Cybersecurity Operations Manager
Lyratechgroup · Jacksonville, FL
About this role
**Cybersecurity Operations Manager** Scarlett’s Cybersecurity Operations Manager is the senior technical leader and final escalation point for security events across managed clients. This is a hands-on leadership role—leading day-to-day managed security services while staying directly involved in detection, investigation, and incident response. **About Scarlett Group** Scarlett Group is recognized as a JBJ Best Places to Work and is one of the fastest-growing technology companies in the region. They offer competitive benefits, opportunities for advancement, professional development support, and a culture built on collaboration, accountability, and having fun while doing meaningful work. --- ## What you’ll do ### Security Leadership and Escalation - Serve as the final escalation point for security alerts and incidents across all managed clients. - Lead and develop the Cybersecurity Operations team with direct, hands-on coaching and clear accountability. - Establish roles, expectations, KPIs, and escalation paths for the SOC team. - Own queue health across all managed clients (alert volume, aging, assignment, and first-line escalation). Delegate day-to-day queue work while retaining accountability for outcomes. - Work the security queue directly when volume exceeds team capacity or when team members are unavailable (PTO/out/etc.). Queue coverage is expected. ### SOC and Incident Response - Oversee daily SOC operations: monitoring, alert triage, and response. - Lead containment, eradication, and recovery during incidents; own post-incident root cause analysis and documentation. Engage Advanced Services for deep forensics when needed. - Improve detection logic, alert quality, and response workflows continuously. - Manage MDR and SIEM partner relationships and hold them to service expectations. ### Client Security Accountability - Own the security outcomes clients experience: detection quality, response speed, containment, and client confidence. - Be the senior technical voice in client-facing security conversations (incidents, posture, reporting, remediation). - Partner with the vCISO and account teams to align operations with client roadmaps and compliance requirements. ### Operational Excellence - Develop and maintain runbooks, playbooks, and standard operating procedures. - Track performance against response times, detection accuracy, and SLA adherence; act on trends to reduce noise and improve efficiency. - Partner with Advanced Services on detection engineering, automation, and tooling (EDR/XDR, log/SIEM ingestion, identity protection, email security)—rather than maintaining a separate engineering function. ### Cross-Functional Collaboration - Coordinate security-related work with Support, NOC, and Professional Services. - Ensure clean escalation and resolution across operational teams. - Contribute to company-wide automation, AI, and service delivery initiatives. --- ## Qualifications - 4–6 years in cybersecurity/security operations, including direct experience triaging alerts and responding to incidents. - 2+ years in a leadership role (formal or informal), mentoring or directing analysts. - MSP/MSSP or multi-client environment strongly preferred. - Strong working knowledge of EDR/XDR, SIEM and log management, identity and access management (Entra, Conditional Access), and email security. - Comfortable serving as the final technical decision-maker under pressure during active incidents. - Familiarity with security framewor
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.