Why This Role Stands Out
Elevate your career by leading cybersecurity operations for an award-winning, rapidly growing technology firm with a strong reputation for fostering exceptional careers and a collaborative culture. You'll thrive in this role if you're a skilled cybersecurity professional seeking significant growth opportunities and a competitive salary of $80,000 - $95,000 annually. Apply today to join a team dedicated to meaningful work and professional development.
Quick Overview
Job Description
Award-Winning Culture. Rapid Growth. Exceptional Careers.
More Than a Job - A Place to Grow.
When you join Scarlett Group, you're joining a team recognized as a JBJ Best Places to Work and one of the fastest-growing technology companies in the region. We offer competitive benefits, opportunities for advancement, professional development support, and a culture built on collaboration, accountability, and having fun while doing meaningful work.
Great benefits. Great people. Great opportunities. That's the Scarlett difference.
Cybersecurity Operations Manager Needed
(Must be local to Jacksonville area)
- Serve as the final escalation point for security alerts and incidents across all managed clients.
- Lead and develop the Cybersecurity Operations team with direct, hands-on coaching and clear accountability.
- Establish roles, expectations, KPIs, and escalation paths for the SOC team.
- Own queue health across all managed clients, including alert volume, aging, assignment, and first-line escalation. Delegate day-to-day queue work to SOC team members while retaining accountability for the outcome.
- Work the security queue directly when volume exceeds team capacity or when SOC team members are on PTO, out, or otherwise unavailable. This is a working leadership role and queue coverage is an expected part of it, not an exception.
- Oversee daily SOC operations, including monitoring, alert triage, and response.
- Lead containment, eradication, and recovery during security incidents, and own post-incident root cause analysis and documentation. Engage Advanced Services for deep forensic analysis when an incident requires it.
- Improve detection logic, alert quality, and response workflows on an ongoing basis.
- Manage MDR and SIEM partner relationships and hold them to service expectations.
- Own the security outcomes managed clients experience: detection quality, response speed, containment, and client confidence.
- Serve as the senior technical voice in client-facing security conversations covering incidents, posture, reporting, and remediation.
- Partner with the vCISO and account teams to align operations with client roadmaps and compliance requirements.
- Develop and maintain runbooks, playbooks, and standard operating procedures.
- Track performance against response times, detection accuracy, and SLA adherence, and act on trends to reduce noise and improve efficiency.
- Partner with Advanced Services on detection engineering, automation, and tooling, including EDR/XDR, log and SIEM ingestion, identity protection, and email security, rather than maintaining a separate engineering function.
- Coordinate security-related work with Support, NOC, and Professional Services.
- Ensure clean escalation and resolution across operational teams.
- Contribute to company-wide automation, AI, and service delivery initiatives.
- To support onboarding, training, and team integration, employees in this position are expected to work onsite.
- Maintain accurate daily time records and ensure all time worked is entered and submitted by the end of each workday in accordance with company procedures.
- Other duties as assigned.
- 4 to 6 years in cybersecurity or security operations, including direct experience triaging alerts and responding to security incidents.
- 2 or more years in a leadership role, formal or informal, including mentoring or directing other analysts.
- MSP, MSSP, or multi-client environment strongly preferred.
- Strong working knowledge of endpoint detection and response (EDR/XDR), SIEM and log management, identity and access management (Entra, Conditional Access), and email security.
- Comfort serving as the final technical decisionmaker under pressure during active incidents.
- Familiarity with security frameworks (NIST, CIS, ISO) and compliance-driven environments. CMMC and NIST 800-171 experience is a plus.
- Strong coaching, team development, and performance management capabilities.
- Excellent communication, including translating technical issues for business stakeholders.
- Sound problem-solving and decision-making under pressure.
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent experience.
- Preferred: Security+, CySA+, GCIH, or equivalent. CISSP, GCFA, or other advanced certifications are a plus but not expected.
- The work environment for this position is a standard office setting.
- The employee is regularly required to sit, stand, walk, and use hands to operate a computer and other office equipment.
- The employee must occasionally lift and/or move up to 25 pounds.
- Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Incidents are resolved at this level without routinely reaching the vCISO or executive leadership.
- Alerts are high quality, actionable, and efficiently resolved.
- Incident response is fast, structured, and well communicated.
- The team is engaged, growing, and aligned to outcomes.
- Clients trust Scarlett with their security and stay because of it.
- Base salary range: $80,000 to $95,000 annually, dependent on incident response experience, leadership experience, and certifications.
- Salaried and exempt. On-call participation and after-hours incident work are compensated within base salary rather than through hourly or overtime pay.
- Eligible for standard company benefits and any applicable performance incentive.
- Onsite, Jacksonville based.
- Standard office environment with after-hours coordination during security incidents.
- Participates in the standing on-call and escalation rotation alongside SOC team members.
- Serves as backstop on-call coverage when the rotation cannot be filled, including PTO, holidays, unplanned absences, and periods of elevated alert or incident volume.
- Availability outside standard hours is expected during active incidents and coverage gaps. The role is exempt and compensated on outcomes rather than hours.
What We Offer
- Competitive pay and comprehensive benefits
- 401(k) with company match
- Generous PTO and paid holidays
- Professional development and certification program
- Monthly cell phone stipend
- Paid mileage
- Clear opportunities for career growth
- An award-winning culture recognized as a JBJ Best Places to Work
- The chance to make an impact in a fast-growing company where your contributions matter
Compensation details: 80000-95000 Hourly Wage
PIddb579f7ff46-31181-41571302
Similar jobs
- AS
Construction Manager-Level 2 - Experienced (6 - 10 Years)
Apex Systems
Juno Beach, FL🇺🇸On-site6 weeks agoConstruction - GP
Senior Commercial Operations Manager – Salesforce
Global Partners
Newton, MA🇺🇸$136.2k - $204.2k/yrOn-site3 days agoSalesforceTechnology - AA
Manager, Planning
NewAmerican Airlines
Fort Worth, TX🇺🇸Hybrid23 hours agoLean Six SigmaSchedulingSix Sigma - AN
Insurance Sales & Branch Operations Manager
AAA Northern New England
Rutland, VT🇺🇸Hybrid2 weeks agoBusiness DevelopmentMicrosoft OfficeSales - DS
Specialist Off Field Operations - HIRING EVENT
DICK'S Sporting Goods
Corona, CA🇺🇸$20 - $29/hrHybrid3 days agoOnboarding - BC
AI Operations Lead
NewBCforward
Seattle, WA🇺🇸$73 - $79/hrOn-site23 hours agoAgileTriageOperations & Project Management