SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Manager, Security Operations

Motive - Remote - Remote - posted 2026-09-21

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 140,000 - 200,000 / annual

Motive is hiring a Senior Manager, Security Operations to build and lead the company's Security Operations Center (SOC) from the ground up. This is a founding leadership role reporting to the CISO, where you will shape the team, tooling, detection strategy, and operating model rather than inheriting a mature organization. You will own the full detection and response lifecycle across Motive's entire infrastructure: detection engineering, 24/7 incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload security. The scope spans both product/production environments (cloud infrastructure, services, APIs, data platforms, connected device fleet) and enterprise/corporate systems (endpoints, identity, SaaS applications, network, email, internal tooling). Key responsibilities include: - Standing up and growing the SOC with operating model, coverage structure, runbooks, escalation paths, and team development for a globally distributed team - Owning Motive's detection strategy and coverage posture across both estates, treating detection content as code and mapping coverage against MITRE ATT&CK - Extending detection into production and cloud workloads in partnership with Platform Engineering - Owning 24/7 incident response, serving as incident commander for significant incidents, and communicating with executives during incidents - Managing the security telemetry and analytics platform (collection, normalization, enrichment, retention, cost) - Establishing a structured, hypothesis-driven threat hunting program and threat intelligence capability tailored to Motive's sector - Owning EDR across the corporate fleet and runtime/workload protection for production - Owning the operational side of phishing and social engineering defense - Architecting an AI-first operating model for the SOC, personally building triage, enrichment, correlation, and investigation automation The mandate is coverage and automation: you will build a small, senior, highly leveraged team designed around AI and automation from day one, rather than a traditional tiered analyst model. Success means a team focused on hard problems, not queue processing. Requirements: - 8+ years in security operations, incident response, detection engineering, or threat intelligence, with 3+ years leading teams - Demonstrably hands-on with recent personal experience writing detections, running investigations, leading incidents as commander, and building automation - Experience building or substantially rebuilding a SOC function (not just operating within an established one) - Credible across both production/cloud security monitoring and corporate/enterprise security operations - Deep experience with modern detection and response tooling (SIEM, security data platforms, EDR, SOAR or equivalent automation, cloud-native telemetry) and strong detection engineering skills - Strong background in cloud and container security monitoring, with AWS and Kubernetes strongly preferred - Solid grounding in identity-centric attack paths (SSO, OAuth, session compromise, MFA bypass, privilege escalation) - Proven incident command experience on significant incidents with executive communication skills and good judgment on escalation - Concrete, demonstrated use of AI in security operations (triage, enrichment, detection authoring, investigation support, reporting) — not just general enthusiasm - Experience building 24/7 coverage and leading globally distributed teams across multiple timezones - Plus: experience in transportation, logistics, IoT, connected devices, or critical infrastructure

Similar roles