Vaco LLC
Tempe, Arizona
Vaco is partnering with a national retail organization to hire a Manager of Cybersecurity Operations to lead and mature core security operations programs across the enterprise. This is a hands-on leadership role overseeing SOC operations, vulnerability management, endpoint security, DLP, incident response, and security automation. This role is ideal for a cybersecurity leader who can operate at both the program and technical execution level. The team needs someone who can manage internal security talent, hold external MSSP partners accountable, improve alert handling and escalation processes, and build repeatable capabilities around detection, response, reporting, and automation. The environment is collaborative, fast-moving, and highly cross-functional, requiring someone who can communicate clearly across IT, GRC, engineering, and business teams. This position is based in Tempe, Arizona and requires onsite presence Monday through Thursday, with Fridays optional remote. What You'll Be Doing Manage and mature day-to-day SOC operations, including monitoring, alert triage, escalation, and incident response workflows Partner closely with an external MSSP to drive SLA accountability, improve alert quality, and ensure critical issues are escalated quickly Lead vulnerability management efforts across tools such as Rapid7, Defender, and related platforms, including prioritization, remediation tracking, and executive reporting Oversee endpoint security and management initiatives across Intune, Jamf, Defender, and related endpoint controls Drive improvements to SIEM and SOAR capabilities, including automation opportunities for level 1 response, alert enrichment, and repeatable playbooks Build and refine incident response processes, including playbooks, simulations, post-incident reviews, and lessons learned Partner with IT, GRC, engineering, and business stakeholders to improve security posture across the organization Support DLP strategy and monitoring to protect sensitive data across SaaS, cloud, and endpoint environments Use security metrics, scorecards, and framework alignment to communicate program maturity and areas for improvement Evaluate how AI can be used responsibly in security operations, including automation of response workflows and protection of AI-enabled systems Mentor and develop security team members while remaining hands-on with technical operations when needed Help define and operationalize security programs that reduce risk while supporting business velocity Required Experience 6 or more years of experience in cybersecurity, information security operations, incident response, infrastructure, or related technical security roles Proven experience managing or leading SOC operations, either in a corporate environment or MSSP setting Strong understanding of the end-to-end incident response lifecycle, from alert intake through containment, remediation, and post-incident review Hands-on experience with cybersecurity technologies such as MDR, EDR, SIEM, SOAR, vulnerability management, and endpoint security tools Experience maturing vulnerability management programs, including risk prioritization, remediation coordination, and reporting Experience partnering with or managing MSSP relationships and holding vendors accountable to performance expectations Strong understanding of security frameworks and compliance considerations such as NIST, CIS Controls, PCI, SOX, and CCPA Ability to lead without authority and collaborate effectively across IT, engineering, GRC, and business teams Experience managing high-pressure incidents and making informed decisions under time-sensitive conditions Understanding of AI concepts and their impact on cybersecurity operations, including AI-enabled threats and secure use of AI tools Bachelor's degree in a related field, or equivalent additional experience Nice to Have CISM, CISSP, or similar security certification Experience with Rapid7, Microsoft Defender, Intune, Jamf, Workato, or comparable security and automation tools Experience building SOAR workflows or security automation playbooks Familiarity with cloud security controls across AWS, Azure, or GCP Experience in SaaS-heavy environments Experience with DLP program ownership or data protection initiatives Background supporting retail, consumer-facing, or high-growth business environments Compensation & Benefits Salary range: $150,000 to $160,000 base, depending on experience Bonus potential and other financial incentives Comprehensive benefits package available If you are a hands-on cybersecurity operations leader who can mature SOC processes, improve vulnerability and endpoint programs, and build practical automation across a growing security environment, we would welcome the opportunity to connect. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets . click apply for full job details
