DTCC logo

Cyber SOC Team Manager

Hiring from
United States
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.

The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.


Pay and Benefits:

  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).

The Impact you will have in this role:

Being a member of IT Cybersecurity & Platform Strategy team, reporting to the Cyber Monitoring and Incident Response Team Manager, you are responsible for leading a regional Cyber Monitoring and Incident Response (CMIR) function that operates in a 24x7 environment. You provide leadership, oversight, and direction to Senior Associates, Associates, and Senior Analysts responsible for monitoring, detecting, investigating, and responding to cybersecurity threats and incidents.
As a people leader, you are accountable for operational performance, workforce planning, employee development, stakeholder engagement, operational readiness, and continuous improvement. You ensure the consistent execution of cybersecurity monitoring and incident response activities while maintaining alignment with organizational objectives, regulatory requirements, and industry best practices.
As a senior member of the Cyber Security Incident Response Team (CSIRT), you serve as an escalation point during major cybersecurity incidents and may be required to support response activities outside normal business hours.


Your Primary Responsibilities:

  • Be accountable for the overall operational health, performance, and effectiveness of assigned teams and shifts.
  • Ensure continuous operational readiness and appropriate staffing coverage across a 24x7 operating model.
  • Manage workforce planning, scheduling, staffing forecasts, and resource allocation to meet operational requirements.
  • Establish, monitor, and report on key performance indicators, operational metrics, service levels, and quality standards.
  • Oversee the execution of monitoring, detection, investigation, and response activities to ensure consistency with established procedures and organizational expectations.
  • Drive operational maturity through process optimization, automation, reporting enhancements, and continuous improvement initiatives.
    People Leadership
  • Create and maintain a high-performing, inclusive, accountable, and collaborative team culture.
  • Conduct performance reviews, coaching sessions, development planning discussions, and ongoing career conversations with direct reports.
  • Establish clear expectations, objectives, and development goals for employees and managers within the organization.
  • Identify, develop, and retain technical and leadership talent.
  • Lead recruiting, interviewing, onboarding, succession planning, and retention efforts.
  • Effectively delegate responsibilities, empower team members, and remove obstacles impacting team performance.
  • Model appropriate leadership behavior, communication, professionalism, and decision-making.
    Incident Response Leadership
  • Serve as Incident Commander during major cybersecurity incidents (P1-P2) and as an escalation point for significant operational events.
  • Provide executive-level incident coordination and communication during major response activities.
  • Ensure effective coordination between technical teams, technology leadership, business stakeholders, legal, compliance, communications, and executive management.
  • Review major incident reports, root cause analyses, corrective actions, and lessons-learned activities to improve response capabilities.
  • Validate that response activities align with established incident response procedures, regulatory obligations, and organizational expectations.
    Strategic Leadership
  • Develop and execute regional operational strategies aligned with departmental and enterprise cybersecurity objectives.
  • Partner with senior leadership to identify capability gaps, emerging risks, staffing requirements, and investment opportunities.
  • Lead strategic projects related to threat detection, incident response, operational maturity, workforce development, and cyber defense capabilities.
  • Create and socialize program updates, key accomplishments, operational metrics, and strategic initiatives to stakeholders and leadership.
    Risk, Governance, and Compliance
  • Ensure compliance with cybersecurity policies, standards, regulatory requirements, and control frameworks.
  • Support internal audits, regulatory examinations, tabletop exercises, assessments, and evidence requests.
  • Oversee the creation, maintenance, and continuous improvement of operational procedures, playbooks, and response methodologies.
  • Leverage threat intelligence, industry trends, operational metrics, and stakeholder feedback to continuously improve cybersecurity capabilities and security posture.
    Organizational Advocacy
  • Promote cybersecurity awareness and Blue Team capabilities throughout the organization.
  • Build and maintain strong partnerships with technology teams, business units, risk management, compliance, and executive leadership.
  • Represent CMIR within cross-functional initiatives, governance forums, exercises, and strategic planning discussions.
  • Occasionally travel to conferences, training, and other DTCC offices (up to 20%).
  • Act as the management escalation contact for on-call activities and emergency response situations.
  • Support after-hours incident response activities when required.

**NOTE: The Primary Responsibilities of this role are not limited to the details above. **

Qualifications:

  • Min 8 years of relevant experience
  • Bachelors’ Degree and/or equivalent experience

Talents Needed for Success:

  • Have at least seven (7) years of cybersecurity, security operations, incident response, digital forensics, threat hunting, or related experience.
  • Have at least three (3) years of leadership experience managing teams, major initiatives, or operational programs.
  • Demonstrate success leading high-performing technical teams in a fast-paced operational environment.
  • Demonstrate experience conducting performance evaluations, coaching, mentoring, employee development planning, and talent management activities.
  • Demonstrate the ability to establish goals, develop action plans, assign responsibilities, measure outcomes, and drive accountability.
  • Demonstrate experience managing major cybersecurity incidents involving multiple technical teams, business stakeholders, and executive leadership.
  • Demonstrate strong written and verbal communication skills, including the ability to present complex technical concepts to technical and non-technical audiences.
  • Demonstrate the ability to independently manage competing priorities and make sound decisions during high-pressure situations.
  • Demonstrate emotional intelligence, sound judgment, conflict resolution skills, and strong leadership principles.
  • Demonstrate experience using metrics and data to drive operational improvements, workforce planning, and strategic decision-making.
  • Demonstrate a strong commitment to operational excellence, continuous improvement, and employee development.

The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Similar jobs

Apply for this job