Fortified Health Security is seeking a Manager, Threat Defense Services to help lead the delivery and continued evolution of our Security Operations Center (SOC). This role requires a unique combination of personality, technical expertise, people leadership, operational ownership, and strong client-facing skills. The Manager will be expected to develop deep expertise across the technologies that support our managed security services, quickly learn and become proficient in new technologies as our capabilities evolve, and help analysts build the same technical depth and investigative mindset. Equally important, this individual must be a high-energy, engaged, and approachable leader who takes ownership, communicates effectively, coaches and mentors others, and fosters a culture of curiosity, accountability, urgency, continuous improvement, and exceptional client service.
The following duties are normal for this position. The omission of specific statements of duties does not exclude them from being expected of this position if the work is similar, related, or a logical assignment for this position. Other duties may be required.
Special Skills & Knowledge
The successful candidate will demonstrate a strong combination of technical cybersecurity expertise, leadership capability, operational judgment, and client-facing communication skills, including:
Deep knowledge of security operations and threat detection, including incident response, alert investigation and triage, escalation management, SIEM operations, log and network traffic analysis, detection engineering, correlation logic, detection and suppression rule management, playbook development, and malware investigation and remediation.
Broad knowledge of modern security technologies and controls, including SIEM, endpoint detection and response (EDR/XDR), firewalls, intrusion detection and prevention, identity and user security, data loss prevention, vulnerability management, cloud security, and other technologies commonly used within enterprise security programs.
Strong technical aptitude and curiosity, with the ability to quickly learn new security platforms and technologies, develop subject matter expertise, troubleshoot complex issues, and guide analysts in developing their own technical proficiency.
Strong understanding of security architecture and defense-in-depth principles across endpoint, identity, network, cloud, user, and data security, including how telemetry and controls from these environments contribute to effective detection and response.
Strong understanding of Windows operating systems, security events, logging, and common attack techniques, as well as adversary frameworks such as MITRE ATT&CK.
Strong troubleshooting and root cause analysis skills, with the ability to identify patterns, understand complex technical issues, and translate findings into improvements to detections, processes, technologies, and service delivery.
Working knowledge of scripting and automation, including technologies such as Python, PowerShell, and Bash, and an understanding of how automation can improve the scalability, consistency, and effectiveness of SOC operations.
Strong knowledge of incident response and operational decision-making, including the ability to assess risk, prioritize competing issues, exercise sound judgment with incomplete information, and maintain composure during high-pressure security events.
Demonstrated leadership and people-development skills, including team building, coaching, mentoring, motivating, providing meaningful feedback, managing performance, resolving conflict, building consensus, and developing future leaders.
High emotional intelligence and strong interpersonal skills, with the ability to build trust, create accountability, foster collaboration, and maintain effective relationships with analysts, peers, leaders, clients, and other stakeholders.
Exceptional written, verbal, and presentation skills, including the ability to translate complex cybersecurity concepts for technical teams, business leaders, executives, and clients.
Strong relationship-management and client-service skills, with the confidence, professionalism, and presence to represent Fortified during client meetings, technical discussions, service reviews, escalations, and security incidents.
A strong sense of ownership and accountability, with a demonstrated willingness to take responsibility for outcomes, proactively identify and address problems, follow issues through resolution, and continuously improve the quality and effectiveness of the service.
Strong documentation and process-management skills, including the ability to create, maintain, standardize, and improve operational procedures, playbooks, technical documentation, and analyst workflows.
Knowledge of cybersecurity and compliance frameworks relevant to healthcare, including NIST, HIPAA, HITRUST, and other applicable regulatory or industry requirements.
Understanding of healthcare technology and operational environments is strongly preferred, including an appreciation for the operational, clinical, regulatory, and business considerations that influence cybersecurity decisions within healthcare organizations.
Supervisory Responsibility
Working Conditions & Travel Requirements
Fortified Health Security is an Equal Opportunity Employer. In compliance with the Americans with Disabilities Act, Fortified Health Security will provide reasonable accommodations to qualified individuals with disabilities. If a reasonable accommodation is needed to perform this position, you need to inform Fortified Health Security People and Culture Team of such request. Signatures below indicate the receipt and review of this job description by the associate assigned to the position and the People and Culture Team.