Skip to content

Open nowPosted 31 days ago

Senior Manager of IT & Cyber Security

OnTrac395 open roles

Where
Virginia, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Manager of IT & Cyber SecurityOnTrac · Virginia, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on OnTrac's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 31 days ago

The posting

  OnTrac is hiring a Senior Manager of IT & Cyber Security!   Are you eager to join a dynamic and expanding company where you can both learn and make a meaningful impact? If you possess a strong sense of empathy, enjoy assisting others, thrive in a fast-paced environment, and excel at problem-solving, we encourage you to apply today to connect with a recruiter!   Founded in 1986, OnTrac has evolved into the leading provider of same-day and next-day delivery services in the U.S. for premier e-commerce and product-supply businesses, including five of the largest retailers in the U.S.    Location: Remote - This position may be performed remotely in states where the company is authorized to employ individuals. Compensation: The expected starting base pay range for this position is $156,000 - $195,000, with full potential base salary range over a successful candidate’s tenure in the position of $156,000 - $234,000. Actual compensation will be determined based on experience, skills, internal equity, and other job-related factors. This position may also be eligible for bonus, commission, or other incentive compensation in accordance with the terms of the applicable plan of up to a 20% Bonus Target. Employment Logistics:  The Senior Manager, CSIRT / Security Operations Center (SOC) leads and matures the organization’s cyber defense capabilities through operational excellence in security monitoring, cyber incident response, crisis management, threat intelligence, threat hunting, detection engineering, security validation, cloud and identity security operations, and security automation. This role provides strategic and operational leadership for Security Operations personnel and oversees the people, processes, technologies, budget, vendor relationships, and performance measures required to effectively detect, analyze, contain, eradicate, recover from, and learn from cybersecurity threats. The Senior Manager also ensures sustainable 24x7 coverage while driving the responsible adoption of automation and AI-enabled security operations.   Unpacking the Benefits:    Employees are eligible for a comprehensive benefits package which may include:  

Medical, dental, and vision insurance Life and short- and long-term disability coverage 401(k) retirement savings plan with company match  Flex vacation in states other than CA, CO, IL, MA, MT, and NE, with accruals up to 96 hours for first year of employment with tenure-based increases up to 160 hours Two (2) floating holidays per year Paid sick leave* Six (6) paid company holidays Two (2) weeks paid pregnancy disability leave, four (4) weeks paid parental bonding leave   Additional wellness and employee assistance programs

  Benefits eligibility and offerings are subject to the terms and conditions of the applicable plans and company policies.   The Must-Haves: 

Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field Master’s degree preferred, but not required 10+ years of progressive cybersecurity experience 5+ years of leadership experience managing Security Operations, Incident Response, Cyber Defense, or SOC teams Demonstrated experience building and maturing SOC capabilities, incident response programs, and detection engineering functions Experience developing cybersecurity operational metrics, executive reporting, and performance dashboards, including MTTD, MTTR, KPIs, and KRIs Proven success implementing SIEM, EDR, SOAR, and automated or AI-assisted response capabilities Experience managing 24x7 staffing models, budgets, and third-party security vendors or MSSPs Preferred certifications include CISSP, CISM, GIAC GCIH, GIAC GCIA, and GMON Cloud security certifications such as Azure Security Engineer Associate or Microsoft Cybersecurity Architect Expert preferred ​​It is the responsibility of every position to understand and adhere to the security guidelines outlined in OnTrac’s Acceptable Use policy and to conduct their activities accordingly.​

  Your Mission in Motion:  A summary of key responsibilities for the role is outlined below. Additional duties may be assigned as needed to support business objectives.

