SOC Manager

Posted 11 Hours Ago
Be an Early Applicant
Miramar, FL, USA
In-Office
Senior level
Information Technology • Software • Consulting • Cybersecurity
The Role
Manage UDT’s 24x7x365 security operations center and managed detection and response delivery. Lead SOC supervisors, analysts, and dispatchers; oversee incident detection, investigation, escalation, containment coordination, playbooks, on-call coverage, partner governance, detection tuning, MITRE ATT&CK coverage, SLAs, metrics, customer reviews, compliance, and team development. Serve as the senior escalation point for high-severity incidents and primary SOC contact for clients and leadership.
Summary Generated by Built In

UDT is a national technology solutions provider that modernizes, connects, secures, and manages technology environments for commercial enterprises, state and local governments, and educational institutions. The trusted advisor to many of the nation’s top K-12 school districts and corporate leaders across a spectrum of industries including hospitality, health care, financial services and more – UDT offers one of the most robust suites of customizable, end-to-end technology solutions in the industry. With a portfolio that spans IT managed services, endpoint lifecycle solutions, cybersecurity, networking, computing, cloud, connectivity, and voice services, UDT helps clients align technology with their most important business priorities – empowering insight-driven IT strategies that accelerate innovation, streamline costs, and reduce risk. Founded in 1995 and headquartered in Miramar, Florida, UDT has more than 400 professionals nationwide and growing operational facilities in Florida, Tennessee, Texas, and South Carolina. For more information, visit udtonline.com.

This position is remote but must be located in one of the following states:  Florida, North Carolina, South Carolina, Georgia, Arkansas, Missouri, Oklahoma, Texas, Tennessee.

SOC Manager


The SOC (Security Operations Center) Manager is responsible for the strategic and day-to-day operational management of UDT’s 24x7x365 SOC, ensuring effective monitoring, detection, investigation, and response to cyber threats across client and internal environments. The SOC Manager leads a team of SOC Supervisors, Analysts (Levels 1, 2, and 3), and dispatchers, providing the leadership, structure, and process discipline required to maintain a reliable and continuously improving managed-security operation.

This role holds operational ownership of UDT’s managed detection and response (MxDR) delivery. It sits between the per-account Service Delivery Managers (SDMs) and senior leadership within the escalation chain, and is accountable for ensuring that SOC operations run on documented playbooks and defined on-call rotations rather than on individual knowledge or availability.

The SOC Manager collaborates closely with UDT’s Help Desk; Governance, Risk and Compliance (GRC) Team; Professional Services Cyber Security Team, which commands major-incident response; the NOC, which executes infrastructure containment; and UDT’s delivery partners and SIEM/SOAR platform providers, ensuring all security operations align with client SLAs, contractual obligations, and regulatory requirements.

UDT is seeking an experienced, hands-on security operations leader to assume operational ownership of the SOC. The successful candidate will demonstrate:

  • Direct technical engagement. Comfortable working within the toolset (Huntress, Google Chronicle, CrowdStrike, ConnectWise) — producing reports, extracting metrics, and authoring playbooks personally. This is a working management position rather than a purely supervisory one.
  • The ability to operate independently. A record of taking ownership of an objective and executing it with limited day-to-day direction.
  • An improvement orientation. Experience assessing an established operation objectively, applying industry best practices, and strengthening operational discipline.
  • Customer-facing composure. Skill in conflict resolution and in conducting client conversations with professionalism and credibility.
  • Audience-appropriate communication. Able to engage in technical depth with analysts, engineers, and partners, and to present the same material to executive and client audiences in business terms. Strong written and verbal English is required, including the ability to independently produce clear, professional correspondence and reports.

Responsibilities:

SOC Operations Management:

  • Lead and manage the daily operations of the 24x7x365 SOC, ensuring timely detection, triage, investigation, and response to security events across all delivery paths.
  • Supervise and develop the SOC team — Supervisors, Analysts (Levels 1, 2, and 3), and the dispatcher pool — providing direction, coaching, and accountability.
  • Own the escalation matrix and serve as the standing intermediate tier within the UDT escalation chain (SDM to SOC Manager to senior leadership), ensuring escalations follow a defined path.
  • Maintain and refine incident-response playbooks, standard operating procedures (SOPs), runbooks, and escalation protocols so that response procedures are documented, repeatable, and independent of any individual.
  • Ensure the SOC operates in accordance with UDT security policies, contractual scope, and client SLAs.

Coverage, Shift Discipline, and On-Call:

  • Establish and own a defined, rotating, documented on-call tier so that after-hours and weekend escalation follows a published rotation. 
  • Establish a formal shift-handoff process at each shift overlap — a structured written and verbal pass of open incidents, watch items, pending customer callbacks, and in-flight investigations, logged in ConnectWise — to maintain continuity across the shift overlaps (Shifts 1, 2, and 3) and at the UDT-partner boundary.
  • Define and enforce after-hours coverage standards, ensuring overnight and dispatcher coverage follows documented response procedures rather than automated notification alone.

