Cybersecurity Security Operations Center Manager
Company: The Sherwin-Williams Company
Location: Cleveland
Posted on: June 1, 2025
Job Description:
The Cybersecurity Security Operations Center (CSOC) Manager's core
function is to provide leadership and oversee the administration of
the CSOC, including security engineers and security analysts. The
CSOC is responsible for monitoring and alerting on cybersecurity
events, ensuring the maintenance of the current and future
technologies, and continually analyzing threat data to find ways to
improve the organization's security posture. This position requires
both the ability to tactically focus on immediate threats at hand
as identified in alerts and intelligence as well as strategically
remain focused on Initiatives tasked by senior leadership.
Candidates must be highly analytical, technically competent, and
have an ability to provide focus and calm during incident response
scenarios. The ability to lead groups or move forward initiatives
is essential. In addition, the ability to plan for future team
needs requires staying informed of current events in technology
platforms and the Cybersecurity industry.
Operational Management
- Manage team employees reporting directly to you.
Responsibilities include preparing midyear and annual staff
evaluations and addressing both opportunities for growth (such as
promotions) or improvement (such as employee performance
improvement plans) as performances warrant.
- Manage the on-call rotation and time off for the SOC
- Providing regular training sessions and mentorship
opportunities to facilitate knowledge-sharing within the
team.
- Hiring new staff members or contracting outside services to
supplement your team's capabilities when needed.
- Responsible for vendor management - existing and future
contractual relationships with technology and service providers.
This includes working to address support issues, contract renewals
/ discrepancies, bi-weekly meetings, Quarterly Business Reviews,
etc.
- Track tool performance / utilization to measure return on
investment and support future evaluation / rationalization
needs.
- Responsible for identifying tool / service evaluation
opportunities. Working closely with the Security Threat
Architect.
- Responsible for day-to-day CSOC budget management
- Lead your team and communicate with management during incident
response (IR) to ensure timely notification and containment occur.
Responsibilities include ensuring communicating, documenting IR
progress, and following through with post-mortem reviews.
- Ensure CSOC meets regulatory compliance of both internal and
external auditors by adherence to policies and procedures. Ensure
version control of SOC alerts as well as least privilege access to
logs and investigation data.
- Ensure synchronization and collaboration between the CSOC and
Cyber Threat Intelligence team.
- Work with other departments to identify the root causes of
security incidents and develop strategies to mitigate these
risks.
Strategy & Planning
- Work with employees on Individual Development plans. Interface
with management and Human Resources to ensure plans meet business
needs and provide measurable advancement steps to employee
promotion and realization of career goals.
- Responsible for building and briefing at the monthly Governance
Board meetings for existing or future spend as
appropriate.
- Responsible for planning and prioritizing annual spend for CSOC
in support of Operational Plan Development and advising upper
management on budget forecasting.
- Improve incident response times, reduce false positives and
other extraneous alerts, and enhancing threat detection
capabilities.
- Work with CSOC and architecture in determining technology and
resource requirements.
- Participate in engagement with other service families and
departments in addressing CSOC logging and monitoring needs. Engage
with same groups in developing Enterprise logging and monitoring
strategies and solutions.
- Stay abreast of business and technological developments to
properly prepare CSOC future posture.
Acquisition & Deployment
- Work with upper management to understand budget availability to
shape CSOC efforts.
- Supervise team and/or perform compliance assessments to include
Proof of Value (PoV) or Proof of Concept (PoC) for new program
security tools.
- Provide an accurate technical evaluation of the software
application, system, or network, documenting the security posture,
capabilities, and vulnerabilities against relevant information
assurance policies.
Incidental Functions
- Assist with other projects as required to contribute to
efficiency and effectiveness of the organization.
- Travel may be required but should not exceed 10% of work
time.
- Work outside the standard office 7.5-hour workday may be
required with on-call availability.
This position is not eligible for sponsorship for work
authorization now or in the future, including conversion to H1-B
visa.
This position has a hybrid work schedule with three days in the
office and the option for working remotely two days.
Job duties include contact with other employees and access
confidential and proprietary information and/or other items of
value, and such access may be supervised or unsupervised. The
Company therefore has determined that a review of criminal history
is necessary to protect the business and its operations and
reputation and is necessary to protect the safety of the Company's
staff, employees, and business relationships.
Formal Education & Certification
- Bachelor's Degree (or foreign equivalent) or in lieu of a
degree, at least 12 years in experience in the field of Information
Technology or Business (work experience or a combination of
education and work experience in the field of Information
Technology or Business)
Knowledge & Experience
- 10+ years IT experience.
- 8+ years IT security experience
- 4+ years of leading and managing a team of direct
reports
- Minimum 1 year experience with cyber-security investigations
and incident response.
- Minimum 1+ years of experience in process analysis and
improvement.
- Background in metrics/reporting.
- Experience identifying and implementing solutions to complex
business problems.
- Understanding of various operating systems (z/OS, Window, UNIX,
Linux, AIX, etc.) with an emphasis on vulnerability assessment and
hardening.
- Ability to analyze reports by reviewing incident or threat
frequency, severity, and duration data.
Preferred Experience
- Experience in a Security Operations Center (SOC) or working
with a Managed Security Service Provider (MSSP)
- Supervisory and/or Management experience preferred.
- Budget management
- Vendor Management
- Understand Log Management process and program
- Certifications: Lean, CISSP, SANS GIAC, or CISM
- Project Management concepts: use of JIRA, Planner,
etc.
- Delivery of Metrics demonstrating proof of value and key
performance indicators
- Understanding of CVSS, CVE, CWE, CPE, CCE, CWE, OVAL, SCAP
and/or other standards.
- Familiar with both IT and OT detect and respond
functions
- Familiar with email security tools such as Proofpoint, Abnormal
Security, O365, etc.
- Understanding of Threat Analysis and Threat
Intelligence.
- Experience with Security and Information and Event Monitoring
(SIEM) products such as Sumo Logic, Splunk, etc.
- Experience with Vulnerability Management products such as
Qualys and WIZ.
- Utilize key performance indicators to track analyst workloads
as well as the efficiency of detection signatures/rules and
associated monitoring technologies.
- Benchmark and implement industry best practices to mitigate
potential threats.
- Support the preparation of appropriate reports and communicate
status and results.
- Familiarity with SOC-CMM
Personal Attributes
- Strong analytical, evaluative, and problem-solving
abilities.
- Strong leadership skills
- Ability to motivate in a team-oriented, collaborative
environment.
- Ability to set and manage priorities.
- Strong written and oral communication skills.
- Strong interpersonal skills.
- Ability to present ideas in business-friendly and user-friendly
language.
- Self-motivated and directed.
- Keen attention to detail.
- Commitment to fostering a culture of inclusion and
diversity
- Hybrid on-site and remote work.
- Minimal travel is required.
- Work outside the standard office 7.5-hour workday may
occasionally be required for on call coverage or overseeing after
hours team investigations.
Keywords: The Sherwin-Williams Company, East Lake , Cybersecurity Security Operations Center Manager, Executive , Cleveland, Florida
Didn't find what you're looking for? Search again!
Loading more jobs...