Vaco is partnering with a national retail organization to hire a Manager of Cybersecurity Operations to lead and mature core security operations programs across the enterprise. This is a hands-on leadership role overseeing SOC operations, vulnerability management, endpoint security, DLP, incident response, and security automation. This role is ideal for a cybersecurity leader who can operate at both the program and technical execution level. The team needs someone who can manage internal security talent, hold external MSSP partners accountable, improve alert handling and escalation processes, and build repeatable capabilities around detection, response, reporting, and automation. The environment is collaborative, fast-moving, and highly cross-functional, requiring someone who can communicate clearly across IT, GRC, engineering, and business teams. This position is based in Tempe, Arizona and requires onsite presence Monday through Thursday, with Fridays optional remote. What You'll Be Doing Manage and mature day-to-day SOC operations, including monitoring, alert triage, escalation, and incident response workflows Partner closely with an external MSSP to drive SLA accountability, improve alert quality, and ensure critical issues are escalated quickly Lead vulnerability management efforts across tools such as Rapid7, Defender, and related platforms, including prioritization, remediation tracking, and executive reporting Oversee endpoint security and management initiatives across Intune, Jamf, Defender, and related endpoint controls Drive improvements to SIEM and SOAR capabilities, including automation opportunities for level 1 response, alert enrichment, and repeatable playbooks Build and refine incident response processes, including playbooks, simulations, post-incident reviews, and lessons learned Partner with IT, GRC, engineering, and business stakeholders to improve security posture across the organization Support DLP strategy and monitoring to protect sensitive data across SaaS, cloud, and endpoint environments Use security metrics, scorecards, and framework alignment to communicate program maturity and areas for improvement Evaluate how AI can be used responsibly in security operations, including automation of response workflows and protection of AI-enabled systems Mentor and develop security team members while remaining hands-on with technical operations when needed Help define and operationalize security programs that reduce risk while supporting business velocity Required Experience 6 or more years of experience in cybersecurity, information security operations, incident response, infrastructure, or related technical security roles Proven experience managing or leading SOC operations, either in a corporate environment or MSSP setting Strong understanding of the end-to-end incident response lifecycle, from alert intake through containment, remediation, and post-incident review Hands-on experience with cybersecurity technologies such as MDR, EDR, SIEM, SOAR, vulnerability management, and endpoint security tools Experience maturing vulnerability management programs, including risk prioritization, remediation coordination, and reporting Experience partnering with or managing MSSP relationships and holding vendors accountable to performance expectations Strong understanding of security frameworks and compliance considerations such as NIST, CIS Controls, PCI, SOX, and CCPA Ability to lead without authority and collaborate effectively across IT, engineering, GRC, and business teams Experience managing high-pressure incidents and making informed decisions under time-sensitive conditions Understanding of AI concepts and their impact on cybersecurity operations, including AI-enabled threats and secure use of AI tools Bachelor's degree in a related field, or equivalent additional experience Nice to Have CISM, CISSP, or similar security certification Experience with Rapid7, Microsoft Defender, Intune, Jamf, Workato, or comparable security and automation tools Experience building SOAR workflows or security automation playbooks Familiarity with cloud security controls across AWS, Azure, or GCP Experience in SaaS-heavy environments Experience with DLP program ownership or data protection initiatives Background supporting retail, consumer-facing, or high-growth business environments Compensation & Benefits Salary range: $150,000 to $160,000 base, depending on experience Bonus potential and other financial incentives Comprehensive benefits package available If you are a hands-on cybersecurity operations leader who can mature SOC processes, improve vulnerability and endpoint programs, and build practical automation across a growing security environment, we would welcome the opportunity to connect. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets . click apply for full job details
The Scarlett Group
Jacksonville, Florida
Cybersecurity Operations Manager Award-Winning Culture. Rapid Growth. Exceptional Careers. More Than a Job - A Place to Grow. When you join Scarlett Group, you're joining a team recognized as a JBJ Best Places to Work and one of the fastest-growing technology companies in the region. We offer competitive benefits, opportunities for advancement, professional development support, and a culture built on collaboration, accountability, and having fun while doing meaningful work. Great benefits. Great people. Great opportunities. That's the Scarlett difference. Cybersecurity Operations Manager Needed (Must be local to Jacksonville area) Job Overview: The Cybersecurity Operations Manager is the senior technical leader and final escalation point for security events across Scarlett's managed clients. This is a hands-on leadership role. The Manager leads day-to-day delivery of managed security services while remaining directly involved in detection, investigation, and incident response. The position sits between security strategy, owned by the vCISO, and execution, carried out by the SOC team. The Manager is accountable for the security posture and incident outcomes our clients experience. The role is outcome-driven, focused on reducing client risk, improving response times, and being the dependable last line of decision-making when a security event escalates. Responsibilities & Duties: Security Leadership and Escalation