Skip to main content

Security Operations Center Manager

Location: Baltimore, Maryland

Apply

What makes a Security Operations Center Manager successful at OneMain? Check out the top traits we’re looking for and see if you qualify.

  • Adaptable
  • Analytical
  • Curious
  • Entrepreneurial
  • Inventive
  • Problem Solver

Culture

  • We foster an entrepreneurial spirit that's powered by a national brand – our teams are empowered to make a difference
  • We encourage teams to take ownership of initiatives in this fast-paced, innovative culture so they can drive solutions that stay ahead of customer needs
  • We prioritize teamwork and building in-person connections with each other, understanding that fostering a collaborative environment is the best way to support each other.
  • We promote avenues to allow team members to expand their professional capabilities and continuously develop skills, facilitating upward mobility and career progression
Headshot of Andy W.

I like working at OneMain because of the opportunity it provides. You get to work with a lot of talented people, a lot of motivation to better the lives of our customers and a lot of fun technology that you get to interact with on a daily basis. I feel like I have many different options that I can take on yearly.

Andy W., Software Developer

Benefits

  • Blue circular icon with 4 people illustrations

    We promote social and family well-being by offering paid time off for volunteer hours and providing family back-up care.

  • Blue circular icon with open hands holding heart

    We offer extensive, comprehensive coverage to support team members’ needs physically and mentally, such as access to Talkspace and Hinge for on-demand physical therapy via an app.

  • Blue circular icon with piggy bank

    We offer financial wellness that includes 401(k) with match, ESPP, tuition reimbursement and tools like subscription cancelation that help you stay on top of your financial goals.

Security Operations Center Manager

Location: Baltimore, MD
Apply
Job Number R2605-50922 Date posted 05/27/2026

Position Overview:

We are seeking an experienced and highly skilled Security Operations Center (SOC) Manager to lead our cybersecurity operations team. The SOC Manager will oversee the full security operations lifecycle, from threat detection and incident response to team development and planning. This role is critical to ensure our organization maintains a robust security posture while managing day-to-day security operations.

Key Responsibilities:

  • Lead end-to-end incident response activities, including detection, containment, eradication, recovery, and post-incident review
  • Direct SOC analysts in threat detection, triage, investigation, and remediation efforts
  • Maintain accurate incident documentation, escalation workflows, ticket management, and timely event resolution
  • Develop and implement SOAR workflows to automate investigations, response actions, and repetitive security tasks
  • Improve operational efficiency and reduce MTTR through process automation and continuous optimization
  • Develop custom SIEM detection rules and signatures based on evolving business needs, threat intelligence, and threat hunting findings
  • Develop, track, and report SOC KPIs, including MTTD, MTTA, MTTR, dwell time, false positives, and incident closure rates
  • Provide leadership with regular updates on security operations, incident trends, and overall security posture
  • Maintain and improve SOC strategies, policies, SOPs, playbooks, and operational processes

Required Qualifications:

  • Deep technical hands-on knowledge of security monitoring tools and technologies including SIEM, IDS/IPS, EDR/XDR, NDR, firewalls, and SOAR platforms
  • Strong understanding of threat intelligence, indicators of compromise (IOCs), tactics, techniques, and procedures (TTPs), and attack methodologies
  • Expert knowledge of security frameworks and methodologies including NIST Cybersecurity Framework, ISO 27001, MITRE ATT&CK, etc.
  • Proficiency in log analysis, network traffic analysis, threat hunting techniques, and behavioral analysis
  • Strong understanding of cloud security principles and cloud-native security tools
  • Fundamental understanding of programming and scripting languages (Python, PowerShell, Bash) for automation, log parsing, and data analysis
  • At least two industry recognized certifications e.g.: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), GCIH (GIAC Certified Incident Handler), GCIA (GIAC Certified Intrusion Analyst), GCFA (GIAC Certified Forensic Analyst), GSOM (GIAC Security Operations Manager), CSOM (Certified Security Operations Manager)
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field (or equivalent professional experience).

Preferred Qualifications:

  • Experience in the financial services industry with deep understanding of financial sector threat landscape, regulatory requirements.

Experience Requirements:

  • Minimum 8-10 years of progressive experience in information security and cybersecurity operations
  • Minimum 7 years of hands-on experience in security operations, with demonstrated expertise across all three SOC tiers (Tier 1 triage, Tier 2 incident response, and Tier 3 threat hunting/advanced analysis)
  • Minimum 5 years of direct SOC management experience, including team leadership, resource planning, and operational oversight
  • Minimum 2 years of hands-on experience with SIEM platforms, including rule creation, testing, tuning, and change management
  • Proven experience managing 24/7 security operations with demonstrable results in incident response effectiveness

Apply

You have not saved any jobs.

You have not recently viewed any jobs.

Join our Talent Community

Sign up here for job alert emails and SMS messages from OneMain Financial Recruiting.

Already signed up?

Interested InPlease select a category or location option. Click “Add” to create your job alert.