IT Operations – Security Manager
Location
Romania
Posted
6 days ago
Salary
0
Seniority
Senior
Job Description
IT Operations – Security Manager
AMS Accelerate IT
• Run day-to-day IT operations for a remote, globally distributed team • Own onboarding and offboarding end-to-end • Maintain asset inventory, software license hygiene, and vendor relationships • Identify repetitive IT workflows and automate them • Maintain Transcenda’s SOC 2 Type II program • Keep IT-side security baselines current • Respond to client security reviews, questionnaires, and due-diligence requests • Communicate changes in IT and security posture clearly
Job Requirements
- 5+ years in IT operations or IT security
- 2+ years leading an IT Support team
- Hands-on experience running IT for a remote workforce
- Google Workspace administration, SSO, VPN, endpoint protection
- Mac fleet management via MDM (Jamf, Kandji, Mosyle, or equivalent)
- Experience owning onboarding/offboarding, access management, and asset/licensing processes
- SOC 2 Type II maintenance - evidence collection, control upkeep, annual audit prep
- Fluent English; comfortable responding to client security questionnaires
Benefits
- Health insurance
- Flexible work arrangements
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
• Monitor SIEM/XDR/SOAR and other telemetry for alerts, anomalies, and indicators of compromise (IOCs). • Perform Level 1–2 triage, enrichment, scoping, and prioritization of events. • Execute response playbooks (isolation, containment, account/device quarantine, EDR actions, network blocks). • Lead or support incident investigations (forensics acquisition, timeline analysis, root cause). • Document incidents thoroughly (IR tickets, evidence handling, post-incident reports). • Conduct proactive hunts using hypotheses tied to current TTPs (e.g., MITRE ATT&CK). • Draft, test, and deploy high-fidelity detections and correlation rules; reduce alert noise. • Operationalize threat intel (IOCs, behavioral analytics) into monitoring and detections. • Track and respond to emerging threats and vulnerabilities impacting our stack. • Maintain shift logs, knowledge base updates, runbooks, and handoffs. • Support deployment, configuration, and maintenance of SIEM/XDR/SOAR, IDS/IPS, E-mail security, WAF, CASB, DLP, PAM, and endpoint security platforms. • Build and maintain data sources, parsers/normalization, health checks, and content packs. • Implement security baselines, hardening guides, and secure configurations across endpoints, servers, cloud, and network devices. • Integrate cloud telemetry (AWS/GCP/Azure), identity signals (Entra ID/Okta/AD), and SaaS logs into monitoring with robust detections.
• Lead and oversee 24x7 SOC operations, including internal teams and/or managed security partners. • Own threat detection, triage, investigation, and response processes. • Drive improvements in mean time to detect (MTTD), mean time to respond (MTTR), and incident response maturity. • Define and operationalize SIEM/SOAR use cases, playbooks, and automation. • Ensure effective monitoring across endpoints, cloud, identity, and network layers. • Coordinate incident response with internal teams, legal, compliance, and external partners. • Lead post-incident reviews and continuous improvement programs. • Develop SOC metrics, dashboards, and executive reporting. • Own the enterprise IAM program, including identity lifecycle processes for joiners, movers, and leavers. • Drive role-based access control (RBAC) and least-privilege enforcement. • Implement and manage Privileged Access Management (PAM/PIM). • Oversee MFA, SSO, conditional access, and authentication standards. • Lead access governance, certification campaigns, and audit readiness.
• Monitor global systems for potential threats, vulnerabilities, and indicators of compromise. • Perform in-depth analysis of security alerts utilising both NCC Group's UCP and explore further using the underlying detection platform where necessary. • Provide incident remediation and prevention documentation and recommendations to customers based on defined procedures and analyst experience. • Document and adhere to processes related to security monitoring procedures. • Provide customer service that always exceeds our customers’ expectations. • Initiate escalation procedures to counteract potential threats, vulnerabilities, and threat actors. • Compile and review service-focused reports. • Act as an escalation point for junior team members, aiding and mentoring where necessary. • Contribute to the continuous improvement of SOC procedures and documentation. • Perform other SOC duties as assigned.
• Triage and Investigation: Lead investigations into complex security alerts utilising Splunk, Microsoft Sentinel, and SentinelOne SIEMs. • Endpoint Response: Execute rapid containment and remediation actions using CrowdStrike Falcon, Microsoft Defender for Endpoint, and SentinelOne EDR. • Detection Tuning: Optimise detection rules using KQL and SPL to enhance our proactive defence posture. • Threat Hunting: Support regular threat hunting activities based on the MITRE ATT&CK framework to uncover hidden malicious activity. • Reporting & Mentorship: Produce detailed incident reports for technical and executive stakeholders. • DLP: Understand data-loss prevention in the context of Security Operations. • On-call: Participate in paid on-call roster every 3 weeks.