Serve as the final escalation point for security alerts and incidents across all managed clients. Lead and develop the Cybersecurity Operations team with direct, hands-on coaching and clear accountability. Establish roles, expectations, KPIs, and escalation paths for the SOC team. Own queue health across all managed clients, including alert volume, aging, assignment, and first-line escalation. Delegate day-to-day queue work to SOC team members while retaining accountability for the outcome. Work the security queue directly when volume exceeds team capacity or when SOC team members are on PTO, out, or otherwise unavailable. This is a working leadership role and queue coverage is an expected part of it, not an exception. SOC and Incident Response Oversee daily SOC operations, including monitoring, alert triage, and response. Lead containment, eradication, and recovery during security incidents, and own post-incident root cause analysis and documentation. Engage Advanced Services for deep forensic analysis when an incident requires it. Improve detection logic, alert quality, and response workflows on an ongoing basis. Manage MDR and SIEM partner relationships and hold them to service expectations. Client Security Accountability Own the security outcomes managed clients experience: detection quality, response speed, containment, and client confidence. Serve as the senior technical voice in client-facing security conversations covering incidents, posture, reporting, and remediation. Partner with the vCISO and account teams to align operations with client roadmaps and compliance requirements. Operational Excellence Develop and maintain runbooks, playbooks, and standard operating procedures. Track performance against response times, detection accuracy, and SLA adherence, and act on trends to reduce noise and improve efficiency. Partner with Advanced Services on detection engineering, automation, and tooling, including EDR/XDR, log and SIEM ingestion, identity protection, and email security, rather than maintaining a separate engineering function. Cross-Functional Collaboration Coordinate security-related work with Support, NOC, and Professional Services. Ensure clean escalation and resolution across operational teams. Contribute to company-wide automation, AI, and service delivery initiatives. Other To support onboarding, training, and team integration, employees in this position are expected to work onsite. Maintain accurate daily time records and ensure all time worked is entered and submitted by the end of each workday in accordance with company procedures. Other duties as assigned. Qualifications: Experience 4 to 6 years in cybersecurity or security operations, including direct experience triaging alerts and responding to security incidents. 2 or more years in a leadership role, formal or informal, including mentoring or directing other analysts. MSP, MSSP, or multi-client environment strongly preferred. Technical Expertise Strong working knowledge of endpoint detection and response (EDR/XDR), SIEM and log management, identity and access management (Entra, Conditional Access), and email security. Comfort serving as the final technical decisionmaker under pressure during active incidents. Familiarity with security frameworks (NIST, CIS, ISO) and compliance-driven environments. CMMC and NIST 800-171 experience is a plus. Leadership Skills Strong coaching, team development, and performance management capabilities. Excellent communication, including translating technical issues for business stakeholders. Sound problem-solving and decision-making under pressure. Education and Certifications Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent experience. Preferred: Security+, CySA+, GCIH, or equivalent. CISSP, GCFA, or other advanced certifications are a plus but not expected. Environmental and Physical Requirements: The work environment for this position is a standard office setting. The employee is regularly required to sit, stand, walk, and use hands to operate a computer and other office equipment. The employee must occasionally lift and/or move up to 25 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. What Success Looks Like Incidents are resolved at this level without routinely reaching the vCISO or executive leadership. Alerts are high quality, actionable, and efficiently resolved. Incident response is fast, structured, and well communicated. The team is engaged, growing, and aligned to outcomes. Clients trust Scarlett with their security and stay because of it. Compensation Base salary range: $80,000 to $95,000 annually, dependent on incident response experience, leadership experience, and certifications. Salaried and exempt. On-call participation and after-hours incident work are compensated within base salary rather than through hourly or overtime pay. Eligible for standard company benefits and any applicable performance incentive. Work Environment Onsite, Jacksonville based. Standard office environment with after-hours coordination during security incidents. Participates in the standing on-call and escalation rotation alongside SOC team members. Serves as backstop on-call coverage when the rotation cannot be filled, including PTO, holidays, unplanned absences, and periods of elevated alert or incident volume. Availability outside standard hours is expected during active incidents and coverage gaps. The role is exempt and compensated on outcomes rather than hours. What We Offer Competitive pay and comprehensive benefits 401(k) with company match Generous PTO and paid holidays Professional development and certification program Monthly cell phone stipend Paid mileage Clear opportunities for career growth An award-winning culture recognized as a JBJ Best Places to Work The chance to make an impact in a fast-growing company where your contributions matter Compensation details: 0 Yearly Salary PI67f43f98b25f-1302
