MedPro Group’s mission is built on a century-old legacy of protecting those who protect others. From our roots in our hometown of Fort Wayne, Indiana, we've worked diligently to become the nation's premier healthcare liability coverage provider, currently insuring more than 300,000 customers. With that growth, we've built a significant presence in all 50 states. Our team works across the country to provide the best strategies to mitigate risk and preserve the reputations of those who have entrusted their good name to us. That passion – built on a foundation of a culture that values uncompromised integrity, obsessive client focus, great teamwork, and a long-term mindset – make MedPro a preferred employer that many call their career home. General: MedPro Group is an Equal Opportunity Employer. The annual gross base salary range is $93,040 to $130,000. This range anticipates the low and high end of the salary for this position. Actual salaries will vary and are based on factors such as a candidate’s qualifications, skills and competencies. Salary is one component of MedPro’s total compensation and benefits package. For a more detailed overview, visit our careers website at www.medpro.com/careers.
IT Security Operations Center Manager
Location
United States
Posted
7 days ago
Salary
$140K - $170K / year
Seniority
Lead
No structured requirement data.
Job Description
IT Security Operations Center Manager
MedPro Group
Role Description We are seeking a Security Operations Center Manager who will lead and mature our 24x7 cybersecurity threat detection and response processes, procedures, and strategy, manage and provide oversight for the team of analysts and associated vendors, and other various cybersecurity operations responsibilities. The role will also support the Deputy Chief Information Security Officer (Deputy CISO) in defining controls and governance for the overall corporate cybersecurity strategy with a focus on: - Incident response - Logging & analysis - Regulatory compliance - Ongoing defense & detection hardening of the various on-prem and Cloud technologies utilized by the enterprise In this role, you will… - Lead the 24x7 incident detection and response team and day-to-day efforts. - In the event of a breach, lead efforts with detection, containment, and mitigation as well as aid the corporate response team (General Counsel, HR, Marketing, etc.) as needed. - Update and maintain the Incident Response Plan's processes and procedures to keep current with industry best practices, regulatory requirements, and the threat landscape. - Lead efforts in ongoing tabletop and red/blue team exercises to continue implementing better defenses and quick incident detection and response. - Research and understand the regulatory and compliance mandates to ensure cybersecurity practices fulfill these requirements. - Lead efforts with external and internal audit control compliance and responses to due diligence inquiries. - Review industry news, intelligence reports, and emerging technologies to ensure MedPro is taking the proper action to mitigate risk and improve defenses. - Provide recommendations and assistance with developing short and long-term enterprise-wide cybersecurity goals and objectives. - Assist with security assessments and help provide recommendations on applications, vendor, and business & technical team processes and practices used by MedPro. - Work closely with and provide support to the cybersecurity technical team. - Assist with the execution and completion of cybersecurity related projects. - Perform other related duties. Qualifications - Bachelor's degree in computer science, computer engineering, information technology with a focus on cybersecurity, or relevant field. - Seven years of management and industry experience or ten years of management and relevant cybersecurity related experience. - A thorough understanding of cybersecurity defense hygiene and industry best practices (like MITRE ATT&CK tactics) and risk management frameworks (like NIST, COBIT, or OCTAVE). - Strong knowledge of financial services cybersecurity regulations and controls. - Significant experience leading security incident response activities (including detection, analysis, containment, response, and prevention procedures). - Experience with building, defining, and leading 24x7 SOC teams and efforts. - Experience with vendor contracting and management. - A thorough understanding of Cybersecurity attack and defense methodologies. - Ability to work independently, while reporting back to team leader/manager on any issues or concerns in a timely fashion. - Excellent learning, teamwork, relationship management, influence, and creativity skills. - Excellent customer service skills. - Excellent oral and written communication skills. Benefits - Medical, vision, and dental insurance options - Life and accident insurance - 401(k) - Short-term and long-term disability insurance Company Description MedPro Group’s mission is built on a century-old legacy of protecting those who protect others. From our roots in our hometown of Fort Wayne, Indiana, we've worked diligently to become the nation's premier healthcare liability coverage provider, currently insuring more than 300,000 customers. With that growth, we've built a significant presence in all 50 states. Our team works across the country to provide the best strategies to mitigate risk and preserve the reputations of those who have entrusted their good name to us. That passion – built on a foundation of a culture that values uncompromised integrity, obsessive client focus, great teamwork, and a long-term mindset – makes MedPro a preferred employer that many call their career home.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Develop and deliver security reports and metrics to support operational awareness and leadership decision-making. • Identify and support mitigation of information security risks, including evaluating projects and initiatives for alignment with security requirements, policies, and standards. • Support internal and external audits by collecting and analyzing evidence, assessing control effectiveness, and ensuring adherence to established security frameworks and policies. • Track and manage remediation activities, including corrective action plans and audit findings, ensuring timely resolution of identified security issues. • Identify, investigate, and respond to security incidents, including analyzing root cause and impact to contain threats and reduce organizational risk. • Maintain and support security tools, controls, and monitoring capabilities to ensure effective detection and response. • Develop, implement, and continuously improve threat-informed detections and automated response playbooks, including use case development, rule creation, tuning, validation, and optimization through incident feedback and testing. • Monitor systems and security telemetry for violations, vulnerabilities, and anomalous activity. • Analyze and apply threat intelligence to enhance detection, response, and situational awareness. • Identify and support onboarding and validation of security telemetry to ensure effective detection and visibility. • Collaborate with cross-functional teams to support incident response, remediation, and security improvements. • Assist in the evaluation and selection of security technologies and solutions to support detection, monitoring, and response capabilities.
