SOC Manager

Posted Yesterday
Be an Early Applicant
2 Locations
In-Office
98K-199K Annually
Senior level
Fintech • Software • Financial Services
The Role
Leads internal and MSSP-supported SOC operations, including monitoring, incident response, threat hunting, detection engineering, automation, telemetry management, and KPI reporting. Manages Microsoft Sentinel and Defender XDR capabilities, improves detection quality, coordinates major incidents, governs use-case lifecycles, and develops SOC analysts. Partners with technical, compliance, legal, and business stakeholders to strengthen cyber defense, operational readiness, and risk reduction.
Summary Generated by Built In
Overview

Old National Bank has been serving clients and communities since 1834. With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the communities we serve. As a trusted partner, we thrive on helping our clients achieve their goals and dreams, and we are committed to social responsibility and investing in our communities through volunteering and charitable giving. 


We continually seek highly motivated and talented individuals as our people are critical to our success. In return, we offer competitive compensation with our salary and incentive program, in addition to medical, dental, and vision insurance.  401K, continuing education opportunities and an employee assistance program are also included in our benefit suite. Old National also offers a variety of Impact Network Groups led by team members who are passionate about driving engagement, creating awareness of diverse backgrounds and experiences, and building inclusion across the organization.  We offer a unique opportunity to join a growing, community and client-focused company that is firmly rooted in its core values.

Responsibilities

We are seeking a hands-on Security Operations Center (SOC) Manager to turn our Microsoft Sentinel and Microsoft Defender XDR foundation into a high-performing, intelligence-driven SOC. This technical leader will guide internal analysts and MSSP-supported operations while improving detection quality, investigation workflows, incident response, automation, telemetry management, KPI/KRI dashboards, and analyst development. The ideal candidate has senior/Tier 3-level SOC experience and is ready to build the operating model, metrics, capabilities, and team culture that take our cyber defense program to the next level. 

Salary Range

The salary range for this position is $98,4/yr - $199,000/yr plus bonus. The base salary indicated for this position reflects the compensation range applicable to all levels of the role across the United States. Actual salary offers within this range may vary based on a number of factors, including the specific responsibilities of the position, the candidate’s relevant skills and professional experience, educational qualifications, and geographic location.


Key Accountabilities 

  • Lead daily SOC operations across internal and MSSP-supported monitoring, alert triage, investigation, escalation, incident response, threat hunting, and continuous improvement. 
  • Own and evolve the MSSP relationship, including eyes-on-glass coverage, initial triage, handoffs, escalation quality, shared metrics, service improvement, and alignment to the internal SOC operating model. 
  • Implement, evaluate, and govern AI-assisted investigation and response capabilities that improve speed, consistency, evidence quality, and analyst effectiveness. 
  • Ensure appropriate SOC staffing, workload balance, shift handoffs, on-call readiness, and escalation coverage across internal, MSSP-supported, and hybrid operating models. 
  • Define, visualize, and improve SOC KPIs and KRIs through dashboards and recurring reporting that connect operational performance, control effectiveness, risk trends, and business impact. 
  • Mature Microsoft Sentinel capabilities, including analytics rules, KQL, workbooks, automation, playbooks, data connectors, parsing, and cost-aware log ingestion decisions that route high-value telemetry to Sentinel and lower-value or historical data to lake, archive, or cold storage. 
  • Use Microsoft Defender XDR to connect signals across endpoint, identity, email, and cloud app activity, improving incident correlation, advanced hunting, investigation quality, and response speed. 
  • Improve detection quality through false-positive reduction, coverage-gap closure, MITRE ATT&CK alignment, threat intelligence, hunting, validation testing, and purple-team lessons learned. 
  • Establish detection and use-case lifecycle governance, including ownership, documentation, testing, tuning, retirement, and periodic coverage reviews. 
  • Lead, coach, and develop SOC analysts through mentoring, technical reviews, structured training, investigation walk-throughs, tabletop exercises, and hands-on skill development. 
  • Coordinate major incident response, including playbook execution, escalation paths, evidence handling, executive-ready communications, after-action reviews, and response improvement. 
  • Partner with infrastructure, cloud, endpoint, identity, vulnerability management, governance, legal, compliance, privacy, and business teams to improve visibility, control effectiveness, and response readiness. 

