HomeSearchOperations Manager Jobs › Manager, Information Technology Security Operations & Incident Response

Manager, Information Technology Security Operations & Incident Response

recruiting.ultipro.com:TRE1006TRCI:699366e7-23c6-46d9-ae0d-4f649323dabf

Winchester, VA, USA · manager
More Operations Manager jobs: Operations Manager jobsOperations Manager salary

When you work at Trex, you’re helping to grow and enhance a true original. You join a company that boldly launched an entire industry … and still leads the way. We are looking for a Manager, Security Operations & Incident Response to support our team by leading Trex’s day-to-day security operations, incident response program, managed security service partnerships, and operational governance of the endpoint, cloud, email, vulnerability management, and detection platforms.

This role  This role provides centralized leadership and accountability for security operations, ensuring that alert triage, incident response, vulnerability remediation, threat detection, and managed service performance are coordinated, measurable, and aligned with business risk.  Key Duties and Responsibilities: Security Operations Management Lead 24x7 security operations delivered through the managed service model, including alert triage governance, escalation procedures, response expectations, service quality, and performance measurement against contractual SLAs.

Provide oversight of the SOC operating model, ensuring internal teams, offshore resources, and managed service providers have clearly defined responsibilities, documented processes, and measurable outcomes. Direct the detection engineering roadmap across managed endpoint detection and response, cloud-native security information and event management, and extended detection and response platforms, ensuring detection content reflects Trex’s manufacturing environment, threat model, and technology architecture.

Partner with cybersecurity, infrastructure, networking, endpoint, OT, and application teams to ensure security operations are integrated into broader IT service delivery and business operations. Incident Response Own the end-to-end incident response lifecycle, including preparation, detection, containment, eradication, recovery, lessons learned, and post-incident improvement activities. Lead executive-facing communications during high-severity security events, ensuring clear, timely, and business-appropriate updates are provided to leadership and key stakeholders.

Maintain the on-call rotation, escalation model, and quarterly tabletop exercise cadence, including executive-level tabletop exercises with Legal, Finance, Communications, and other business stakeholders. Ensure Trex maintains readiness for SEC 4-day 8-K cyber incident reporting, including materiality determination workflows, coordination with Legal, Finance/CFO, Investor Relations, and post-incident disclosure preparation.

Vulnerability Management and Platform Operations Own the vulnerability management program, including enterprise vulnerability scanning strategy, remediation governance, SLA tracking, exception handling, and coordination with IT Platforms, Servers, and application owners. Lead the application control and allowlisting deployment and tuning program in partnership with IT Platforms and End User Computing, including business change management, allowlisting governance, and false-positive resolution.

Oversee operational security capabilities across secure web gateway, email security, endpoint detection and response, extended detection and response, security information and event management, vulnerability management, application control, and related security platforms. Support Zero Trust and secure access initiatives, including zero trust network access rollout, legacy remote access VPN decommission planning, and conditional access integration in environments using a third-party primary endpoint detection and response platform.

Vendor and Managed Service Management Manage managed security service provider and managed detection and response vendor relationships, including service transitions, ongoing service governance, SLA management, escalation handling, and vendor performance reviews. Coordinate with internal stakeholders and vendors to ensure security platforms, managed services, a

Search all live jobs — free, no account →