MDR Manager

Posted 3 Days Ago
Be an Early Applicant
Home, PA, USA
In-Office
Senior level
Information Technology • Cybersecurity
Unified Detection & Response Built for MSPs and IT Service Providers.
The Role
Lead 24/7 MDR/SOC operations: manage coverage, SLAs, QA, playbooks, and analyst development; act as final T3 escalation, run hunts across EDR/ITDR/email, use BigQuery/SQL/KQL for triage, and partner with MSPs and product teams.
Summary Generated by Built In

Established in 2022, Guardz rapidly emerged as a noteworthy player in the cybersecurity sphere, securing $85M in funding and rallying a dedicated team of 120 industry professionals. Our vision is to foster a safer digital landscape for small and medium businesses across the globe. To this end, we introduced our comprehensive all-in-one platform, and continue to grow and expand our team, our partnerships and our revenue.

We are looking for an experienced MDR Manager to lead our Security Operations team. The ideal candidate combines strong technical expertise with operational leadership and enjoys developing analysts, improving processes, and managing complex security incidents across multi-tenant MSP environments.

As a hands-on leader, you will oversee day-to-day MDR operations, including coverage, SLAs, quality, escalation tiers, and analyst development. You will also serve as the final escalation point for Tier 3 threats and lead the team through the most complex investigations.

Responsibilities:

  • Own 24/7 shift coverage, tiering, and escalation paths so every alert reaches the right analyst and there are no gaps in monitoring or escalation. Participate in an on-call rotation with the team.
  • Own response SLAs (time-to-triage, time-to-notify, MTTR) and report SOC KPIs (MTTD, MTTR, detection efficacy, false-positive rate, case aging, customer satisfaction) to leadership.
  • Run QA on closed alerts and incidents, drive down false positives, and maintain the team's runbooks, playbooks, and SOC standards.
  • Lead, coach, and mentor MDR Analysts: regular 1:1s, performance feedback, onboarding, and the T1-to-T3 training path. Run tabletop exercises and post-incident reviews.
  • Act as technical lead and final escalation point for T3 incidents (advanced malware, identity threats like MFA fatigue and token theft, active breaches), leading the full lifecycle with defensible documentation.
  • Correlate alerts across EDR (SentinelOne, Defender for Endpoint), ITDR (M365, Google Workspace), and email security, and run proactive threat hunts aligned to MITRE ATT&CK.
  • Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed.
  • Partner with MSPs on major incidents and posture reviews, and feed findings back into detection with product, threat research, and engineering.

Requirements:

  • 5+ years in SOC, MDR, or Incident Response handling complex attacks, including 2+ years as a Team Lead, Shift Lead, or senior.
  • Hands-on expertise with EDR (SentinelOne, CrowdStrike, Defender for Endpoint) and ITDR (identity threat management across M365 and Google Workspace).
  • Hands-on experience with Google BigQuery, Snowflake, Splunk, Elastic, or equivalent, and fluency in a query language such as SQL, KQL, or SPL.
  • Experience with MITRE ATT&CK-aligned detection, proactive threat hunting, and AI-driven triage engines, automated playbooks, or agentic SecOps platforms.
  • Excellent communication skills, able to make high-risk technical findings clear to both technical and non-technical audiences.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience.
  • Preferred: CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH / GCIA / GCFA, or CISSP (or equivalent DoD 8570 / 8140 IAT Level II).

Skills Required

  • 5+ years in SOC, MDR, or Incident Response handling complex attacks
  • 2+ years as a Team Lead, Shift Lead, or senior
  • Hands-on expertise with EDR (SentinelOne, CrowdStrike, Defender for Endpoint) and ITDR (identity threat management across M365 and Google Workspace)
  • Hands-on experience with Google BigQuery, Snowflake, Splunk, Elastic, or equivalent
  • Fluency in a query language such as SQL, KQL, or SPL
  • Experience with MITRE ATT&CK-aligned detection, proactive threat hunting, and AI-driven triage engines or automated playbooks
  • Excellent communication skills, able to explain high-risk technical findings to technical and non-technical audiences
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience
  • CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH/GCIA/GCFA, or CISSP (or equivalent DoD 8570/8140 IAT Level II)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Miami, Florida
146 Employees
Year Founded: 2022

What We Do

Guardz is the unified cybersecurity platform purpose-built for MSPs. We consolidate the essential security controls, including identities, endpoints, email, awareness, and more, into one AI-native framework designed for operational efficiency. Our identity-centric approach connects the dots across vectors, reducing the gaps that siloed tools leave behind so MSPs can see, understand, and act on user risk in real time. Backed by an elite research and threat hunting team, Guardz strengthens detection across environments, turning signals into actionable insights. With 24/7 AI + human-led MDR, Guardz utilizes agentic AI to triage at machine speed while expert analysts validate, mitigate, and guide response, giving MSPs scalable protection without adding headcount. Our mission is simple: give MSPs the scale, confidence, and clarity they need to stay ahead of attackers and deliver protection to every SMB they serve.

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Senior Underwriting Manager, Liberty Mutual Mobility Solutions

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
5 Locations
40000 Employees
98K-359K Annually

Samsara Logo Samsara

Staff Software Engineer

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
162K-290K Annually

Bestow Logo Bestow

Product Actuary, Life & Annuity

Big Data • Fintech • Information Technology • Insurance • Software
Remote or Hybrid
US
160 Employees
175K-200K Annually

PNC Bank Logo PNC Bank

Product Owner

Machine Learning • Payments • Security • Software • Financial Services
Hybrid
Pittsburgh, PA, USA
55000 Employees
91K-186K Annually

Similar Companies Hiring

Scrunch  Thumbnail
Artificial Intelligence • Information Technology • Marketing Tech • Software • SEO
Salt Lake City, Utah
Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account