Detection and Response Manager, Tempus Technologies
Auburn, AL - USA
Job Summary
As a Detection and Response Manager within Tempus Technologies subsidiary of PNC you will be based remotely.
The Detection and Response Manager is responsible for overseeing and maturing the full detection and security incident response lifecycle to minimize organizational risk ensure rapid containment and drive timely and effective remediation. This role leads daytoday SOC operationsincluding proactive monitoring triage investigation and responsewhile ensuring 24/7 readiness through oncall management process rigor and operational discipline.
The ideal candidate brings strong analytical and technical expertise deep understanding of modern threat landscapes and the leadership skills required to guide analysts through complex investigations. This role partners closely with Security Engineering IT Application teams Compliance and external stakeholders to coordinate response activities facilitate clear communication and ensure incidents are managed with consistency transparency and measurable addition the Detection and Response Lead drives continuous enhancement of SIEM detections playbooks automation and readiness exercises strengthening the organizations overall security posture and operational resilience.
Responsibilities:
Core Detection & Response Operations
Lead daytoday Detection and Response activities ensuring timely detection triage investigation and response to security events.
Ensure 24/7 incident response readiness by maintaining and managing the oncall rotation including scheduling escalation paths and servicelevel expectations.
Serve as the owner for incident response execution including initial containment escalation incident declaration and forensic coordination.
Act as the primary technical lead and liaison during highseverity incidents collaborating with Infrastructure Engineering Legal and Executive leadership.
Detection Engineering & Threat Intelligence
Oversee the development tuning and continuous improvement of SIEM detections alerting logic and correlation rules.
Drive integration of internal and external Threat Intelligence to enhance visibility and detection capabilities.
Produce operational metrics and performance reporting focused on detection coverage MTTD/MTTR case handling quality and tooling efficacy.
Evaluate and implement new technologies integrations and automation opportunities to reduce manual workload and enhance response capabilities.
Incident Response Program Management
Own and maintain incident response playbooks SOPs escalation paths and response frameworks.
Ensure regulatory contractual and internal stakeholder notifications are initiated and documented when required.
Manage post-incident activities including after-action reviews corrective actions and measurable improvements.
Lead readiness activities such as tabletop exercises red/blue/purple team scenarios and simulationbased training.
Ensure incident response posture aligns with organizational risk appetite audit requirements and industry best practices.
Leadership Coaching & Continuous Improvement
Direct and mentor analysts in investigations incident handling and operational processes.
Execute staffing decisions performance evaluations onboarding and the professional development pipeline for analysts.
Identify operational gaps and recommend technical or process improvements to mature the detection and response program.
Champion a culture of continuous improvement documentation discipline and analytical excellence.
Key Relationships:
Security Operations & Application Security Teams
IT Infrastructure Teams
Development Teams
Executive Leadership
External Vendors & Incident Response Partners
Qualifications:
Bachelors degree in Computer Science Information Security Engineering or a related field (or equivalent experience).
CCSP CISSP GCIA GCIH GCFA CySA or equivalent certifications.
5 years of experience leading security operations incident response digital forensics or security engineering.
Demonstrated ability to lead incident response activities from detection through containment eradication recovery and post incident review.
Experience performing root cause analysis log analysis and threat investigation.
Exposure to compliance frameworks such as PCI DSS SOC 2 HIPAA and FedRAMP.
Strong understanding of cybersecurity fundamentals including networking operating systems endpoint security cloud security and identity access management.
Hands-on experience with SIEM platforms (e.g. Elastic Splunk) EDR tools IDP/IPS and other monitoring technologies.
Expertise with incident handling methodologies and frameworks such as NIST 800 61 ISO 27035 and MITRE ATT&CK.
Proficiency in incident management tools and ticketing systems (e.g. Jira ServiceNow).
Excellent ability to translate technical details into clear actionable communication for both technical and non-technical stakeholders.
Strong communication and interpersonal skills with the ability to manage stressful situations.
Strong organizational skills with the ability to prioritize and manage multiple concurrent incidents and tasks.
Excellent problem-solving analytical and decision-making skills.This position may be eligible for remote work in select geographic locations subject to approval by PNC. If approved work must be conducted from a quiet secure and confidential home-based workspace. Occasional in-office participation may be required based on business needs.PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position.
- Manages a team that oversees the day-to-day operations and effectiveness of assigned security technology and programs.
- Manages resources that enables security control effectiveness with a team and technology.
- Monitor trends and continuously assesses staff/security system capabilities to meet business demands.
- Leads in policy development audit mitigation and other tasks related to securing and maintaining the operational health of the infrastructure. Evaluates security systems teams and processes to provide recommendations to maintain continuity and operational health.
- Documents and revises procedures and playbooks for teams processes and technology to provide a standard security practice and increase team effectiveness.
PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be:
- Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions.
- Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNCs Enterprise Risk Management Framework.
PNC also has fundamental expectations of our people managers. As a manager of talent in PNC you will be expected to:
- Include Intentionally - Cultivates diverse teams and inclusive workplaces to expand thinking.
- Live the Values - Role models our values with transparency and courage.
- Enable Change - Takes action to drive change and innovation that will transform our business.
- Achieve Results - Takes personal ownership to deliver results. Empowers and trusts others in decision making.
- Develop the Best - Raises the bar with every talent decision and guides the achievement of all employees and customers.
Successful candidates must demonstrate appropriate knowledge skills and abilities for a role. Listed below are skills competencies work experience education and required certifications/licensures needed to be successful in this position.
To learn more about these and other programs including benefits for full time and part-time employees visit .
If an accommodation is required to participate in the application process please contact us via email at . Please include accommodation request in the subject line title and be sure to include your name the job ID and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call and say Workday for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions.
PNC provides equal employment opportunity to qualified persons regardless of race color sex religion national origin age sexual orientation gender identity disability veteran status or other categories protected by law.
This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and for any registered role the Secure and Fair Enforcement for Mortgage Licensing Act of 2008 (SAFE Act) and/or the Financial Industry Regulatory Authority (FINRA) which prohibit the hiring of individuals with certain criminal history.
Required Experience:
Manager