Jobs › Companies › Optiv › ASO Threat Analyst Manager | Remote, USA

Über diese ASO Threat Analyst Manager | Remote, USA Stelle bei Optiv

Optiv · Vor Ort · Overland Park, Kansas

This is a second shift position working Tuesday-Friday from 12PM-11PM Eastern Time.


The ASO Threat Analyst Manager is a tactical, hands-on operational leader responsible for daily frontline execution across our global 24/7/365 Agentic Security Operations (ASO) team. You will lead a high-performing team of threat analysts triaging, investigating, and containing threats across a multi-tenant client base, operating directly alongside automated and agentic AI workflows.

While grounded in daily queue management and incident handling, you maintain a strategic perspective on service health. You will actively connect daily frontline operations with Detection Engineering, SOAR Engineering, and Threat Hunting, while partnering closely with Client Success to tackle chronic operational friction and noisy client environments. You will need situational awareness during tense client interactions to de-escalate friction and drive practical, collaborative solutions.


How you'll make an impact
Tactical Operations & Queue Governance:

  • Own daily shift execution, queue hygiene, and alert velocity to meet strict client SLAs and SLOs across our ASO service delivery model.
  • Supervise the human-in-the-loop operational interface, validating agentic AI triage outputs, enriched telemetry, and automated investigations for analytical rigor and accuracy.
  • Conduct regular ticket audits and investigation spot-checks to ensure high-fidelity analysis, defensible evidence gathering, and crisp client-facing notes.
  • Act as the primary operational escalation point, stepping in as tactical incident lead during critical (P1/P0) security events and client crises.
  • Run disciplined shift handoffs, identify operational bottlenecks, and balance analyst workload across the floor.
  • Lead tactical After-Action Reviews (AARs) to identify process breakdowns and immediate remediation steps.
     
    Engineering & Hunting Feedback Loops:
  • Direct and mentor the Threat Analysis team, specifically Senior Threat Analysts, to own the working-level handoffs with Detection Engineering, SOAR Engineering, and Threat Hunting.
  • Provide quality control and governance over analyst feedback, ensuring tuning requests, automation ideas, and hunt referrals make technical sense, address root causes, and align with operational standards.
  • Engage directly with engineering and hunting leads only when escalations occur, blockers arise, or cross-team prioritization is needed.
  • Define clear next steps, action items, and accountability loops across all teams to ensure feedback items are tracked to completion rather than lost in transition.
     
    Consultative Client & Partner Engagement:
  • Read the room effectively during high-pressure client calls, gauging stakeholder temperament, adjusting communication style dynamically, and actively de-escalating tense situations.
  • Partner tactically with Client Success Managers (CSMs) on at-risk or noisy accounts to review repeat alerts, agent health issues, and policy misconfigurations.
  • Lead client-facing incident discussions with a calm, consultative posture, turning recurring operational friction into actionable security recommendations rather than repeatedly handling the same false alarms.
     
    Team Coaching & Performance:
  • Mentor analysts on the floor through real-time investigation guidance, scenario walk-throughs, and technical quality reviews.
  • Guide analysts in working effectively with autonomous and agentic tools, ensuring team members build strong critical-thinking and investigative skills rather than blindly trusting automated outputs.
  • Manage shift schedules, coverage models, and on-call rotations to prevent analyst burnout in a high-tempo environment.
  • Coach frontline analysts toward technical career milestones in threat hunting, detection engineering, and advanced incident response.
     
