
Security Operations & Engineering Manager
- Hybrid
- Bucharest, București, Romania
- IT Services
Job description
The Security Operations & Engineering Manager leads both the operational defense of the organization (monitoring, detection, incident response) and the engineering of the security infrastructure that powers it (tooling, automation, detection logic, integrations). This is a hybrid leadership role for someone equally comfortable managing a team through a live incident and architecting the systems that prevent the next one.
Key Responsibilities:
Operations
Build and lead 24/7 (or business-hours, depending on org) security monitoring, detection, and incident response functions.
Architect and own the incident response lifecycle: detection, triage, containment, eradication, recovery, and post-incident review/root cause analysis.
Oversee vulnerability management program — scanning, prioritization, and remediation tracking with asset owners.
Deliver regular metrics, dashboards, and executive reporting on security posture, MTTR/MTTD, and incident trends.
Contribute to capacity management and budget management
Engineering
Design, build, and maintain security infrastructure: SIEM, SOAR, EDR, IDS/IPS, infrastructure hardening and log pipelines.
Develop and tune detection engineering — writing and refining correlation rules, alerts, and automated response playbooks.
Automate repetitive SOC workflows (triage, enrichment, ticketing) to reduce analyst toil and alert fatigue.
Partner with software/platform engineering on secure architecture reviews, threat modeling, and shift-left security practices.
Evaluate, pilot, and implement new security technologies; manage tool lifecycle and vendor relationships.
Leadership & Governance
Hire, mentor, coach and manage a team of security analysts and security engineers.
Collaborate cross-functionally with IT, legal, compliance, and engineering leadership on audits, investigations, and security initiatives.
Manage relationships with MSSPs, security vendors and business partners
Job requirements
Required Qualifications:
Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).
6–10+ years in cybersecurity, including hands-on SOC/IR work and security engineering/automation experience.
2–4+ years in a management or team-lead capacity.
Good understanding scripting/automation skills (Python, PowerShell, or similar) for detection engineering and devsecops principles
Deep familiarity with SIEM/SOAR platforms (Splunk preferred) and EDR tools (SentinelOne preferred).
Solid grasp of networking and IAM
Professional certifications such as CISSP or equivalent are a plus
Skills:
Professional command of English
Good command of French is a plus
Strong leadership and people-management skills, balanced with a desire to stay technically hands-on.
Comfortable context-switching between incident command and long-term architecture/engineering work.
Ability to translate technical risk into business impact for executive stakeholders.
Strong documentation, process design, and automation mindset.
or
- Bucharest, București, Romania
All done!
Your application has been successfully submitted!
You've already applied for this job
We appreciate your interest in this position. Unfortunately, you have already applied for this job.