Cybersecurity Operations Manager Award-Winning Culture. Rapid Growth. Exceptional Careers. More Than a Job - A Place to Grow. When you join Scarlett Group, you're joining a team recognized as a JBJ Best Places to Work and one of the fastest-growing technology companies in the region. We offer competitive benefits, opportunities for advancement, professional development support, and a culture built on collaboration, accountability, and having fun while doing meaningful work. Great benefits. Great people. Great opportunities. That's the Scarlett difference. Cybersecurity Operations Manager Needed (Must be local to Jacksonville area) Job Overview: The Cybersecurity Operations Manager is the senior technical leader and final escalation point for security events across Scarlett's managed clients. This is a hands-on leadership role. The Manager leads day-to-day delivery of managed security services while remaining directly involved in detection, investigation, and incident response. The position sits between security strategy, owned by the vCISO, and execution, carried out by the SOC team. The Manager is accountable for the security posture and incident outcomes our clients experience. The role is outcome-driven, focused on reducing client risk, improving response times, and being the dependable last line of decision-making when a security event escalates. Responsibilities & Duties: Security Leadership and Escalation Serve as the final escalation point for security alerts and incidents across all managed clients. Lead and develop the Cybersecurity Operations team with direct, hands-on coaching and clear accountability. Establish roles, expectations, KPIs, and escalation paths for the SOC team. Own queue health across all managed clients, including alert volume, aging, assignment, and first-line escalation. Delegate day-to-day queue work to SOC team members while retaining accountability for the outcome. Work the security queue directly when volume exceeds team capacity or when SOC team members are on PTO, out, or otherwise unavailable. This is a working leadership role and queue coverage is an expected part of it, not an exception. SOC and Incident Response Oversee daily SOC operations, including monitoring, alert triage, and response. Lead containment, eradication, and recovery during security incidents, and own post-incident root cause analysis and documentation. Engage Advanced Services for deep forensic analysis when an incident requires it. Improve detection logic, alert quality, and response workflows on an ongoing basis. Manage MDR and SIEM partner relationships and hold them to service expectations. Client Security Accountability Own the security outcomes managed clients experience: detection quality, response speed, containment, and client confidence. Serve as the senior technical voice in client-facing security conversations covering incidents, posture, reporting, and remediation. Partner with the vCISO and account teams to align operations with client roadmaps and compliance requirements. Operational Excellence Develop and maintain runbooks, playbooks, and standard operating procedures. Track performance against response times, detection accuracy, and SLA adherence, and act on trends to reduce noise and improve efficiency. Partner with Advanced Services on detection engineering, automation, and tooling, including EDR/XDR, log and SIEM ingestion, identity protection, and email security, rather than maintaining a separate engineering function. Cross-Functional Collaboration Coordinate security-related work with Support, NOC, and Professional Services. Ensure clean escalation and resolution across operational teams. Contribute to company-wide automation, AI, and service delivery initiatives. Other To support onboarding, training, and team integration, employees in this position are expected to work onsite. Maintain accurate daily time records and ensure all time worked is entered and submitted by the end of each workday in accordance with company procedures. Other duties as assigned. Qualifications: Experience 4 to 6 years in cybersecurity or security operations, including direct experience triaging alerts and responding to security incidents. 2 or more years in a leadership role, formal or informal, including mentoring or directing other analysts. MSP, MSSP, or multi-client environment strongly preferred. Technical Expertise Strong working knowledge of endpoint detection and response (EDR/XDR), SIEM and log management, identity and access management (Entra, Conditional Access), and email security. Comfort serving as the final technical decisionmaker under pressure during active incidents. Familiarity with security frameworks (NIST, CIS, ISO) and compliance-driven environments. CMMC and NIST 800-171 experience is a plus. Leadership Skills Strong coaching, team development, and performance management capabilities. Excellent communication, including translating technical issues for business stakeholders. Sound problem-solving and decision-making under pressure. Education and Certifications Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent experience. Preferred: Security+, CySA+, GCIH, or equivalent. CISSP, GCFA, or other advanced certifications are a plus but not expected. Environmental and