Manager / Sr. Manager, SecOps & Cyber Defense

Posted 14 Days Ago
Be an Early Applicant
New York, NY, USA
In-Office
185K-235K Annually
Senior level
Blockchain • Fintech • Financial Services • Cryptocurrency
The future is Bullish
The Role
Lead and scale 24/7 SecOps and cyber defense across US, UK, and EMEA. Manage SOC analysts and incident responders, handle high-severity incidents, design and tune detections, perform forensics and threat hunting, build SOAR automation, and run adversarial testing and readiness exercises while partnering with cross-functional teams.
Summary Generated by Built In
About BullishBullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. These include: Bullish Exchange – a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high-performance central limit order book matching engine with automated market making to provide deep and predictable liquidity. Bullish Exchange is regulated in Germany, Hong Kong, and Gibraltar. CoinDesk Indices – a collection of tradable proprietary and single-asset benchmarks and indices that track the performance of digital assets for global institutions in the digital assets and traditional finance industries. CoinDesk Data - a broad suite of digital assets market data and analytics, providing real-time insights into prices, trends, and market dynamics. CoinDesk Insights – a digital asset media and events provider and operator of Coindesk.com, a digital media platform that covers news and insights about digital assets, the underlying markets, policy, and blockchain technology.

Reports to:

Head of Security Engineering

Position Overview

We are seeking an experienced, hands-on Manager / Sr. Manager of SecOps & Cyber Defense to lead, scale, and actively drive our 24/7 security detection and response capabilities in the US, UK, & EMEA.

In this dual-capability role, you will lead a lean, highly technical group of SOC analysts and incident responders while remaining deeply connected to the engineering work. You will sit in the hot seat during major incidents, build high-efficacy detection engineering pipelines across cloud and hybrid infrastructure, and continuously elevate our threat hunting and triage posture.

This role is based in NYC and will be required to work onsite at our office located in Chelsea a minimum of 4 days per week. The position reports to the Head of Security Engineering.

Responsibilities:

Leadership & Team Operations

  • Manage & Mentor: Lead and mentor a small, high-performing team of SOC Analysts and Incident Response engineers across multiple time zones.

  • On-Call & Escalations: Serve as the primary point of escalation for high-severity security incidents, managing the global operational shift structure and continuous coverage model.

  • Metrics & Maturity: Define and track key SOC operational metrics (MTTD, MTTR, false positive ratios, incident coverage against MITRE ATT&CK) to drive continuous improvement.

  • Cross-Functional Collaboration: Partner closely with Infrastructure, Cloud Platform, DevOps, Corporate IT, Legal, and Compliance teams during critical triage and investigation phases.

Technical Execution & Incident Response

  • Incident Management: Drive end-to-end response for major security incidents—from initial detection, containment, and eradication to root-cause analysis and post-mortem reporting.

  • Detection Engineering: Design, write, and tune high-precision detection rules (SIEM, EDR, Cloud-native logs) to minimize noise and highlight sophisticated threat activity.

  • Forensics & Triage: Perform hands-on digital forensics (memory, disk, network artifact analysis) and reverse-engineer suspicious scripts/payloads when necessary.

  • Threat Research & Readiness: Conduct targeted research into emerging threat actor TTPs, zero-days, and cloud vulnerabilities to preemptively fortify detection capabilities and response playbooks.

  • Adversarial Testing & Exercises: Lead and participate in regular Red/Purple team operations and executive tabletop exercises to stress-test incident response readiness and validate control coverage.

  • Threat Hunting: Proactively hunt for undetected threat actor behavior using internal logs, intelligence feeds, and custom queries.

  • SOAR & Automation: Build and refine automated response playbooks using Python, API integrations, and SOAR tools to streamline repetitive analyst workflows.

Experience & Qualifications:

  • 8+ years of dedicated, hands-on experience in SOC operations, threat detection, and security incident response.

  • 2+ years of direct people management or formal team leadership experience, preferably overseeing a geographically distributed workforce.

  • Deep operational expertise in investigating cloud-native threats (AWS, GCP, or Azure), container environments (Kubernetes, Docker), and modern SaaS infrastructure.

  • Advanced proficiency with modern SIEM platforms, EDR/XDR suites, log aggregators, and SOAR tools.

