Optimize Search Group

Security Operations Manager
Cyber Security
PlanoTexas Direct Hire Sep 9, 2026

Job Title: Manager, Security Operations
Location: Location: Hybrid – Plano, TX (onsite Tuesday - Thursday)
Duration: Direct Hire 

 

Position Summary

The Security Operations Manager will lead enterprise security monitoring, incident response, and security operations processes while helping drive the strategic and technical direction of the organization's cybersecurity program.

This is a hands-on technical management role responsible for day-to-day security operations, incident response, security monitoring, third-party security services, and employee security awareness initiatives.

The Security Operations Manager will serve as a key member of the cybersecurity leadership team and will work closely with infrastructure, cloud, application, IT, risk, and business stakeholders to strengthen the organization's ability to detect, respond to, and recover from cybersecurity threats.

Key Responsibilities

  • Serve as the primary incident commander for significant cybersecurity events, ensuring structured response and recovery in accordance with established incident response frameworks and organizational playbooks.

  • Manage the cybersecurity incident lifecycle, including communications, stakeholder coordination, forensic support, remediation oversight, and post-incident review.

  • Lead post-incident lessons-learned activities to identify control gaps, process improvements, and opportunities to strengthen security defenses.

  • Partner with technology and business teams to ensure timely remediation and improve security detection and response coverage.

  • Maintain and continuously improve incident response playbooks and procedures across a range of potential threat scenarios.

  • Manage relationships with external managed security service providers and security partners, ensuring appropriate service levels, escalation procedures, performance expectations, and reporting.

  • Monitor and evaluate third-party security operations performance, including detection quality, false-positive rates, escalation effectiveness, and response times.

  • Ensure appropriate visibility into enterprise security telemetry, detection capabilities, alerting, and response mechanisms.

  • Collaborate with security service providers to prioritize improvements in threat detection and adversary technique coverage.

  • Partner with internal and external security teams to coordinate threat hunting, threat intelligence integration, detection engineering, and response automation.

  • Lead the organization's Cybersecurity Awareness and Training Program, including enterprise training, targeted security education, and recurring awareness campaigns.

  • Design and manage phishing simulation exercises to measure employee security awareness and improve security behaviors.

  • Develop operational metrics and reporting to communicate security operations performance, incident trends, response effectiveness, and areas of risk to cybersecurity leadership.

  • Identify opportunities to improve security monitoring, incident response processes, automation, and operational efficiency.

  • Partner with cybersecurity leadership to support the ongoing development and maturity of the organization's security operations program.

Required Skills & Experience

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent professional experience.

  • 7+ years of cybersecurity experience, including at least 2 years leading a security operations, incident response, or related cybersecurity function.

  • Demonstrated experience coordinating with external security service providers, including MDR, MSSP, managed detection, or incident response vendors.

  • Strong working knowledge of security detection, incident response, monitoring, and automation concepts across cloud and hybrid environments.

  • Experience managing enterprise security awareness and phishing simulation programs.

  • Strong incident management, communication, problem-solving, and cross-functional leadership skills.

  • Ability to translate technical security events and risks into clear business communications and actionable recommendations.

Preferred Skills & Experience

  • Familiarity with Operational Technology (OT), Industrial Control Systems (ICS), or other specialized technology environments.

  • Experience with Endpoint Detection and Response (EDR) and managed detection and response ecosystems.

  • Experience with threat hunting, detection engineering, security automation, and security telemetry.

  • Familiarity with MITRE ATT&CK, NIST Cybersecurity Framework, NIST incident response guidance, or similar security frameworks.

  • Certifications such as GCIH, GCFA, CISM, CISSP, or comparable cybersecurity credentials.

  • Experience developing or maturing security operations capabilities within complex or geographically distributed organizations.