Key Competencies for Position  

  • Develops Talent - Advocates for talent development as an organizational imperative and develops people according to talent strategy needs cultivating a diverse succession “pipeline”. Continuously assesses talent across the bank to develop an understanding of capabilities and potential and leverages talent as a corporate resource to meet needs today and into the future. Cultivates an environment of trust and optimizes others' talents and capabilities across the organization, driving a culture of continuous coaching and feedback. Retains, attracts and recruits top diverse talent leveraging opportunistic hires to meet current and future people needs at Old National.  
  • Promotes Change - Explains the business need, impact, and anticipated benefits of the change while engaging stakeholders to gain buy-in. Shapes and transforms culture by building an organizational culture of change agility. Manages risk associated with the change through appropriate contingency planning. Promotes change where it is needed to stay relevant and successful while creating conditions for team members to creatively generate new ways to enhance Old National's ability to succeed.  
  • Strategy in Action - Develops, communicates, and aligns organization with a clear vision and strategy empowering team members to take action. Maintains a strong network of advisors and leverages resources to stay current on emerging trends and market factors that may influence ONB’s strategy. Envisions how Old National's responses to trends may impact our longer-term vision and strategy while formulating a clear strategy that will accelerate ONB towards its strategic goals. Challenges the status quo to develop new ways of thinking encouraging curiosity beyond the current state. Conveys opportunities to realize the organization’s purpose, strategy, and culture in a way that captures attention, arouses emotion and compels others to act despite obstacles.  
  • Compelling Communication - Conveys transparent messages logically, simply, succinctly and at the right pace while being in command of the message. Captivates audience through compelling language tailored to the audience’s expectations and communication style. Checks for understanding and presents messages in different ways to enhance receiver’s understanding. Listens and objectively considers others’ ideas and perspectives while encouraging others to do the same while addressing negative reactions to others’ ideas that jeopardize this open exchange.  
  • Makes Decisions & Solves Problems - Analyzes, contrasts, combines and compares data to define the most relevant organizational problems and opportunities and gain clarity on potential impact. Creates sound strategies by gathering information through listening, deep questions, challenging assumptions and collaborating with networks in and outside of Old National. Aligns efforts and resources around blue chips and formulates decisions on relevant factors (e.g., costs, benefits, buy-in, risks) with the greatest potential for positive impact. Sets strategic direction for short-and long-term goals while remaining agile to adjust plans to close current gaps, modifying priorities as circumstances change.  
  • Delights Clients - Cultivates an environment where team members passionately serve internal/external clients with excellence. Promotes a growth mindset culture by keeping current with development and trends in industry and sharing information to build knowledge base of organization and net promotor score. Understands data, metrics and/or financial information and how they tie to clients, business outcomes, organization and industry. Empowers a culture of accountability across the organization where all team members nurture client relationships by listening, prioritizing, and acting responsibly to meet client needs, mitigate risk and add shareholder value.  
  • Leads Inclusively - Advocates the value of diversity as a competitive advantage and initiates and champions inclusive recruiting and development processes that challenge the status quo, when necessary, to increase diversity in the workplace. Sets up outreach systems and processes that seek ideas, opinions, and insights from diverse sources and while optimizing effectiveness by aligning individuals’ unique talents, interests and abilities with the most relevant roles and responsibilities. Thinks with an inclusive lens promotes inclusion by actively leading DEI initiatives while encouraging all team members to engage in DEI experiences. Demonstrates self-awareness, admits mistakes and seeks feedback from all levels within Old National while acknowledging and challenging bias (conscious and unconscious) and exclusionary behavior.  
  • Personifies ONB Culture - Instills confidence in one’s actions and outcomes consistent with Old National's culture. Promotes the organization’s vision, strategy, and values while recognizing behavior that supports the vision and values. Conveys opportunities to realize the organization’s purpose, strategy, and culture in a way that captures attention, arouses emotion and compels others to take action despite obstacles. Inspires others to personally contribute to the organization’s success for the long term by investing time, heart, and expertise to help clients and communities thrive. 