SOC leadership, structure & coverage: Lead daily SOC/ARC monitoring, alert triage, investigations, and incident response; manage analysts, shift leads, and incident handlers across all tiers; define Tier 1/2/3 responsibilities and escalation criteria; and establish a sustainable coverage model using follow-the-sun, dedicated shifts, or hybrid on-call rotations. Workforce planning & operational readiness: Ensure qualified staffing and service coverage while developing organizational and workforce plans that support current and future security operations requirements. Incident response & crisis management: Build and mature incident response procedures, runbooks, and playbooks; lead cyber incident response end-to-end; coordinate countermeasures and mitigating controls; and serve as the primary escalation point for complex investigations and significant incidents. Incident communication, exercises & lessons learned: Coordinate high-severity incident response across IT, Legal, Communications/PR, and executive leadership; conduct post-incident reviews; lead technical and executive tabletop exercises, cyber simulations, and readiness drills; and track corrective, preventive, and remediation actions to closure. Detection engineering, threat hunting & monitoring effectiveness: Develop the detection engineering and proactive threat-hunting programs; perform quality control of detection and alerting mechanisms; tune SIEM, EDR, and other security technologies to improve efficacy and reduce false positives; and align detection use cases with MITRE ATT&CK, threat intelligence, emerging threats, and organizational risks. Metrics, dashboards & performance management: Establish and report MTTD, MTTR, MTTC, detection coverage, alert fidelity, incident volume, severity trends, and analyst productivity; create SOC/ARC KPIs and KRIs; and develop executive dashboards that communicate threat trends, operational performance, and program maturity. Automation, AI & continuous improvement: Optimize security tools, processes, and SIEM/SOAR platforms to reduce analyst fatigue and accelerate response; implement AI/ML-supported triage, correlation, and investigation capabilities; define the appropriate division between automated action and human judgment; and monitor emerging agentic AI and autonomous response technologies. Governance, risk & compliance: Align security operations and incident handling with applicable regulatory requirements and frameworks, including NIST CSF, NIST SP 800-61, MITRE ATT&CK, CIS Controls, ISO 27001, PCI-DSS, SOX, and HIPAA, and support related audits, assessments, and evidence-collection activities. Budget, vendors & service performance: Manage the SOC operating budget across tools, staffing, and managed services; oversee MSSPs, MDR providers, incident response retainers, and security technology partners; and define and enforce vendor and contract SLAs. Talent development & security culture: Recruit, coach, mentor, and develop security operations personnel at all levels; establish career paths, training programs, skills assessments, and succession plans; and foster accountability, collaboration, innovation, continuous learning, and high performance.

  Paving your way to your success:   

You lead the strategy and execution of major cybersecurity projects that affect multiple areas of the organization. You set operational objectives, policies, procedures, and work plans while delegating responsibilities effectively across the team. You develop, adapt, and implement policies that strengthen immediate security operations and may influence the broader organization. You engage effectively with frontline and senior management on issues spanning multiple functions, departments, and customers. You use strong persuasion and sound judgment to navigate sensitive, complex situations while maintaining productive relationships.

  Posting Timeline:    This job posting is anticipated to remain open for at least 15 days from the date of posting   Disclosures:    *Washington state employees are eligible for up to 56 hours of paid sick leave annually.   The salary range above represents the national range for this position. The salary range may be inclusive of several career levels at OnTrac, and the actual base salary offered may vary depending on several factors including, but not limited to: Geographic location, candidate experience and qualifications, job-related skills and competencies, market alignment, and financial considerations.    Compensation decisions are made based on the specific circumstances of each hire to ensure fair and competitive pay.   ADA Statement:    We are committed to providing equal employment opportunities to all qualified individuals. If you require reasonable accommodation to participate in the application or interview process, perform essential job functions, or access other employment benefits, please contact Human Resources.   If you are excited to be part of our team and grow with our OnTrac family, we invite you to apply!   

OnTrac is proud to be an Equal Opportunity Employer Lasership, Inc. dba OnTrac Final Mile with its affiliates, including OnTrac Logistics, Inc. (collectively, "OnTrac" or the "Company") is an equal opportunity employer. We value diversity and welcome applications from individuals of all backgrounds, abilities, and experiences. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or age. Join us in our commitment to creating a diverse and inclusive workplace. If you are excited to be part of our team and contribute to our talent acquisition efforts, we invite you to apply.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against OnTrac's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on OnTrac's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    OnTrac's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.