[Remote] Lead Security Operations Manager - CrowdStrike Falcon NGSIEM
Note: The job is a remote job and is open to candidates in USA. Cognizant is seeking a Lead Security Operations Manager to strengthen enterprise cybersecurity operations. The role leads threat monitoring, incident response, threat hunting, detection engineering, CrowdStrike Falcon NGSIEM administration, security automation, governance reporting, and SOC team guidance.
Responsibilities
- Lead security operations, threat monitoring, and detection activities using CrowdStrike Falcon NGSIEM
- Manage incident detection, investigation, response, and proactive threat hunting activities across the enterprise
- Oversee NGSIEM administration, platform health, performance management, and continuous optimization
- Develop, tune, and maintain detection rules, correlation logic, security use cases, and operational dashboards
- Drive security automation, governance reporting, operational excellence, and continuous improvement initiatives while providing leadership and guidance to SOC analysts and security engineers
Skills
- Extensive experience leading Security Operations Center (SOC) functions, incident response, and threat detection programs
- Hands-on experience with CrowdStrike Falcon, Falcon NGSIEM, or comparable SIEM and security analytics platforms
- Strong expertise in threat hunting, incident investigation, detection engineering, and cybersecurity operations
- Experience managing log onboarding, integrations, and monitoring across cloud, identity, endpoint, and network security platforms
- Proven ability to develop and optimize detection rules, correlation use cases, security dashboards, and response workflows
- Experience monitoring and improving security operations metrics such as SLAs, KPIs, MTTD, and MTTR
- Demonstrated leadership experience managing and mentoring security analysts and engineers
- Strong communication and stakeholder management skills with the ability to present security posture, risks, and recommendations to technical and business audiences
- Remote position open to qualified applicants in the United States
- Please note, this role is not able to offer visa transfer or sponsorship now or in the future*
- Industry certifications such as CISSP, GCIA, GCIH, GCFA, Security+, or similar cybersecurity credentials
- Experience implementing security orchestration, automation, and response (SOAR) capabilities
- Knowledge of cloud security monitoring across AWS, Azure, and Google Cloud environments
- Experience supporting compliance frameworks and regulatory requirements
- Familiarity with MITRE ATT&CK, threat intelligence platforms, and advanced adversary detection methodologies
Benefits
- Remote position open to qualified applicants in the United States
- Wellbeing programs supporting a healthy work-life balance
- Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans
- Medical/Dental/Vision/Life Insurance
- Paid holidays plus Paid Time Off
- 401(k) plan and contributions
- Long-term/Short-term Disability
- Paid Parental Leave
- Employee Stock Purchase Plan
Company Overview
- Cognizant is a professional services company that helps clients alter their business, operating, and technology models for the digital era. It was founded in 1994, and is headquartered in Teaneck, New Jersey, USA, with a workforce of 10001+ employees. Its website is