Cybersecurity Manager - Incident Response and Security Operations

Location

Canada

Posted

3 days ago

Salary

0

Seniority

Lead

Professional Certificate

Job Description

Cybersecurity Manager - Incident Response and Security Operations

Match Group

Title: Cybersecurity Manager (Incident Response & Security Operations) Location: Vancouver, British Columbia Type: Full-time Workplace: hybrid Category: Security Job Description: About the Role As the Manager, IR / SOC, you will lead the integrated team responsible for Detection Engineering, Security Operations Center (SOC), and Incident Response (IR) across Match Group. Reporting to the Sr. Director of Security Engineering, you will drive the strategic vision of maximizing rapid and accurate threat response capabilities by integrating these three core functions and leveraging AI-driven innovation. You will own the detection lifecycle end-to-end — from signal engineering and alert tuning through triage, investigation, and incident resolution — while building toward an AI-augmented SOC model that reduces noise, accelerates response, and scales across a global portfolio. What You'll Do - Lead and develop a high-performing team of SOC analysts, detection engineers, and incident responders operating across multiple time zones with 24/7 coverage - Play a key role in developing the detection engineering framework, contributing to detections-as-code (DaC) via GitOps/CI/CD pipelines for consistency and automated deployment - Drive AI Agentic SOC adoption — evaluate, select, and implement AI-driven triage and investigation tooling to maximize SOC efficiency, reduce false positives, and accelerate initial response speed - Manage the full incident lifecycle — from detection through containment, eradication, recovery, and lessons learned — partnering with Legal, Communications, Privacy, and Engineering teams - Build and refine detection content across the SIEM platform, integrating log sources across all MG brands (Tinder, Hinge, Match, E&E, HPCNT, Eureka, and New Bets) - Establish and track SOC metrics and SLAs, creating dashboards to visualize performance, alert fidelity, and response effectiveness - Coordinate and execute IR tabletop exercises (technical and management-level) across brands to validate readiness and improve playbooks - Partner with the Red Team to validate detection capabilities through adversary simulation and assumed-compromise testing - Collaborate with Platform Security, InfraSec, and AppSec teams to identify and close detection gaps across cloud-native and hybrid environments (AWS, GCP), datacenter infrastructure, endpoints (CrowdStrike), identity (Okta), SaaS, and application layers - Integrate threat intelligence into detection and response workflows to anticipate and proactively defend against emerging threats - Use automation to improve detection and response times and mitigate incident impact What You'll Bring - 5+ years of experience in security operations, incident response, detection engineering, or threat hunting, with 2+ years in a team leadership or management role - Proven experience building and operating a modern SOC in cloud-native and hybrid environments (AWS, GCP) and datacenter infrastructure - Hands-on experience with SIEM platforms and SOAR tools — including detection-as-code methodologies - Strong understanding of AI/ML applications in security operations — agentic SOC, automated triage, and intelligent alert enrichment - Experience managing the full incident lifecycle across complex, multi-brand or multi-tenant environments - Deep knowledge of attacker TTPs (MITRE ATT&CK), endpoint and network forensics, and threat hunting techniques - Experience with cloud security monitoring (AWS CloudTrail, GuardDuty, Security Hub, CloudWatch; GCP Security Command Center), datacenter security, and container orchestration security (Kubernetes) - Familiarity with identity and access security monitoring (Okta, SSO, MFA events) - Experience coordinating with external incident response teams, law enforcement, and cross-functional stakeholders during security events - Polished verbal and written communication skills — ability to communicate clearly during high-pressure incidents and deliver thorough post-incident reports to technical and executive audiences - Relevant certifications are a plus: GCIH, GCFA, GCIA, GSOM, CISSP, or equivalent Nice to Have - Experience with Python-based detections and log analysis in modern cloud-native SIEM platforms - Background in the consumer internet/dating industry or other high-scale B2C platforms - Familiarity with Cloudflare (WAF, Bot Management), CrowdStrike, and SaaS security monitoring (Obsidian or similar) - Experience building or leading a Blue Team volunteer program or cross-functional security response team Why Match Group? Our mission is simple – to help people find love and happiness! We love our employees too and understand the importance of all life's milestones. Here are some of the benefits we are proud to offer: Mind & Body – Medical, mental health, and wellness benefits to support your overall health and well-being Financial Wellness – Competitive compensation, 100% employer match on 401k contributions up to 10% (cap at $10,000), as well as an employee stock purchase program to help you feel supported in your financial security Unplug – Generous PTO and 14 paid holidays so you can unplug Career – Annual training allowance for professional development and ERG membership opportunities and events so you feel connected and empowered in your work Family – Families come in all shapes and sizes so we offer 20 weeks of 100% paid parental leave, fertility, adoption, and child care resources, as well as pet insurance and discounts Company Gatherings – We host company events where our employees get to know each other and build a sense of connection and belonging! We are proud to be an equal opportunity employer and we value the rich dynamics that diversity brings to our company. We do not discriminate on the basis of race, religion, color, creed, national origin, ancestry, disability, marital status, age, sexual orientation, sex (including pregnancy and sexual harassment), gender identity or expression, uniformed service or veteran status, genetic information, or any other legally protected characteristic. Period. If you require a reasonable accommodation to participate in the hiring process — such as during pre-employment testing or interviews — please indicate this by selecting “Yes” in the accommodation request field.