Physical Requirements: The work environment for this position is a standard office setting. The employee is regularly required to sit, stand, walk, and use hands to operate a computer and other office equipment. The employee must occasionally lift and/or move up to 25 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. What Success Looks Like Incidents are resolved at this level without routinely reaching the vCISO or executive leadership. Alerts are high quality, actionable, and efficiently resolved. Incident response is fast, structured, and well communicated. The team is engaged, growing, and aligned to outcomes. Clients trust Scarlett with their security and stay because of it. Compensation Base salary range: $80,000 to $95,000 annually, dependent on incident response experience, leadership experience, and certifications. Salaried and exempt. On-call participation and after-hours incident work are compensated within base salary rather than through hourly or overtime pay. Eligible for standard company benefits and any applicable performance incentive. Work Environment Onsite, Jacksonville based. Standard office environment with after-hours coordination during security incidents. Participates in the standing on-call and escalation rotation alongside SOC team members. Serves as backstop on-call coverage when the rotation cannot be filled, including PTO, holidays, unplanned absences, and periods of elevated alert or incident volume. Availability outside standard hours is expected during active incidents and coverage gaps. The role is exempt and compensated on outcomes rather than hours. What We Offer Competitive pay and comprehensive benefits 401(k) with company match Generous PTO and paid holidays Professional development and certification program Monthly cell phone stipend Paid mileage Clear opportunities for career growth An award-winning culture recognized as a JBJ Best Places to Work The chance to make an impact in a fast-growing company where your contributions matter Compensation details: 0 Yearly Salary PI67f43f98b25f-1302
The Scarlett Group
Jacksonville, Florida
Cybersecurity Operations Manager Award-Winning Culture. Rapid Growth. Exceptional Careers. More Than a Job - A Place to Grow. When you join Scarlett Group, you're joining a team recognized as a JBJ Best Places to Work and one of the fastest-growing technology companies in the region. We offer competitive benefits, opportunities for advancement, professional development support, and a culture built on collaboration, accountability, and having fun while doing meaningful work. Great benefits. Great people. Great opportunities. That's the Scarlett difference. Cybersecurity Operations Manager Needed (Must be local to Jacksonville area) Job Overview: The Cybersecurity Operations Manager is the senior technical leader and final escalation point for security events across Scarlett's managed clients. This is a hands-on leadership role. The Manager leads day-to-day delivery of managed security services while remaining directly involved in detection, investigation, and incident response. The position sits between security strategy, owned by the vCISO, and execution, carried out by the SOC team. The Manager is accountable for the security posture and incident outcomes our clients experience. The role is outcome-driven, focused on reducing client risk, improving response times, and being the dependable last line of decision-making when a security event escalates. Responsibilities & Duties: Security Leadership and Escalation Serve as the final escalation point for security alerts and incidents across all managed clients. Lead and develop the Cybersecurity Operations team with direct, hands-on coaching and clear accountability. Establish roles, expectations, KPIs, and escalation paths for the SOC team. Own queue health across all managed clients, including alert volume, aging, assignment, and first-line escalation. Delegate day-to-day queue work to SOC team members while retaining accountability for the outcome. Work the security queue directly when volume exceeds team capacity or when SOC team members are on PTO, out, or otherwise unavailable. This is a working leadership role and queue coverage is an expected part of it, not an exception. SOC and Incident Response Oversee daily SOC operations, including monitoring, alert triage, and response. Lead containment, eradication, and recovery during security incidents, and own post-incident root cause analysis and documentation. Engage Advanced Services for deep forensic analysis when an incident requires it. Improve detection logic, alert quality, and response workflows on an ongoing basis. Manage MDR and SIEM partner relationships and hold them to service expectations. Client Security Accountability Own the security outcomes managed clients experience: detection quality, response speed, containment, and client confidence. Serve as the senior technical voice in client-facing security conversations covering incidents, posture, reporting, and remediation. Partner with the vCISO and account teams to align operations with client roadmaps and compliance requirements. Operational Excellence Develop and maintain runbooks, playbooks, and standard operating procedures. Track performance against response times, detection accuracy, and SLA adherence, and act on trends to reduce noise and improve efficiency. Partner with Advanced Services on detection engineering, automation, and tooling, including EDR/XDR, log and SIEM ingestion, identity protection, and email security, rather than maintaining a separate engineering function. Cross-Functional Collaboration Coordinate security-related work with Support, NOC, and Professional Services. Ensure clean escalation and resolution across operational teams. Contribute to company-wide automation, AI, and service delivery initiatives. Other To support onboarding, training, and team integration, employees in this position are expected to work onsite. Maintain accurate daily time records and ensure all time worked is entered and submitted by the end of each workday in accordance with company procedures. Other duties as assigned. Qualifications: Experience 4 to 6 years in cybersecurity or security operations, including direct experience triaging alerts and responding to security incidents. 