Incident Detection and Response:

    • Oversee all phases of incident management — detection, triage, investigation, containment, and post-incident review — across UDT’s detection stack:
    • Huntress (Managed EDR/MDR/ITDR — Ransomware Canaries, Persistent Footholds)
    • Google Chronicle (SIEM, SOAR, and threat-intelligence plane)
    • CrowdStrike (alternate endpoint MDR engine), Microsoft Defender (managed endpoint telemetry), Datto SIRIS (backup and disaster recovery), and KnowBe4 (security awareness)
  • Act as the senior point of escalation for high-severity incidents, coordinating the SOC, NOC, PS Cyber, the customer, and, where engaged, legal and executive leadership.
  • Operate within UDT’s defined control boundaries:
  • Infrastructure containment follows a SOC-to-NOC handoff — the SOC raises the ticket and the NOC executes — managed to avoid delay at the handoff.
  • Major-incident response command resides with PS Cyber. The SOC detects, confirms true-positive status and indicators of compromise, and provides support.
  • Support the adoption of pre-authorized emergency incident-response authorization so that containment of a confirmed breach is not delayed pending contractual approval.
  • Ensure breach-notification requirements — for example, contractual 24-hour written notification for regulated accounts — are tracked and met, escalating legal determinations to counsel.

Partner and Vendor Operational Governance:

  • Assume operational ownership of UDT’s co-delivery and managed-SIEM partner relationships, including participation in partner quarterly business reviews with a UDT-maintained coverage, escalation, miss-rate, and SLA scorecard, and governance of the UDT-partner handoff.
  • Manage the operational fit of SOC subcontractors and partners with respect to coverage, shift, and escalation. Cost decisions route to Finance.
  • Evaluate detection and response tooling for operational effectiveness and recommend stack changes to SecOps.

Detection Coverage and Tuning Quality:

  • Build and maintain a single, UDT-owned, validated MITRE ATT&CK coverage baseline spanning the Huntress and Chronicle paths, including customer-tenant Sentinel, mapped to ingested log sources, with gaps ranked and tracked.
  • Maintain a detection-tuning and false-positive backlog feeding the SIEM/SOAR platform and governing tool-direct alert volume. Detection quality is addressed through tuning; alert suppression is not an acceptable substitute.
  • Partner with the SIEM/SOAR platform’s detection-engineering function — parser and UDM mapping, use-case authoring, and detection scoring — so that UDT’s coverage view consumes those outputs rather than duplicating them.

SLAs, Metrics, and Reporting:

  • Maintain outcome-based SLAs and SLOs. MTTA, MTTD, and MTTR are measured against the defined, severity-based classification-completion clock, including the 60-day Service Alignment Phase and documented pause states.
  • Own the monthly Customer Service Review (CSR) and quarterly business review (QBR) cadence: coverage assessment, MITRE use-case coverage, alert breakdown, and gap reporting via UDT HUB, ARMED, and Smart Analytics.
  • Report metrics that accurately reflect risk reduction and response performance, including known gaps.

Team Development and Mentorship:

  • Provide leadership, mentorship, and career development for the SOC team; conduct performance reviews and identify training and certification paths.
  • Partner with Human Resources on role standards and professional development plans to build out the Level 1 to Level 2 to Level 3 analyst progression and senior-bench depth. Indicative certification path: Security+, CrowdStrike Falcon, BTL1, MITRE ATT&CK, and CySA+, advancing toward CISSP, CISM, or GCIH for senior roles.

Compliance and Stakeholder Engagement:

  • Ensure SOC activities align with applicable frameworks and regulations across the client base, including NIST, ISO 27001, CIS, MITRE ATT&CK, HIPAA, PCI-DSS, and GLBA for regulated accounts, and others as contracted.
  • Serve as a primary SOC point of contact for senior leadership and clients regarding SOC performance, the threat landscape, and incidents.

Other:

  • Enter time and all work — activities, service tickets, and project tickets — into the ConnectWise Manage PSA as it occurs.
  • This position is based at UDT’s headquarters in Miramar, FL and follows a hybrid schedule; occasional travel to customer sites may be required.
  • Other duties related to the scope of the department and the business may be assigned.

Education and Experience:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field; master’s degree preferred.
  • Seven or more years in security operations, including at least three years in a SOC leadership or management role.
  • Demonstrated experience managing SOC teams and directing high-severity incidents in a fast-paced, multi-client MSSP or MSP environment.
  • Experience operating a co-delivery or partner-fronted MDR model (managed SIEM and EDR delivered through partners) is strongly preferred.

Technical Skills:

  • Working fluency with a modern MDR stack: EDR and MDR platforms (Huntress, CrowdStrike, Microsoft Defender); SIEM and SOAR platforms (Google Chronicle, or comparable platforms such as Microsoft Sentinel or Splunk); and ticketing and PSA-driven escalation. Familiarity with ConnectWise Manage is a strong plus.
  • Strong command of incident management, threat intelligence, forensic fundamentals, and vulnerability-management processes.
  • Working knowledge of MITRE ATT&CK as a coverage-design and validation discipline.
  • Understanding of cybersecurity frameworks and regulatory regimes, including NIST, ISO 27001, HIPAA, PCI-DSS, and GLBA.