• Oversee 24/7 monitoring, triage, and escalation of OT security alerts across industrial environments • Support complex incident investigations and ensure quality of analysis across all tiers • Ensure adherence to SLAs, ticket quality, and operational KPIs • Lead and manage a team of OT SOC analysts (Tier 1 / Tier 2) • Provide coaching, mentoring, and performance feedback • Support shift planning, coverage, and handovers • Drive improvements to detection rules, playbooks, and SOC procedures • Identify gaps in monitoring, response, and tooling • Collaborate with engineering and threat detection teams for tuning and optimisation • Act as a key point of contact for customers during incidents and escalations • Ensure proper communication during major incidents • Support reporting, service reviews, and customer discussions • Coordinate with internal teams (engineering, IR, service delivery)
Security Operations Manager
Aya HealthcareAya Healthcare has provided travel nurse staffing solutions for thousands of medical facilities since 2001. The largest travel nurse provider in North America, the company offers s
• You will report to the VP, Information Security. • Own the execution and continuous improvement of Aya Healthcare’s enterprise Security Operations program. • Lead a blended security operations model combining internal analysts, nearshore/offshore resources, and managed service providers. • Establish clear operating models, escalation paths, staffing coverage expectations, and accountability across all SecOps resources. • Serve as the primary owner of ServiceNow Security Incident Response (SIR) workflows, data models, and operating procedures. • Design, implement, and continuously improve SIR playbooks to automate triage, enrichment, containment, and response actions. • Drive automation that reduces manual analyst effort and improves MTTD, MTTR, and MTTC through standardized playbook execution. • Ensure incidents are consistently triaged, investigated, documented, and remediated using ServiceNow SIR. • Oversee detection and response capabilities across EDR and SIEM platforms, ensuring high-quality signal ingestion and routing into SIR. • Operate confidently across Microsoft Azure security capabilities available through Microsoft E5 environments (e.g., Defender, Sentinel). • Define, track, and improve MTTx metrics, using data to prioritize automation and process improvements. • Lead post-incident reviews and ensure lessons learned translate into improved detections, playbooks, and response procedures. • Manage, coach, and develop security operations personnel while fostering a high-energy, accountable team culture. • Act as a trusted escalation point during security incidents and clearly communicate operational risk and response status to leadership.
• Operate and tune enterprise security tools (EDR, SIEM/SOAR, WAF/proxy, email security). • Manage proxy filtering policies, exceptions, SSL inspection, and performance troubleshooting. • Build automation and playbooks (Python/PowerShell, SOAR, APIs) to streamline SecOps tasks. • Implement CI/CD pipelines and Infrastructure-as-Code workflows for consistent, auditable security configuration changes. • Author and tune detection rules; improve signal quality and reduce false positives. • Maintain and author health dashboards, uptime/coverage metrics, and change governance documentation. • Conduct knowledge transfers through runbooks, how-to guides, tabletop exercises, and lunch & learn training sessions. • Maintain upgrade schedules, license compliance, configuration baselines, and key/secret rotations. • Administer URL/category policies, SSL inspection, identity-aware policies, geo/risk-based controls, and performance troubleshooting. • Analyze block events for false positives; measure impact; retire exceptions on schedule and report residual risk. • Build and maintain an automation backlog in partnership with SecOps, prioritizing high-frequency, high-toil tasks. • Provide on-call support for tooling availability and ingestion/normalization issues. • Report on metrics (uptime, coverage, MTTR, lead time, change success rate, exception aging). • Keep documentation, diagrams, and asset inventories current. • As needed, monitor and respond to alerts raised by various toolsets as part of an ongoing 24/7 Security Operations Center. • Report outages or incidents following guidelines and procedures. • Detect, analyze, and respond to incidents, coordinate with other stakeholders for containing, eradicating, and recovering from an incident. • Assist in developing testing criteria to implement new signatures/rules. • Participate in on-call rotations, including nights, weekends, and holidays.