2 or more years in a leadership role, formal or informal, including mentoring or directing other analysts. MSP, MSSP, or multi-client environment strongly preferred. Technical Expertise Strong working knowledge of endpoint detection and response (EDR/XDR), SIEM and log management, identity and access management (Entra, Conditional Access), and email security. Comfort serving as the final technical decisionmaker under pressure during active incidents. Familiarity with security frameworks (NIST, CIS, ISO) and compliance-driven environments. CMMC and NIST 800-171 experience is a plus. Leadership Skills Strong coaching, team development, and performance management capabilities. Excellent communication, including translating technical issues for business stakeholders. Sound problem-solving and decision-making under pressure. Education and Certifications Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent experience. Preferred: Security+, CySA+, GCIH, or equivalent. CISSP, GCFA, or other advanced certifications are a plus but not expected. Environmental and Physical Requirements: The work environment for this position is a standard office setting. The employee is regularly required to sit, stand, walk, and use hands to operate a computer and other office equipment. The employee must occasionally lift and/or move up to 25 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. What Success Looks Like Incidents are resolved at this level without routinely reaching the vCISO or executive leadership. Alerts are high quality, actionable, and efficiently resolved. Incident response is fast, structured, and well communicated. The team is engaged, growing, and aligned to outcomes. Clients trust Scarlett with their security and stay because of it. Compensation Base salary range: $80,000 to $95,000 annually, dependent on incident response experience, leadership experience, and certifications. Salaried and exempt. On-call participation and after-hours incident work are compensated within base salary rather than through hourly or overtime pay. Eligible for standard company benefits and any applicable performance incentive. Work Environment Onsite, Jacksonville based. Standard office environment with after-hours coordination during security incidents. Participates in the standing on-call and escalation rotation alongside SOC team members. Serves as backstop on-call coverage when the rotation cannot be filled, including PTO, holidays, unplanned absences, and periods of elevated alert or incident volume. Availability outside standard hours is expected during active incidents and coverage gaps. The role is exempt and compensated on outcomes rather than hours. What We Offer Competitive pay and comprehensive benefits 401(k) with company match Generous PTO and paid holidays Professional development and certification program Monthly cell phone stipend Paid mileage Clear opportunities for career growth An award-winning culture recognized as a JBJ Best Places to Work The chance to make an impact in a fast-growing company where your contributions matter Compensation details: 0 Yearly Salary PI67f43f98b25f-1302
Cybersecurity Operations Manager Award-Winning Culture. Rapid Growth. Exceptional Careers. More Than a Job - A Place to Grow. When you join Scarlett Group, you're joining a team recognized as a JBJ Best Places to Work and one of the fastest-growing technology companies in the region. We offer competitive benefits, opportunities for advancement, professional development support, and a culture built on collaboration, accountability, and having fun while doing meaningful work. Great benefits. Great people. Great opportunities. That's the Scarlett difference. Cybersecurity Operations Manager Needed (Must be local to Jacksonville area) Job Overview: The Cybersecurity Operations Manager is the senior technical leader and final escalation point for security events across Scarlett's managed clients. This is a hands-on leadership role. The Manager leads day-to-day delivery of managed security services while remaining directly involved in detection, investigation, and incident response. The position sits between security strategy, owned by the vCISO, and execution, carried out by the SOC team. The Manager is accountable for the security posture and incident outcomes our clients experience. The role is outcome-driven, focused on reducing client risk, improving response times, and being the dependable last line of decision-making when a security event escalates. Responsibilities & Duties: Security Leadership and Escalation Serve as the final escalation point for security alerts and incidents across all managed clients. Lead and develop the Cybersecurity Operations team with direct, hands-on coaching and clear accountability. Establish roles, expectations, KPIs, and escalation paths for the SOC team. Own queue health across all managed