Security Operations & Engineering Manager
Veo Worldwide Services · Bucharest, Romania
International Trade and Development · 501-1,000 employees
About the role
The manager will lead security operations, including incident response and monitoring, while architecting and maintaining security infrastructure. They will also oversee vulnerability management, mentor the security team, and collaborate with cross-functional departments on security initiatives.
What they look for
Requirements
Candidates must have a bachelor's degree in a relevant field and 6-10+ years of experience in cybersecurity, including SOC/IR and engineering. Proficiency in SIEM/SOAR platforms, scripting languages, and 2-4 years of management experience are required.
Full description
The Security Operations & Engineering Manager leads both the operational defense of the organization (monitoring, detection, incident response) and the engineering of the security infrastructure that powers it (tooling, automation, detection logic, integrations). This is a hybrid leadership role for someone equally comfortable managing a team through a live incident and architecting the systems that prevent the next one.
Key Responsibilities:
Operations
- Build and lead 24/7 (or business-hours, depending on org) security monitoring, detection, and incident response functions.
- Architect and own the incident response lifecycle: detection, triage, containment, eradication, recovery, and post-incident review/root cause analysis.
- Oversee vulnerability management program — scanning, prioritization, and remediation tracking with asset owners.
- Deliver regular metrics, dashboards, and executive reporting on security posture, MTTR/MTTD, and incident trends.
- Contribute to capacity management and budget management
Engineering
- Design, build, and maintain security infrastructure: SIEM, SOAR, EDR, IDS/IPS, infrastructure hardening and log pipelines.
- Develop and tune detection engineering — writing and refining correlation rules, alerts, and automated response playbooks.
- Automate repetitive SOC workflows (triage, enrichment, ticketing) to reduce analyst toil and alert fatigue.
- Partner with software/platform engineering on secure architecture reviews, threat modeling, and shift-left security practices.
- Evaluate, pilot, and implement new security technologies; manage tool lifecycle and vendor relationships.
Leadership & Governance
- Hire, mentor, coach and manage a team of security analysts and security engineers.
- Collaborate cross-functionally with IT, legal, compliance, and engineering leadership on audits, investigations, and security initiatives.
- Manage relationships with MSSPs, security vendors and business partners
Required Qualifications:
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience).
- 6–10+ years in cybersecurity, including hands-on SOC/IR work and security engineering/automation experience.
- 2–4+ years in a management or team-lead capacity.
- Good understanding scripting/automation skills (Python, PowerShell, or similar) for detection engineering and devsecops principles
- Deep familiarity with SIEM/SOAR platforms (Splunk preferred) and EDR tools (SentinelOne preferred).
- Solid grasp of networking and IAM
- Professional certifications such as CISSP or equivalent are a plus
Skills:
- Professional command of English
- Good command of French is a plus
- Strong leadership and people-management skills, balanced with a desire to stay technically hands-on.
- Comfortable context-switching between incident command and long-term architecture/engineering work.
- Ability to translate technical risk into business impact for executive stakeholders.
- Strong documentation, process design, and automation mindset.