Related Categories

Related Job Pages

More Security Operations Jobs

Target logo

Lead Engineer – Network Security Monitoring

Target

An industry-leading retailer with corporate headquarters in Minneapolis, Minnesota, Target operates over 1,800 stores in 47 states, as well as several distribut

• ensure Cybersecurity visibility requirements are being met through collaboration with Target’s broader Network Engineering organization • be working closely with Cybersecurity stakeholders to develop and continually improve our visibility posture so network-based threats can be detected

Minnesota
$132K - $238K / year
Eclipse Foundation logo

Intermediate SecOps Engineer

Eclipse Foundation

The Community for Open Innovation and Collaboration

Full TimeRemoteTeam 11-50Since 2004H1B No Sponsor

• Develop, maintain, and improve detection rules, alerts, dashboard, and monitoring workflows across infrastructure, cloud services, identity systems, endpoints, and application platforms. • Participate in incident response activities, including triage, investigation, containment, remediation coordination and post-incident analysis. • Operate and improve security monitoring tooling, including SIEM, log aggregation, alerting, vulnerability management, and related detection and response platforms. • Proactively investigate suspicious activity, anomalous behavior, and emerging threats affecting infrastructure and services. • Create and maintain incident response playbooks, escalation procedure, actionable security guidance, and operational documentation to cloud operations, product development, and systems engineering teams. • Collaborate with the systems engineering team to identify and remediate security weaknesses in cloud, container, Linux, network, identity, and service configurations. • Actively participate in comprehensive disaster recovery planning, business continuity strategy formulation, and live simulations/exercises to validate system resilience and team readiness.

Belgium
€50K - €75K / year
Nelnet logo

AI SecOps Engineer

Nelnet

Follow and catch a glimpse of what #LifeAtNelnet is like.

Full TimeRemoteTeam 5,001-10,000Since 1996H1B Sponsor

• Own the working relationship with CSG on data residency, PII handling, access governance, and model security controls • Translate policy into guardrails the delivery team and citizen developers can act on • Build and maintain security tooling, guardrail enforcement, and policy-as-code integrations across Enterprise AI platforms • Reduce manual review through automation where possible • Develop reusable security components and patterns that delivery teams and citizen developers can drop into Agent builds—making the secure path the easy path • Instrument AI platforms to detect anomalous behavior, access patterns, and policy violations • Build the detection layer, not just consume it

Nebraska
$100K - $150K / year
Optum logo

Security Platform Detection Engineer

Optum

Optum, part of the UnitedHealth Group family of businesses, is a global organization that delivers care, aided by technology to help millions of people live healthier lives. The work you do with our team will directly improve health outcomes by connecting people with the care, pharmacy benefits, data and resources they need to feel their best. Here, you will find a culture guided by inclusion, talented peers, comprehensive benefits and career development opportunities. Come make an impact on the communities we serve as you help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. At Optum, we support your well-being with an understanding team, extensive benefits and rewarding opportunities. By joining us, you’ll have the resources to drive system transformation while we help you take care of your future. We recognize the power of connection to drive change, improve efficiency and make a difference in health care. Join a team where your skills and ideas can make an impact and where collaboration is key to creating technology that produces healthier outcomes.

Full TimeRemoteTeam 160,000Since 2011

Requisition Number: 2365239 Security Platform & Detection Engineer Are you an experienced security engineering professional looking to take the next step and make an impact within our Security Operations team? Do you thrive in an environment where you're empowered to innovate, challenge ideas, and create meaningful change? If so, then I encourage you read on. About the Team / Business Area: The Security Operations team operates within a fast-paced and highly regulated healthcare technology environment, protecting nationally critical systems that support frontline healthcare delivery. The team provides services including Security Operations Centre (SOC) oversight, vulnerability management, attack surface management, and continuous monitoring across enterprise, cloud, and network environments. Our work ensures security controls remain effective, resilient, and aligned to real-world threats and patient safety priorities. About the Role: This role is an exciting opportunity to join our Security Operations team as a Security Platform & Detection Engineer, where you will own and optimise our security tooling and detection capability. You will work closely with the SOC, Security Engineering, and Architecture teams to ensure tooling is effective, governed, and aligned to evolving threats. This position is central to delivering high-quality, measurable, and auditable security outcomes across the organisation. Key Responsibilities:• Own BAU administration, configuration, and lifecycle management of security tooling platforms• Provide oversight of detection engineering, improving alert quality and reducing false positives• Enforce change control and governance for tooling and detection updates• Maintain threat framework mapping (MITRE ATT&CK) and detection coverage analysis• Drive continuous improvement and optimisation across security tooling estate Who You Are: You will be a proactive, experienced, and innovative security professional with a background in security engineering or detection engineering. You'll thrive in a dynamic environment, balancing deep technical expertise with strong communication and problem-solving skills. You're someone who enjoys working collaboratively while taking ownership of meaningful work that drives real impact. Key Skills, Experience & Qualifications:• 5+ years experience in Security Engineering, Tooling, or Detection Engineering roles• Hands-on experience with SIEM, EDR, NDR, or security posture tooling• Experience building, tuning, and governing detections• Experience working within structured change control and governance frameworks• Working knowledge of SIEM operations including log onboarding and alert triage Take the next step in your career with us If this sounds like the right next step for you, we'd love to hear from you. If you have any questions about the role or would like an informal conversation before applying, please reach out to the hiring manager for a quick chat. We look forward to receiving your application. -

United Kingdom