SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 140,000 - 200,000 / annual
Motive is hiring a Senior Manager, Security Operations to build and lead the company's Security Operations Center (SOC) from the ground up. This is a founding leadership role reporting to the CISO, where you will shape the team, tooling, detection strategy, and operating model rather than inheriting a mature organization.
You will own the full detection and response lifecycle across Motive's entire infrastructure: detection engineering, 24/7 incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload security. The scope spans both product/production environments (cloud infrastructure, services, APIs, data platforms, connected device fleet) and enterprise/corporate systems (endpoints, identity, SaaS applications, network, email, internal tooling).
Key responsibilities include:
- Standing up and growing the SOC with operating model, coverage structure, runbooks, escalation paths, and team development for a globally distributed team
- Owning Motive's detection strategy and coverage posture across both estates, treating detection content as code and mapping coverage against MITRE ATT&CK
- Extending detection into production and cloud workloads in partnership with Platform Engineering
- Owning 24/7 incident response, serving as incident commander for significant incidents, and communicating with executives during incidents
- Managing the security telemetry and analytics platform (collection, normalization, enrichment, retention, cost)
- Establishing a structured, hypothesis-driven threat hunting program and threat intelligence capability tailored to Motive's sector
- Owning EDR across the corporate fleet and runtime/workload protection for production
- Owning the operational side of phishing and social engineering defense
- Architecting an AI-first operating model for the SOC, personally building triage, enrichment, correlation, and investigation automation
The mandate is coverage and automation: you will build a small, senior, highly leveraged team designed around AI and automation from day one, rather than a traditional tiered analyst model. Success means a team focused on hard problems, not queue processing.
Requirements:
- 8+ years in security operations, incident response, detection engineering, or threat intelligence, with 3+ years leading teams
- Demonstrably hands-on with recent personal experience writing detections, running investigations, leading incidents as commander, and building automation
- Experience building or substantially rebuilding a SOC function (not just operating within an established one)
- Credible across both production/cloud security monitoring and corporate/enterprise security operations
- Deep experience with modern detection and response tooling (SIEM, security data platforms, EDR, SOAR or equivalent automation, cloud-native telemetry) and strong detection engineering skills
- Strong background in cloud and container security monitoring, with AWS and Kubernetes strongly preferred
- Solid grounding in identity-centric attack paths (SSO, OAuth, session compromise, MFA bypass, privilege escalation)
- Proven incident command experience on significant incidents with executive communication skills and good judgment on escalation
- Concrete, demonstrated use of AI in security operations (triage, enrichment, detection authoring, investigation support, reporting) — not just general enthusiasm
- Experience building 24/7 coverage and leading globally distributed teams across multiple timezones
- Plus: experience in transportation, logistics, IoT, connected devices, or critical infrastructure