Manager / Senior Manager, SecOps & Cyber Defense

CoinDesk is a media, events, indices, and data company serving the global crypto economy.

Distributed

Funding history

Investors

About CoinDesk

CoinDesk operates a cryptocurrency newsroom covering markets, policy, technology, and digital assets. It also provides institutional digital-asset market data through CoinDesk Data and benchmark indices and reference rates through CoinDesk Indices.

View jobs by CoinDesk

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

Lead and mentor SOC analysts and incident response engineers across time zones while serving as the escalation point for high-severity incidents. Manage incident response from detection through post-mortem reporting, build and tune detections, conduct forensics and threat hunting, and automate response workflows.

Requirements

  • 8+ years of hands-on experience in SOC operations, threat detection, and security incident response
  • 2+ years of people management or formal team leadership experience
  • Expertise investigating cloud-native threats, container environments, and SaaS infrastructure
  • Proficiency with SIEM platforms, EDR/XDR suites, log aggregators, and SOAR tools
  • Scripting and automation skills in Python, Bash, or Go
  • Knowledge of network protocols, cloud architecture, identity systems, and digital forensics

Responsibilities

  • Lead and mentor SOC analysts and incident response engineers
  • Serve as the primary escalation point for high-severity security incidents
  • Manage global operational shifts and continuous security coverage
  • Define and track SOC operational metrics
  • Partner with Infrastructure, Cloud Platform, DevOps, Corporate IT, Legal, and Compliance during investigations
  • Drive end-to-end response for major security incidents
  • Design, write, and tune detection rules across SIEM, EDR, and cloud-native logs
  • Perform digital forensics and reverse-engineer suspicious scripts and payloads
  • Research emerging threat actor tactics, zero-days, and cloud vulnerabilities
  • Lead and participate in Red and Purple team operations and tabletop exercises
  • Hunt for undetected threat actor behavior
  • Build and refine automated response playbooks using Python, API integrations, and SOAR tools

Benefits

  • Discretionary annual target bonus
  • Performance incentives