Skip to content

Open nowPosted 10 days ago

Cybersecurity Operations Manager

Lyra Technology Group15 open roles

Pay
$90,000 – $100,000 a year
Where
Jacksonville, FL
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCybersecurity Operations ManagerLyra Technology Group · Jacksonville, FL
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Lyra Technology Group's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Lyra Technology Group postings stay open a median of 2 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 10 days ago

Lyra Technology Group median: 2 days open

The posting

Lyra Technology Group is a private equity-backed holding company that invests in and operates industry leading technology service businesses. Our companies are operated independently by exceptional management teams. Companies that join our group retain the employees, name, and culture that have made them successful. As a platform of Evergreen Services Group, we never divest from businesses we partner with and approach every decision with the goal of driving sustainable and healthy growth over the long term.

The Cybersecurity Operations Manager is the senior technical leader and final escalation point for security events across Scarlett's managed clients. This is a hands-on leadership role: the Manager leads day-to-day delivery of managed security services while remaining directly involved in detection, investigation, and incident response. The position sits between security strategy, owned by the vCISO, and execution, carried out by the SOC team. The Manager is accountable for the security posture and incident outcomes our clients experience, with a role that is outcome-driven, focused on reducing client risk, improving response times, and being the dependable last line of decision-making when a security event escalates.

About Scarlett Group....

Scarlett Group is recognized as a JBJ Best Places to Work and is one of the fastest-growing technology companies in the region. We offer competitive benefits, opportunities for advancement, professional development support, and a culture built on collaboration, accountability, and having fun while doing meaningful work. Great benefits. Great people. Great opportunities. That's the Scarlett difference.

Your work as a Cybersecurity Operations Manager will include several components:

Security Leadership and Escalation

  • Serve as the final escalation point for security alerts and incidents across all managed clients.
  • Lead and develop the Cybersecurity Operations team with direct, hands-on coaching and clear accountability.
  • Establish roles, expectations, KPIs, and escalation paths for the SOC team.
  • Own queue health across all managed clients, including alert volume, aging, assignment, and first-line escalation; delegate day-to-day queue work to SOC team members while retaining accountability for the outcome.
  • Work the security queue directly when volume exceeds team capacity or when SOC team members are on PTO, out, or otherwise unavailable – queue coverage is an expected part of this working leadership role, not an exception.

SOC and Incident Response

  • Oversee daily SOC operations, including monitoring, alert triage, and response.
  • Lead containment, eradication, and recovery during security incidents, and own post-incident root cause analysis and documentation; engage Advanced Services for deep forensic analysis when an incident requires it.
  • Improve detection logic, alert quality, and response workflows on an ongoing basis.
  • Manage MDR and SIEM partner relationships and hold them to service expectations.

Client Security Accountability

  • Own the security outcomes managed clients experience: detection quality, response speed, containment, and client confidence.
  • Serve as the senior technical voice in client-facing security conversations covering incidents, posture, reporting, and remediation.
  • Partner with the vCISO and account teams to align operations with client roadmaps and compliance requirements.

Operational Excellence

  • Develop and maintain runbooks, playbooks, and standard operating procedures.
  • Track performance against response times, detection accuracy, and SLA adherence, and act on trends to reduce noise and improve efficiency.
  • Partner with Advanced Services on detection engineering, automation, and tooling – including EDR/XDR, log and SIEM ingestion, identity protection, and email security – rather than maintaining a separate engineering function.

Cross-Functional Collaboration

  • Coordinate security-related work with Support, NOC, and Professional Services.
  • Ensure clean escalation and resolution across operational teams.
  • Contribute to company-wide automation, AI, and service delivery initiatives.

Our ideal Cybersecurity Operations Manager has the following qualifications:

  • 4 to 6 years in cybersecurity or security operations, including direct experience triaging alerts and responding to security incidents.
  • 2 or more years in a leadership role, formal or informal, including mentoring or directing other analysts.
  • MSP, MSSP, or multi-client environment strongly preferred.
  • Strong working knowledge of endpoint detection and response (EDR/XDR), SIEM and log management, identity and access management (Entra, Conditional Access), and email security.
  • Comfort serving as the final technical decision-maker under pressure during active incidents.
  • Familiarity with security frameworks (NIST, CIS, ISO) and compliance-driven environments; CMMC and NIST 800-171 experience is a plus.
  • Strong coaching, team development, and performance management capabilities.
  • Excellent communication, including translating technical issues for business stakeholders.
  • Sound problem-solving and decision-making under pressure.
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent experience.
  • Preferred: Security+, CySA+, GCIH, or equivalent; CISSP, GCFA, or other advanced certifications are a plus but not expected.

This role will operate on a hybrid basis out of Jacksonville, FL and will host a base compensation of $90,000-$100,000.

We are seeking candidates who thrive as the dependable last line of decision-making when a security event escalates. If you are a hands-on security leader who wants ownership over both the SOC's day-to-day execution and its long-term outcomes, we would welcome the opportunity to speak with you.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Lyra Technology Group's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Lyra Technology Group's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Lyra Technology Group's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.