responsibilities

  • Own 24/7 shift coverage, tiering, and escalation paths to ensure every alert reaches the right analyst without gaps in monitoring or escalation.
  • Participate in an on-call rotation with the team.
  • Manage response SLAs (time-to-triage, time-to-notify, MTTR) and report SOC KPIs (MTTD, MTTR, detection efficacy, false-positive rate, case aging, customer satisfaction) to leadership.
  • Run QA on closed alerts and incidents, drive down false positives, and maintain the team's runbooks, playbooks, and SOC standards.
  • Lead, coach, and mentor MDR Analysts through regular 1:1s, performance feedback, onboarding, and the T1-to-T3 training path. Conduct tabletop exercises and post-incident reviews.
  • Act as technical lead and final escalation point for T3 incidents (advanced malware, identity threats like MFA fatigue and token theft, active breaches), leading the full lifecycle with defensible documentation.
  • Correlate alerts across EDR (SentinelOne, Defender for Endpoint), ITDR (M365, Google Workspace), and email security, and run proactive threat hunts aligned to MITRE ATT&CK.
  • Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed.
  • Partner with MSPs on major incidents and posture reviews, and feed findings back into detection with product, threat research, and engineering teams.

Requirements

  • 5+ years in SOC, MDR, or Incident Response handling complex attacks, including 2+ years as a Team Lead, Shift Lead, or senior analyst.
  • Hands-on expertise with EDR (SentinelOne, CrowdStrike, Defender for Endpoint) and ITDR (identity threat management across M365 and Google Workspace).
  • Hands-on experience with Google BigQuery, Snowflake, Splunk, Elastic, or equivalent, and fluency in a query language such as SQL, KQL, or SPL.
  • Experience with MITRE ATT&CK-aligned detection, proactive threat hunting, and AI-driven triage engines, automated playbooks, or agentic SecOps platforms.
  • Excellent communication skills, able to make high-risk technical findings clear to both technical and non-technical audiences.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience.

Qualifications

  • Preferred certifications: CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH / GCIA / GCFA, or CISSP (or equivalent DoD 8570 / 8140 IAT Level II).

Similar jobs

MDU manager

CI Services, a UniTek Global Services CompanyMyrtle Beach, SC· 6 days ago
OTHRapply on myjobs.adp.com