Skip to content

Security Operations & Engineering Manager

  • Hybrid
    • Bucharest, București, Romania
  • IT Services

Job description

The Security Operations & Engineering Manager leads both the operational defense of the organization (monitoring, detection, incident response) and the engineering of the security infrastructure that powers it (tooling, automation, detection logic, integrations). This is a hybrid leadership role for someone equally comfortable managing a team through a live incident and architecting the systems that prevent the next one.

Key Responsibilities:

Operations

  • Build and lead 24/7 (or business-hours, depending on org) security monitoring, detection, and incident response functions.

  • Architect and own the incident response lifecycle: detection, triage, containment, eradication, recovery, and post-incident review/root cause analysis.

  • Oversee vulnerability management program — scanning, prioritization, and remediation tracking with asset owners.

  • Deliver regular metrics, dashboards, and executive reporting on security posture, MTTR/MTTD, and incident trends.

  • Contribute to capacity management and budget management

Engineering

  • Design, build, and maintain security infrastructure: SIEM, SOAR, EDR, IDS/IPS, infrastructure hardening and log pipelines.

  • Develop and tune detection engineering — writing and refining correlation rules, alerts, and automated response playbooks.

  • Automate repetitive SOC workflows (triage, enrichment, ticketing) to reduce analyst toil and alert fatigue.

  • Partner with software/platform engineering on secure architecture reviews, threat modeling, and shift-left security practices.

  • Evaluate, pilot, and implement new security technologies; manage tool lifecycle and vendor relationships.

Leadership & Governance

  • Hire, mentor, coach and manage a team of security analysts and security engineers.

  • Collaborate cross-functionally with IT, legal, compliance, and engineering leadership on audits, investigations, and security initiatives.

  • Manage relationships with MSSPs, security vendors and business partners

Job requirements

Required Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).

  • 6–10+ years in cybersecurity, including hands-on SOC/IR work and security engineering/automation experience.

  • 2–4+ years in a management or team-lead capacity.

  • Good understanding scripting/automation skills (Python, PowerShell, or similar) for detection engineering and devsecops principles

  • Deep familiarity with SIEM/SOAR platforms (Splunk preferred) and EDR tools (SentinelOne preferred).

  • Solid grasp of networking and IAM

  • Professional certifications such as CISSP or equivalent are a plus

Skills:

  • Professional command of English

  • Good command of French is a plus

  • Strong leadership and people-management skills, balanced with a desire to stay technically hands-on.

  • Comfortable context-switching between incident command and long-term architecture/engineering work.

  • Ability to translate technical risk into business impact for executive stakeholders.

  • Strong documentation, process design, and automation mindset.

or

Hybrid
  • Bucharest, București, Romania
IT Services