SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Keepit is seeking a Technical Project Manager for its Security Operations Center (SOC). This role sits at the intersection of project management and security operations, responsible for turning operational priorities into planned, tracked, and delivered work. You will have no direct reports but will lead the team's on-shift rotation and operating cadence, carrying real coordination authority across the SOC.
Key responsibilities include:
**Project Delivery & Roadmap Management**
Support daily security operations in deploying and implementing operational security priorities. Own the security roadmap and ensure the team stays on track to complete annual commitments. Lead communication, planning, and coordination with other teams and stakeholders. Run the SOC's recurring cadence including backlog refinement, sprint and roadmap reviews, shift handover syncs, and stakeholder check-ins. Maintain and prioritize the SOC's project backlog in coordination with security engineering and detection engineering leads. Track project risks, dependencies, and blockers; escalate when needed. Manage vendor and tool procurement timelines, including renewals, proofs of concept, and onboarding of new security tools. Own documentation of processes, standard operating procedures, and runbooks, keeping them current. Report roadmap and project status to leadership. Manage change requests and change management for production security tooling changes.
**Team Maturity & Metrics**
Define and track a maturity model (e.g., mapped to NIST Cybersecurity Framework or MITRE ATT&CK coverage). Own operational KPIs and metrics including mean time to detect (MTTD), mean time to respond (MTTR), alert-to-incident ratio, false positive rate, and detection coverage by use case. Run periodic gap assessments and turn findings into roadmap items. Coordinate tabletop exercises and purple team engagements, and track remediation of findings. Benchmark against industry peers or frameworks annually.
**Scheduling & Coverage**
Ensure schedule coverage for phishing triage and SIEM monitoring. Manage the on-shift rotation for incident response. Plan for PTO and holiday coverage gaps well in advance. Maintain a documented shift handover process between shifts. Extend scheduling oversight to other monitoring duties as needed.
**Incident Management**
Participate in incident response and coordination. Own and maintain incident response playbooks and runbooks. Facilitate post-incident reviews (blameless retrospectives) and track remediation actions to closure. Track incident metrics and produce leadership-facing incident reports. Manage escalation paths and ensure the right people and teams are looped in during major incidents. Coordinate with legal, compliance, and communications teams on incidents with regulatory or public exposure.
**Stakeholder & Vendor Management**
Serve as the single point of contact for cross-functional teams needing SOC engagement, including IT, legal, compliance, and engineering. Manage relationships with security tool vendors and external partners, from evaluation and proof of concept through onboarding and renewal.
**Tools & Systems**
You will work with Jira (power-user level for backlog, sprints, and roadmap tracking), Confluence (power-user level for processes, SOPs, runbooks), Figma for process diagrams, Wazuh for SIEM, Microsoft Defender XDR for endpoint detection and response, and Tenable One for attack surface management and vulnerability management. You will not administer security platforms but need working familiarity to read what they tell you and hold credible conversations with engineers. Part of this role includes helping decide which IT service management platform the SOC standardizes on.
**Success Metrics (First 90 Days)**
The SOC backlog is prioritized, current, and reviewed on a predictable cadence with security engineering and detection engineering leads. Annual roadmap commitments are broken into tracked work with owners, dependencies, and dates, with a status view leadership trusts. Coverage for phishing triage and SIEM monitoring is planned ahead with documented handover between shifts. You have facilitated at least one post-incident review and tracked its actions to closure.
**Requirements**
Must-haves:
- 5+ years managing technical projects or programs, ideally in security, infrastructure, or IT operations
- Proven ownership of a backlog and roadmap end-to-end: prioritization, dependency tracking, and delivery against dated commitments
- A working understanding of security operations — how detection, alert triage, incident response, and vulnerability management fit together (no need to have run a SOC yourself, but enough fluency to hold credible conversations with engineers who do)
- Power-user fluency in Jira and Confluence, or the ability to get there fast
- Experience coordinating coverage schedules or on-call rotations, including planning around absence and handover
- Strong written English and the ability to write documentation people can follow and will keep using
Nice-to-haves:
- Exposure to a security maturity or coverage framework such as NIST CSF or MITRE ATT&CK
- Experience facilitating post-incident reviews, tabletop exercises, or purple team engagements
- Experience selecting or rolling out an IT service management platform
- Familiarity with change management for production systems
- Vendor management or procurement coordination experience