  

Required Qualifications and Education Requirements 

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent hands-on experience. 
  • 7+ years of hands-on cybersecurity operations experience, including at least 2 years in a SOC manager, SOC lead, or senior/Tier 3 technical SOC role. 
  • Experience managing SOC staffing, coverage models, shift handoffs, on-call expectations, workload distribution, or capacity planning in an internal, MSSP-supported, or hybrid SOC environment. 
  • Experience hiring, onboarding, coaching, and performance-managing SOC analysts or security operations team members. 
  • Strong hands-on experience with Microsoft Sentinel and log pipeline tooling such as Cribl, including KQL, analytics rules, incidents, workbooks, automation, parser development, SIEM tuning, and cost-aware telemetry decisions that shape, filter, enrich, route, and optimize security logs before they reach Sentinel or longer-term storage. 
  • Strong hands-on experience with Microsoft Defender XDR and related Defender products, especially endpoint, identity, email, cloud app, incident correlation, advanced hunting, and response workflows. 
  • Demonstrated ability to build, track, visualize, and improve SOC KPIs, KRIs, dashboards, and operational reporting that show security value, risk reduction, and team effectiveness. 
  • Deep understanding of incident response, security monitoring, telemetry, identity-based attacks, cloud security, malware behaviors, adversary tactics, and the development of playbooks, escalation models, detection logic, threat hunting methods, and analyst enablement materials. 
  • Experience with scripting or automation using PowerShell, Python, KQL, Logic Apps, APIs, or similar tools. 
  • Familiarity with MITRE ATT&CK, threat modeling, cyber kill chain concepts, and mapping detections to adversary behaviors. 
  • Experience managing or partnering with an MSSP, MDR provider, or outsourced SOC function, including service expectations, escalation quality, operational handoffs, continuous improvement, shared metrics, and vendor accountability. 
  • Ability to set clear expectations, prioritize work, hold teams accountable, and create a culture of operational excellence and continuous improvement. 
  • Strong communication skills with the ability to explain technical findings, operational risk, and incident status to technical teams, business stakeholders, and leadership. 

Preferred Qualifications 

  • Experience leading SOC modernization, SIEM migration, Defender XDR rollout, Sentinel detection content lifecycle management, or security automation initiatives. 
  • Experience in financial services, banking, regulated environments, or organizations with mature governance, risk, compliance, audit, and privacy expectations. 
  • Relevant certifications such as CISSP, GCIH, GCIA, GCFA, GNFA, GMON, SC-200, AZ-500, MS-500, OSCP, or equivalent practical experience. 
  • Experience with cloud security across Azure, AWS, or GCP, including cloud logging, identity, workload protection, and incident response. 
  • Experience designing purple-team scenarios, validating detections, and turning exercise results into measurable improvements. 
  • Experience with malware analysis, forensics, endpoint investigation, memory analysis, or advanced incident response techniques. 
  • Knowledge of regulatory and control frameworks such as NIST CSF, NIST 800-53, FFIEC, ISO 27001, PCI DSS, CIS Controls, or related guidance. 

Old National is proud to be an equal opportunity employer focused on fostering an inclusive workplace and committed to hiring a workforce comprised of diverse backgrounds, cultures and thinking styles. 


As such, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, status as a qualified individual with disability, sexual orientation, gender identity or any other characteristic protected by law.


We do not accept resumes from external staffing agencies or independent recruiters for any of our openings unless we have an agreement signed by the Director of Talent Acquisition, SVP, to fill a specific position.


Our culture is firmly rooted in our core values.

We are optimistic. We are collaborative. We are inclusive. We are agile. We are ethical.

We are Old National Bank.  Join our team!

