MDR Manager

Guardz - Miami, FL

Hiring: MDR Manager Company: Guardz Location: Miami, FL Job Posted Time: 2026-09-16 19:08:49 Target Skills & Keywords : BigQuery, SOC, SQL, Snowflake, Splunk About the job Experience: •5+ years in SOC, MDR, or Incident Response handling complex attacks, including 2+ years as a Team Lead, Shift Lead, or senior. Required Skills: •Own 24/7 shift coverage, tiering, and escalation paths so every alert reaches the right analyst and there are no gaps in monitoring or escalation. Participate in an on-call rotation with the team. •Own response SLAs (time-to-triage, time-to-notify, MTTR) and report SOC KPIs (MTTD, MTTR, detection efficacy, false-positive rate, case aging, customer satisfaction) to leadership. •Run QA on closed alerts and incidents, drive down false positives, and maintain the team's runbooks, playbooks, and SOC standards. •Lead, coach, and mentor MDR Analysts: regular 1:1s, performance feedback, onboarding, and the T1-to-T3 training path. Run tabletop exercises and post-incident reviews. •Act as technical lead and final escalation point for T3 incidents (advanced malware, identity threats like MFA fatigue and token theft, active breaches), leading the full lifecycle with defensible documentation. •Correlate alerts across EDR (SentinelOne, Defender for Endpoint), ITDR (M365, Google Workspace), and email security, and run proactive threat hunts aligned to MITRE ATT&CK. •Use Guardz AI agents, Google BigQuery, and query languages such as SQL and KQL to triage, hunt across high-volume logs, and confirm incident scope at machine speed. •Partner with MSPs on major incidents and posture reviews, and feed findings back into detection with product, threat research, and engineering. Qualifications: •Hands-on expertise with EDR (SentinelOne, CrowdStrike, Defender for Endpoint) and ITDR (identity threat management across M365 and Google Workspace). •Applied hands-on capability in Google BigQuery, Snowflake, Splunk, Elastic, or equivalent, and fluency in a query language such as SQL, KQL, or SPL. •Excellent communication skills, able to make high-risk technical findings clear to both technical and non-technical audiences. •Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent hands-on experience. •Preferred: CompTIA Security+, CompTIA CySA+, Microsoft SC-200, GIAC GCIH / GCIA / GCFA, or CISSP (or equivalent DoD 8570 / 8140 IAT Level II). Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!