Job Description:
As the Manager, Cyber Threat Intelligence & Security Operations, you will lead a team of approximately 12 cybersecurity professionals across Threat Intelligence, Detection Engineering, Security Operations, and Incident Response.
This is a hands-on technical management position responsible for the operational effectiveness of the Security Operations Center while driving the organization's threat intelligence program and continuously improving detection capabilities.
You will work closely with Security Engineering, Identity & Access Management, Cloud Security, Enterprise Architecture, Legal, Privacy, Fraud Prevention, and Information Technology teams to ensure cyber threats are rapidly identified, investigated, and mitigated.
Responsibilities:
Leadership & Team Management
• Lead, mentor, and develop a multidisciplinary team consisting of:Â
o Cyber Threat Intelligence AnalystsÂ
o Detection EngineersÂ
o SOC AnalystsÂ
o Incident RespondersÂ
• Foster a collaborative, high-performing culture focused on operational excellence and continuous learningÂ
• Provide technical coaching, career development, and mentorship across the organizationÂ
• Establish operational priorities and coordinate security response activities across multiple teamsÂ
• Serve as the escalation point during significant security incidentsÂ
Security Operations Center Leadership
• Lead day-to-day Security Operations Center activities including monitoring, investigation, containment, eradication, and recovery effortsÂ
• Direct major cyber incident response activities from identification through post-incident reviewÂ
• Ensure operational readiness for security events across cloud, on-premises, endpoint, identity, and application environmentsÂ
• Drive continuous improvement of operational procedures, investigation methodologies, and response playbooksÂ
• Partner with Security Engineering to improve operational supportability of security platformsÂ
Cyber Threat Intelligence
• Lead the enterprise Cyber Threat Intelligence programÂ
• Oversee intelligence collection, analysis, enrichment, and disseminationÂ
• Monitor emerging threat actors, campaigns, vulnerabilities, and industry trendsÂ
• Translate external intelligence into actionable defensive capabilitiesÂ
• Manage Indicators of Compromise (IOCs), adversary tracking, and threat intelligence repositoriesÂ
• Produce executive and technical threat intelligence briefingsÂ
• Partner with Fraud, Legal, Privacy, and business leadership regarding emerging cyber risksÂ
Detection Engineering
• Lead development and continuous improvement of enterprise detection capabilitiesÂ
• Oversee SIEM content development and detection engineeringÂ
• Drive detection use-case development and continuous tuningÂ
• Improve alert fidelity while reducing false positivesÂ
• Lead proactive threat hunting initiativesÂ
• Develop new analytics based on adversary tactics, techniques, and procedures (TTPs)Â
• Ensure security content aligns with the MITRE ATT&CK framework and current threat landscapeÂ
Security Platforms
Provide technical leadership for security operations technologies including:
• Google SecOpsÂ
• CrowdStrike FalconÂ
• Cortex XSOARÂ
• MISP Threat Intelligence PlatformÂ
• TaniumÂ
Collaborate with Security Engineering regarding architecture, upgrades, integrations, and operational improvements across the enterprise security technology stack.
Incident Response
• Lead enterprise cyber incident response activitiesÂ
• Coordinate investigations involving malware, ransomware, insider threats, account compromise, phishing, and advanced attacksÂ
• Direct technical response teams during high-severity incidentsÂ
• Conduct post-incident reviews and identify opportunities to strengthen defensesÂ
• Develop and maintain incident response procedures, playbooks, and operational readinessÂ
Governance & Cross-Functional Collaboration
• Support regulatory investigations, internal audits, and security assessmentsÂ
• Prepare executive summaries and threat reports for security leadershipÂ
• Partner closely with:Â
o Security EngineeringÂ
o Identity & Access ManagementÂ
o Enterprise Security ArchitectureÂ
o LegalÂ
o PrivacyÂ
o Fraud PreventionÂ
o Information TechnologyÂ
• Contribute to long-term cyber defense strategy and operational planningÂ
Basic Qualifications
• 7–10 years of experience in Cyber Security with expertise in Security Operations, Threat Intelligence, Detection Engineering, and Incident ResponseÂ
• Previous experience leading technical cybersecurity teamsÂ
• Proven experience managing enterprise Security Operations CentersÂ
• Strong understanding of modern cyber threats, adversary tactics, and threat intelligence methodologiesÂ
• Experience leading major cyber incident investigationsÂ
• Hands-on experience with SIEM, SOAR, EDR, endpoint security, and threat intelligence platformsÂ
• Strong understanding of enterprise networking, operating systems, identity technologies, cloud environments, and application securityÂ
• Excellent communication and leadership skills with the ability to influence technical and executive stakeholdersÂ
• Experience mentoring engineers and analysts while fostering technical growthÂ
Preferred Qualifications
• Experience with Google SecOpsÂ
• Experience with CrowdStrike FalconÂ
• Experience with Cortex XSOARÂ
• Experience with MISP or other Threat Intelligence PlatformsÂ
• Experience with TaniumÂ
• Experience implementing threat hunting programsÂ
• Familiarity with MITRE ATT&CK, Cyber Kill Chain, Diamond Model, and intelligence-driven defense methodologiesÂ
• Experience supporting regulatory investigations and compliance initiativesÂ
• Experience building or maturing enterprise detection engineering programsÂ
• Knowledge of automation and scripting using Python or PowerShellÂ
Job Type & LocationThis is a Permanent position based out of Rocklin, CA.
Pay and BenefitsThe pay range for this position is $70.00 - $75.00/hr.
Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: • Medical, dental & vision • Critical Illness, Accident, and Hospital • 401(k) Retirement Plan – Pre-tax and Roth post-tax contributions available • Life Insurance (Voluntary Life & AD&D for the employee and dependents) • Short and long-term disability • Health Spending Account (HSA) • Transportation benefits • Employee Assistance Program • Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace TypeThis is a fully onsite position in Rocklin,CA.
Application DeadlineThis position is anticipated to close on Sep 11, 2026.
About TEKsystems
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We’re a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We’re a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We’re strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We’re building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.
Learn more about this Employer on their Career Site
