Security Operations Manager
EmpiRx Health · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time
Key Responsibilities
- Lead and oversee 24x7 SOC operations, including internal teams and/or managed security partners.
- Own threat detection, triage, investigation, and response processes.
- Drive improvements in mean time to detect (MTTD), mean time to respond (MTTR), and incident response maturity.
- Define and operationalize SIEM/SOAR use cases, playbooks, and automation.
- Ensure effective monitoring across endpoints, cloud, identity, and network layers.
- Capture incident response with internal teams, legal, compliance, and external partners.
- Lead post-incident reviews and continuous improvement programs.
- Develop SOC metrics, dashboards, and executive reporting.
Identity and Access Management (IAM)
- Own the enterprise IAM program, including identity lifecycle processes for joiners, movers, and leavers.
- Drive role-based access control (RBAC) and least-privilege enforcement.
- Implement and manage Privileged Access Management (PAM/PIM).
- Oversee MFA, SSO, conditional access, and authentication standards.
- Lead access governance, certification campaigns, and audit readiness.
- Reduce manual processes through automation and workflow integration, including tools such as ServiceNow.
- Ensure compliance with SOC 2, HIPAA, and regulatory access requirements.
- Partner with application, infrastructure, and business teams on secure access design.
Leadership and Strategy
- Lead, mentor, and develop security analysts.
- Define the roadmap for SOC and IAM maturity aligned to NIST CSF and Zero Trust principles.
- Partner with IT, Engineering, Compliance, and business stakeholders.
- Translate technical risks into business impact and decision-ready insights.
- Manage vendors, including SOC providers, IAM platforms, and security tools.
Required Qualifications & Experience
- 5–7+ years of cybersecurity experience, including leadership experience.
- Strong hands-on expertise in SOC operations, including SIEM, EDR, threat detection, threat hunting and incident response.
- Strong hands-on expertise in IAM, including RBAC, SSO, MFA, PAM/PIM, and lifecycle automation.
- Experience with cloud security; Azure and Microsoft ecosystem experience strongly preferred.
- Knowledge of security frameworks and requirements, including NIST CSF, SOC 2, and HIPAA.
- Proven experience managing incident response and access governance programs.
Preferred Qualifications
- Certifications such as CISSP, CISM, CRISC, or equivalent.
- Experience managing managed SOC, MDR, or MXDR providers.
- Exposure to Zero Trust and identity-first security models.
- Experience in healthcare or other regulated environments.