clients, including alert volume, aging, assignment, and first-line escalation. Delegate day-to-day queue work to SOC team members while retaining accountability for the outcome. Work the security queue directly when volume exceeds team capacity or when SOC team members are on PTO, out, or otherwise unavailable. This is a working leadership role and queue coverage is an expected part of it, not an exception. SOC and Incident Response Oversee daily SOC operations, including monitoring, alert triage, and response. Lead containment, eradication, and recovery during security incidents, and own post-incident root cause analysis and documentation. Engage Advanced Services for deep forensic analysis when an incident requires it. Improve detection logic, alert quality, and response workflows on an ongoing basis. Manage MDR and SIEM partner relationships and hold them to service expectations. Client Security Accountability Own the security outcomes managed clients experience: detection quality, response speed, containment, and client confidence. Serve as the senior technical voice in client-facing security conversations covering incidents, posture, reporting, and remediation. Partner with the vCISO and account teams to align operations with client roadmaps and compliance requirements. Operational Excellence Develop and maintain runbooks, playbooks, and standard operating procedures. Track performance against response times, detection accuracy, and SLA adherence, and act on trends to reduce noise and improve efficiency. Partner with Advanced Services on detection engineering, automation, and tooling, including EDR/XDR, log and SIEM ingestion, identity protection, and email security, rather than maintaining a separate engineering function. Cross-Functional Collaboration Coordinate security-related work with Support, NOC, and Professional Services. Ensure clean escalation and resolution across operational teams. Contribute to company-wide automation, AI, and service delivery initiatives. Other To support onboarding, training, and team integration, employees in this position are expected to work onsite. Maintain accurate daily time records and ensure all time worked is entered and submitted by the end of each workday in accordance with company procedures. Other duties as assigned. Qualifications: Experience 4 to 6 years in cybersecurity or security operations, including direct experience triaging alerts and responding to security incidents. 2 or more years in a leadership role, formal or informal, including mentoring or directing other analysts. MSP, MSSP, or multi-client environment strongly preferred. Technical Expertise Strong working knowledge of endpoint detection and response (EDR/XDR), SIEM and log management, identity and access management (Entra, Conditional Access), and email security. Comfort serving as the final technical decisionmaker under pressure during active incidents. Familiarity with security frameworks (NIST, CIS, ISO) and compliance-driven environments. CMMC and NIST 800-171 experience is a plus. Leadership Skills Strong coaching, team development, and performance management capabilities. Excellent communication, including translating technical issues for business stakeholders. Sound problem-solving and decision-making under pressure. Education and Certifications Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent experience. Preferred: Security+, CySA+, GCIH, or equivalent. CISSP, GCFA, or other advanced certifications are a plus but not expected. Environmental and Physical Requirements: The work environment for this position is a standard office setting. The employee is regularly required to sit, stand, walk, and use hands to operate a computer and other office equipment. The employee must occasionally lift and/or move up to 25 pounds. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. What Success Looks Like Incidents are resolved at this level without routinely reaching the vCISO or executive leadership. Alerts are high quality, actionable, and efficiently resolved. Incident response is fast, structured, and well communicated. The team is engaged, growing, and aligned to outcomes. Clients trust Scarlett with their security and stay because of it. Compensation Base salary range: $80,000 to $95,000 annually, dependent on incident response experience, leadership experience, and certifications. Salaried and exempt. On-call participation and after-hours incident work are compensated within base salary rather than through hourly or overtime pay. Eligible for standard company benefits and any applicable performance incentive. Work Environment Onsite, Jacksonville based. Standard office environment with after-hours coordination during security incidents. Participates in the standing on-call and escalation rotation alongside SOC team members. Serves as backstop on-call coverage when the rotation cannot be filled, including PTO, holidays, unplanned absences, and periods of elevated alert or incident volume. Availability outside standard hours is expected during active incidents and coverage gaps. The role is exempt and compensated on outcomes rather than hours. What We Offer Competitive pay and comprehensive benefits 401(k) with company match Generous PTO and paid holidays Professional development and certification program Monthly cell phone stipend Paid mileage Clear opportunities for career growth An award-winning culture recognized as a JBJ Best Places to Work The chance to make an impact in a fast-growing company where your contributions matter Compensation details: 0 Yearly Salary PI67f43f98b25f-1302