  • Strong scripting and automation skills in Python, Bash, or Go to automate triage tasks and query APIs.

  • Strong knowledge of network protocols, cloud architecture, identity systems (Okta, Azure AD), and digital forensics fundamentals.

  • Proven ability to stay calm, decisive, and communicative under pressure during high-severity security incidents.

Nice-to-Have:

  • Prior experience in Financial Services, FinTech, Digital Assets, or high-throughput trading environments operating under strict regulatory audit standards (SOC 2, ISO 27001, SEC/FINRA frameworks).

  • Relevant industry certifications such as GIAC (GCIH, GCFA, GNFA, GCDA), CISSP, or OSCP.

Bullish US LLC & CoinDesk Inc. are committed to offering competitive compensation and benefits. The anticipated base salary for this position is $185,000 - $235,000 + discretionary annual target bonus + performance incentives/benefits. Offered salary will be reflective of job related knowledge, skills and commensurate experience.

Bullish is proud to be an equal opportunity employer. We are fast evolving and striving towards being a globally-diverse community. With integrity at our core, our success is driven by a talented team of individuals and the different perspectives they are encouraged to bring to work every day.

Skills Required

  • 8+ years hands-on SOC operations, threat detection, and incident response
  • 2+ years direct people management or formal team leadership
  • Experience investigating cloud-native threats in AWS, GCP, or Azure
  • Experience with container environments (Kubernetes, Docker)
  • Advanced proficiency with SIEM platforms, EDR/XDR suites, and log aggregators
  • Experience building and operating SOAR playbooks and automation
  • Strong scripting and automation skills in Python, Bash, or Go
  • Knowledge of network protocols, cloud architecture, identity systems (Okta, Azure AD), and digital forensics fundamentals
  • Ability to serve as primary escalation for high-severity incidents and manage 24/7 on-call/escalation model
  • Work onsite in NYC office a minimum of 4 days per week
  • Prior experience in Financial Services/FinTech/Digital Assets or high-throughput trading environments
  • Relevant certifications (GIAC GCIH/GCFA/GNFA/GCDA, CISSP, OSCP)

Bullish Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bullish and has not been reviewed or approved by Bullish.

  • Fair & Transparent Compensation Job postings disclose clear base pay bands and incentives for senior roles, and feedback suggests these ranges are competitive for the sector. This visibility signals clarity for leadership-level candidates evaluating offers.
  • Healthcare Strength U.S. operations provide health and vision insurance through a major carrier, indicating solid core medical coverage. Feedback suggests the medical offering aligns with market expectations.
  • Wellbeing & Lifestyle Benefits Perks such as free daily meals, UberEats allowances on in-office days, stocked fridges, catered lunches, rooftop events, and a home‑office stipend support everyday wellbeing. The company also emphasizes a flexible working environment and regular team activities.

Bullish Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Gibraltar
350 Employees
Year Founded: 2020

What We Do

Bullish is an institutionally focused global digital asset platform that provides market infrastructure and information services. Bullish services are regulated in the United States, European Union, United Kingdom, Hong Kong, and Gibraltar. These include: Bullish Exchange – a regulated and institutionally focused digital assets spot and derivatives exchange, integrating a high-performance central limit order book matching engine with automated market making to provide deep and predictable liquidity. CoinDesk Indices – a collection of tradable proprietary and single-asset benchmarks and indices that track the performance of digital assets for global institutions in the digital assets and traditional finance industries. CoinDesk Data - a broad suite of digital assets market data and analytics, providing real-time insights into prices, trends, and market dynamics. CoinDesk Insights – a digital asset media and events provider and operator of Coindesk.com, a digital media platform that covers news and insights about digital assets, the underlying markets, policy, and blockchain technology. For more information, please visit bullish.com and follow LinkedIn and X.

Gallery

Gallery

Similar Jobs

Formation Bio Logo Formation Bio

Associate Director, Analytical Development & QC

Artificial Intelligence • Big Data • Healthtech • Biotech • Pharmaceutical
Easy Apply
Hybrid
2 Locations
150 Employees
177K-235K Annually

Wise Logo Wise

Compliance Senior Manager

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
New York, NY, USA
9000 Employees
144K-207K Annually
Hybrid
2 Locations
289097 Employees
Hybrid
New York, NY, USA
289097 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account