    What we're looking for
  • 6 to 8+ years in Information Security, with strong technical foundations in threat analysis, network traffic analysis, or systems administration.
  • 3+ years within an active SOC, MDR, or MSSP environment, including 1 to 2+ years in a tactical lead, supervisory, or senior escalation role.
  • Strong situational awareness and proven experience de-escalating difficult client interactions, reading client sentiment under pressure, and steering conversations toward productive resolutions.
  • Demonstrated ability to coach senior technical staff, delegating working-level tasks while maintaining quality control and cross-team alignment.
  • Hands-on experience working in modern operational environments leveraging AI-assisted triage, SOAR playbooks, or agentic security workflows.
  • Proven ability to run live incident triage and manage queue dynamics under pressure in a multi-tenant services model.
  • Working knowledge of modern EDR/XDR and SIEM tools (e.g., Google SecOps, CrowdStrike, SentinelOne, Microsoft Defender/Sentinel, Splunk).
  • Practical familiarity with the MITRE ATT&CK framework and common adversary tradecraft.
  • Clear, adaptive verbal and written communication skills, comfortable briefing both frontline engineers and executive stakeholders.
  • Bachelor's degree in a technical field or equivalent hands-on operational experience.
  • Direct experience collaborating with Detection Engineering and SOAR automation pipelines.
  • Practical knowledge of ITIL-aligned ticketing workflows (e.g., ServiceNow, Jira).
  • Active certifications reflecting technical hands-on capability (e.g., GCIH, GCIA, CySA+, or vendor-specific platforms).

#LI-KG1


What you can expect from Optiv

  • A company committed to our inclusive value through our Employee Resource Groups
  • Work/life balance
  • Professional training resources
  • Creative problem-solving and the ability to tackle unique, complex projects
  • Volunteer Opportunities. “Optiv Chips In” encourages employees to volunteer and engage with their teams and communities.
  • The ability and technology necessary to productively work remotely/from home (where applicable)

EEO Statement

Optiv is an equal opportunity employer. All qualified applicants for employment will be considered without regard to race, color, religion, sex, gender identity or expression, sexual orientation, pregnancy, age 40 and over, marital status, genetic information, national origin, status as an individual with a disability, military or veteran status, or any other basis protected by federal, state, or local law.

Optiv respects your privacy. By providing your information through this page or applying for a job at Optiv, you acknowledge that Optiv will collect, use, and process your information, which may include personal information and sensitive personal information, in connection with Optiv’s selection and recruitment activities.  For additional details on how Optiv uses and protects your personal information in the application process, click here to view our Applicant Privacy Notice. If you sign up to receive notifications of job postings, you may unsubscribe at any time.

Bereit, sich bei Optiv zu bewerben?
Bei Optiv bewerben

Über Optiv

We work alongside clients to manage cyber risk and equip them with perspectives and programs to accelerate business progress. Our real-world experience, deep vertical expertise and diverse teams enable us to face any challenge with confidence. We put you at the center of our unmatched ecosystem of people, products, partners and programs to design and implement agile solutions. Our adaptive approach continually assesses risk in the context of cyber and broader objectives to secure today's business and fortify it for the future. At Optiv, we manage cyber risk so you can secure your full potential.

Alle Jobs bei Optiv ansehen →

Ähnliche Jobs

OP
Director, Marketing Programs | Remote, USA
Optiv
⚡ Früh bewerben Overland Park, Kansas Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
OP
Sr. Security Advisor - Threat Exposure Management | TX, MO, MN
Optiv
⚡ Früh bewerben Houston, Texas Vor Ort $200,000–$250,000
● Neu 👁 Gesehen ✓ Beworben vor 5 Tg.
OP
Account Manager - Cybersecurity - MidAtlantic
Optiv
⚡ Früh bewerben Washington, District of Columb... Vor Ort $140,000–$250,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
OP
Account Manager - Cybersecurity
Optiv
⚡ Früh bewerben Phoenix, Arizona Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
OP
Enterprise Sales Development Representative | Kansas City, USA
Optiv
⚡ Früh bewerben Kansas City, Missouri Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
OP
Engineer - BeyondTrust I On-site, Bangalore
Optiv
⚡ Früh bewerben Bangalore, Karnataka Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
OP
Sr. Account Manager - Cybersecurity | New England
Optiv
⚡ Früh bewerben Boston, Massachusetts Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
OP
Client Operations Specialist - Renewals | Remote, USA
Optiv
⚡ Früh bewerben Overland Park, Kansas Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.
OP
Client Operations Specialist - Renewals | Remote, USA
Optiv
⚡ Früh bewerben Leawood, Kansas Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Wo.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Optiv

Alle Jobs bei Optiv ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos