
location_onI 95, Brooklyn, Jacksonville, Duval County, Florida, 32204, United States
The IT SOC Manager provides strategic and operational leadership to ensure rapid detection and response to cyber threats while continuously improving people, processes, and technology. This role is pivotal in partnering with the information security organization, IT, risk management, legal, privacy, and business leaders to protect the organization from evolving cyber risks.
Based in Jacksonville, Florida, you will lead a geographically distributed Security Operations Center (SOC) team, managing analysts across multiple shifts and regions. The position requires interaction with global teams and time zones, with participation in major incident response activities outside standard business hours as needed. Rare travel may be required to support team engagement or leadership meetings.
You will drive a culture of accountability, continuous improvement, and operational excellence within the SOC. Your day involves overseeing daily operations including monitoring, triage, investigation, containment, and remediation of security incidents. You will ensure consistent execution of response playbooks and coordinate cross-functional response efforts with DFIR, IT, legal, privacy, HR, and communications teams.
Beyond daily operations, you will evaluate emerging threats and translate intelligence into actionable detection strategies. You will define and track SOC KPIs, providing clear reporting to executive leadership on performance and risk posture. Additionally, you will develop a multiyear SOC maturity roadmap, participate in vendor evaluations, and support audits and tabletop exercises to maintain organizational resilience.
Work model: On-site
I 95, Brooklyn, Jacksonville, Duval County, Florida, 32204, United States
Jacksonville, Florida
Experience operating a SOC in a large, complex, or regulated enterprise environment. Relevant certifications such as CISSP, CISM, GCED, GCIH, or equivalent. Familiarity with cloud security operations (AWS, Azure, GCP). Experience managing globally distributed or follow the sun SOC models. Prior experience supporting executive level incident communications.
Skills: Siem, XDR, NDR, Threat Intelligence Platforms, Incident Response, Threat Detection, Cloud Security Operations, Aws, Azure, GCP.
Education: Bachelor's degree in Information Security, Computer Science, or related field, or equivalent practical experience.