Skip to content

Open nowPosted 54 days ago

Sr. Manager, Technology - Security

Williams-Sonoma11 open roles

Pay
$170,000 – $202,000 a year
Where
San Francisco, CA, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr. Manager, Technology - SecurityWilliams-Sonoma · San Francisco, CA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Williams-Sonoma's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. Williams-Sonoma postings stay open a median of 6 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 54 days ago

Williams-Sonoma median: 6 days open

The posting

Job Description

About the Team

You will lead the Cyber Threat Intelligence (CTI) and Security Operations (SOC) functions within the Cyber Security organization. This team is responsible for monitoring, detecting, investigating, and responding to cyber threats while continuously improving the organization's detection and response capabilities. This role reports to the Director of Cybersecurity and is a critically strategic domain within the WSI Security Governance program.

The CTI and SOC team's mission is to proactively defend the enterprise by leveraging intelligence-driven operations, detection engineering, incident response, and threat hunting to reduce cyber risk and enable secure business operations.

About the Role

As Manager, Cyber Threat Intelligence & Security Operations, you will lead a multidisciplinary team of Threat Intelligence Analysts, Detection Engineers, SOC Analysts, and Incident Responders. This is a hands-on technical leadership role where you will drive strategy, execution, and operations for this critical security domain while actively contributing to engineering and incident response efforts.

This role offers the opportunity to shape the future of cyber defense across a globally recognized portfolio of retail brands by building modern detection, response, intelligence, and automation capabilities.

Responsibilities

  • Lead, mentor, and develop approximately 24 cybersecurity professionals across Threat Intelligence, Detection Engineering, Security Operations, Red Team, and Incident Response; think Player/Coach, someone coaching from experience gained from being a former individual contributor.
  • Define, execute, and continuously mature the enterprise Cyber Threat Intelligence, Detection Engineering, and Security Operations strategy aligned to business risk.
  • Lead the operation and continuous evolution of Google SecOps, CrowdStrike, Cortex XSOAR, MISP, Tanium, and supporting detection technologies.
  • Direct enterprise cyber incident response from initial triage through containment, eradication, recovery, executive communications, and lessons learned.
  • Drive proactive threat hunting, adversary tracking, IOC management, and intelligence collection and analysis.
  • Lead Detection Engineering including SIEM content development, use-case creation, alert tuning, and continuous improvements in detection quality.
  • Expand automation, orchestration and Ai-assisted capabilities to eliminate repetitive analyst work and accelerate investigation and response.
  • Develop intelligence-driven detections based on emerging threat actor tactics, techniques, and procedures (TTPs).
  • Lead Red Team operations including adversary emulation, penetration testing, purple team exercises, and validation of defensive controls and ensure Detection Engineering translates findings into improved detections and defensive capabilities.
  • Partner with Security Engineering, Identity & Access Management, Enterprise Security Architecture, Legal, Privacy, Fraud, and Information Technology teams to strengthen enterprise cyber defenses.
  • Provide hands-on support during major security incidents, investigations, platform integrations, and complex operational escalations.
  • Establish and maintain operational standards, playbooks, investigation procedures, and best practices.
  • Develop, track, and communicate key operational metrics and program maturity to executive leadership, driving continuous improvement through measurable outcomes.
  • Lead audit, governance, regulatory investigations, and executive cyber threat reporting.

Basic Qualifications

  • 7–10 years of progressive experience in Cyber Security with expertise in Security Operations, Threat Intelligence, Detection Engineering, and Incident Response.
  • Proven experience managing technical teams and comfortable rolling up sleeves and logging into consoles to verify configurations and adjust settings.
  • Demonstrated expertise across SIEM, SOAR, EDR, Threat Intelligence, endpoint security, penetration testing and incident response technologies.
  • Experience developing and reporting operational metrics including MTTD, MTTR, detection coverage, alert fidelity, incident trends, automation effectiveness, and threat intelligence impact.
  • Experience developing and executing a multi-year roadmap to mature the organization's SOC capabilities across people, process, technology, and automation.
  • Strong understanding of enterprise networking, cloud, identity, operating systems, and modern attack techniques.
  • Excellent communication, leadership, and cross-functional collaboration skills.

Preferred Qualifications

  • Hands-on experience with Google SecOps, CrowdStrike, Cortex XSOAR, MISP, and Tanium.
  • Experience building or maturing enterprise Detection Engineering and Threat Intelligence programs.
  • Capable of delivering automation and scripting (Python, PowerShell, etc.); agentic AI experience is an emerging plus.
  • Experience supporting regulatory investigations, governance, and compliance initiatives.
  • Strong familiarity with MITRE ATT&CK and intelligence-driven defense methodologies.

About Williams-Sonoma, Inc.

Founded in 1956, Williams-Sonoma, Inc. is the premier specialty retailer of high-quality products for the home. Our family of brands includes Williams Sonoma, Pottery Barn, Pottery Barn Kids, PBteen, West Elm, Williams-Sonoma Home, Rejuvenation, and Mark and Graham. Today, we're a multi-brand, multi-channel, global enterprise supported by state-of-the-art technology and talented teams.

Benefits

Once you are here, you can look forward to a wide variety of benefits designed to help you grow personally and professionally, keep you healthy, prepare you for the unexpected, care for your family, and build a secure future.

  • A generous associate discount across Williams-Sonoma brands
  • 401(k) plan and investment opportunities
  • Paid vacation, holidays, and time-off programs
  • Comprehensive health, dental, and vision benefits
  • Wellness and employee assistance programs
  • Learning and development opportunities
  • Cross-brand career opportunities
  • Volunteer time and matching charitable donations

Continued Learning

  • In-person and online learning opportunities through WSI University
  • Cross-brand and cross-function career opportunities
  • Resources for self-development
  • Advisor (Mentor) program
  • Career development workshops, learning programs, and speaker series

WSI will not now or in the future commence an immigration case or "sponsor" an individual for this position (for example, H-1B or other employment-based immigration).

This role is not eligible for relocation assistance.

Williams-Sonoma, Inc. is an Equal Opportunity Employer. Williams-Sonoma, Inc. will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the San Francisco Fair Chance Ordinance, or other applicable state or local laws and ordinances.

The expected starting pay range for this position is $170,000-$202,000. Applicable pay ranges may differ across markets. Actual pay will be determined based on experience and other job-related factors permitted by law. In addition to competitive pay, compensation may include a variety of other components like benefits, paid time off, merit, and bonus opportunities

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Williams-Sonoma's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Williams-Sonoma's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Williams-Sonoma's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.