Certifications:

  • Manager-level security certification required or strongly preferred: CISSP or CISM.
  • Governance, risk, and audit credentials, one or more strongly preferred: CISA or CRISC.
  • Hands-on detection and incident-response credentials, one or more a plus: GCIH, GCIA, GIAC, or CEH.
  • Baseline expected: CompTIA Security+ or CySA+.
  • Operational excellence, a plus: ITIL Foundation and a process-improvement credential such as Lean Six Sigma (Green Belt or above).

Soft Skills:

  • Strong leadership and team-building skills, with the ability to motivate and develop a diverse, multi-tier SOC team.
  • Sound judgment under pressure during high-severity incidents.
  • Clear communication of complex technical matters to technical, non-technical, executive, and client audiences.
  • Strong organizational and prioritization skills in a 24x7, multi-client environment.

Required Knowledge, Skills, and Abilities:

  • Cross-functional leadership, with the ability to lead and achieve results with a strong customer orientation.
  • Strategic planning across a 6- to 12-month horizon, with the discipline to operationalize the plan.
  • Excellent written and verbal communication, including the ability to translate technical issues into business terms.
  • Self-directed, results-driven, detail-oriented, and accurate, with the ability to manage multiple priorities concurrently.
  • Proficiency with Microsoft Office and the ability to develop reports, recommendations, and executive and client presentations.

What UDT offers you 

We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to the organization. UDT’s Total Rewards package includes medical, dental, vision, life and disability coverage as of the 1st of the month, health savings accounts, flexible savings accounts, 401(k) plan with company match, 7 annual holidays and unlimited paid time off options.

Join us and be part of an inclusive, energizing, and collaborative environment. UDT is an Equal Opportunity Employer who is committed to workforce diversity. Qualified applicants will receive consideration without regard to age, race, color, religion, sex, sexual orientation, disability, or national origin. In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Employment is contingent upon successful completion of background and pre-employment drug screen. UDT is not currently hiring individuals for this position who now or in the future require sponsorship for employment visa status

Skills Required

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field
  • Seven or more years of experience in security operations
  • At least three years of SOC leadership or management experience
  • Experience managing SOC teams and directing high-severity incidents
  • Experience in a multi-client MSSP or MSP environment
  • Working fluency with EDR/MDR platforms, SIEM/SOAR platforms, and ticketing or PSA-driven escalation
  • Strong command of incident management, threat intelligence, forensic fundamentals, and vulnerability-management processes
  • Working knowledge of MITRE ATT&CK
  • Knowledge of cybersecurity frameworks and regulations including NIST, ISO 27001, HIPAA, PCI-DSS, and GLBA
  • Manager-level security certification such as CISSP or CISM
  • CompTIA Security+ or CySA+ certification
  • Master’s degree
  • Experience operating a co-delivery or partner-fronted MDR model
  • CISA or CRISC certification
  • GCIH, GCIA, GIAC, or CEH certification
  • ITIL Foundation or Lean Six Sigma Green Belt or above
  • Familiarity with ConnectWise Manage
  • Ability to work from one of the specified states and comply with the stated hybrid schedule
  • Strong written and verbal English communication skills
  • Proficiency with Microsoft Office and ability to develop executive and client presentations
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Miramar, Florida
624 Employees
Year Founded: 1995

What We Do

UDT is a technology enabler that helps clients in major industries evaluate, architect, provide, secure, and manage technology on the go, in the rack and in the cloud. UDT provides flexible and interoperable services, including mobility, cloud, collaboration, data, cyber security and software and IT as a service. The company also provides technical, professional and managed services. Accomplish more with UDT. Our purpose and passion is to radically energize our clients’ performance, mitigate their technology risk and speed time to value. We exist to create seamless experiences and competitive advantages for enterprises investing in their future. In our impassioned focus to deliver high value for our clients, we are a team driven by smart business sense, critical thinking, unconventional problem-solving, hard work, and old-fashioned ethics. When we say the client comes first, those aren’t just empty words: we prioritize you and build long-term relationships based on trust, results and the relentless pursuit of excellence. We understand that you need to invest in technology to meet your specific business needs – and that means having the right level of skills to ensure that technology is put in place so that it delivers what it was intended to deliver. Our comprehensive services and solutions will assist your IT teams with the successful implementation of your technology. We have the consulting skills and technical expertise to deliver end-to-end, multivendor solutions across your entire enterprise. We are privileged to offer transformational solutions that: clients adopt to advance their missions; partners recognize as industry leading; employees are proud of; community benefits from.

Similar Jobs

In-Office
2 Locations
5075 Employees

Cloudflare Logo Cloudflare

Product Marketing Manager

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
10 Locations
4400 Employees
148K-234K Annually

Samsara Logo Samsara

Senior Product Manager

Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Easy Apply
Remote or Hybrid
United States
4000 Employees
131K-220K Annually

Pluralsight Logo Pluralsight

Sr. Manager, Revenue Operations

Edtech • Information Technology • Software
Remote or Hybrid
USA
1000 Employees
122K-160K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account