Skills Required

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent hands-on experience
  • 7+ years of hands-on cybersecurity operations experience, including at least 2 years in a SOC manager, SOC lead, or senior/Tier 3 technical SOC role
  • Experience managing SOC staffing, coverage models, shift handoffs, on-call expectations, workload distribution, or capacity planning
  • Experience hiring, onboarding, coaching, and performance-managing SOC analysts or security operations team members
  • Hands-on experience with Microsoft Sentinel, Cribl, KQL, analytics rules, incidents, workbooks, automation, parser development, SIEM tuning, and cost-aware telemetry decisions
  • Hands-on experience with Microsoft Defender XDR and related endpoint, identity, email, cloud app, incident correlation, advanced hunting, and response workflows
  • Ability to build, track, visualize, and improve SOC KPIs, KRIs, dashboards, and operational reporting
  • Deep understanding of incident response, security monitoring, telemetry, identity-based attacks, cloud security, malware behaviors, playbooks, escalation models, detection logic, threat hunting, and analyst enablement
  • Experience with scripting or automation using PowerShell, Python, KQL, Logic Apps, APIs, or similar tools
  • Familiarity with MITRE ATT&CK, threat modeling, cyber kill chain concepts, and mapping detections to adversary behaviors
  • Experience managing or partnering with an MSSP, MDR provider, or outsourced SOC function
  • Ability to set expectations, prioritize work, hold teams accountable, and create a culture of operational excellence
  • Strong communication skills for explaining technical findings, operational risk, and incident status to technical teams, business stakeholders, and leadership
  • Experience leading SOC modernization, SIEM migration, Defender XDR rollout, Sentinel detection lifecycle management, or security automation initiatives
  • Experience in financial services, banking, regulated environments, or organizations with mature governance, risk, compliance, audit, and privacy expectations
  • Relevant certifications such as CISSP, GCIH, GCIA, GCFA, GNFA, GMON, SC-200, AZ-500, MS-500, OSCP, or equivalent practical experience
  • Experience with cloud security across Azure, AWS, or GCP, including cloud logging, identity, workload protection, and incident response
  • Experience designing purple-team scenarios, validating detections, and turning exercise results into measurable improvements
  • Experience with malware analysis, forensics, endpoint investigation, memory analysis, or advanced incident response techniques
  • Knowledge of NIST CSF, NIST 800-53, FFIEC, ISO 27001, PCI DSS, CIS Controls, or related regulatory and control frameworks

Old National Bank Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Old National Bank and has not been reviewed or approved by Old National Bank.

  • Retirement Support Retirement support is positioned as a standout, with a dollar-for-dollar 401(k) match up to 5% and immediate vesting. Auto-enrollment and auto-increase features further strengthen the perceived reliability of retirement benefits.
  • Healthcare Strength Healthcare offerings appear broad and feature-rich, including multiple plan types, HSA contributions for HDHP participants, and access to programs like virtual care and a nurse line. Medical premium discounts tied to wellness and tobacco-free status can meaningfully improve the value of coverage for those who complete the steps.
  • Strong & Reliable Incentives Incentives can provide meaningful upside in revenue-generating roles, with individual incentive structures described as strong in certain lending/commercial positions. Stock purchase access with a discount also adds a supplementary reward mechanism beyond base pay.

Old National Bank Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Evansville, IN
5,373 Employees

What We Do

Old National is a regional bank with substantial assets, based in the Midwest. Our dual headquarters are in Chicago, Illinois, and Evansville, Indiana. Since our founding in 1834, we have kept the heart, culture and DNA of a smaller community bank. We are proud to have strong relationships with our clients and communities and an inclusive work environment that empowers our team members to deliver their best. Our story is reflected in our clients and the communities we support. Hopeful entrepreneurs. First-time homebuyers. Parents and families. Business owners. Retirees. We are every bit as committed as we were in 1834 to exceeding client expectations and strengthening and supporting the communities that we call home.

Similar Jobs

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Senior Claims Adjuster I - Workers Compensation

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Hybrid
5 Locations
40000 Employees
67K-126K Annually

Wipfli Logo Wipfli

Consultant

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
60K-81K Annually

Wipfli Logo Wipfli

Product Owner

Cloud • Fintech • Software • Business Intelligence • Consulting • Financial Services
Remote or Hybrid
United States
2900 Employees
107K-144K Annually

Boeing Logo Boeing

Equity Compensation Administration Specialist

Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
In-Office
Chicago, IL, USA
170000 Employees
162K-219K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software • Productivity
US
15 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account