1

Soc Engineering Manager Jobs in Batavia, IL (NOW HIRING)

Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process ... Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment * Strong ...

Senior Security Engineer

Chicago, IL · On-site

$118K - $161K/yr

... SOC Engineer I and II employees. 2. Analyze and respond to security threats from various security platforms and technologies. 3. Support, troubleshoot, configure, manage, and upgrade FW, NIDPS, UTM ...

Senior Security Engineer

Chicago, IL · On-site

$118K - $161K/yr

... SOC Engineer I and II employees. 2. Analyze and respond to security threats from various security platforms and technologies. 3. Support, troubleshoot, configure, manage, and upgrade FW, NIDPS, UTM ...

SecOps Lead

Chicago, IL · On-site

$160K - $180K/yr

... SOC engineering, or incident response * Strong understanding of SOC workflows and incident lifecycle management * Experience with SIEM, EDR, and security tooling integrations * Proven ability to ...

Security Engineer

Chicago, IL · On-site +1

$97K - $142K/yr

Maintain the SOC technology stack: integrations, health, and content engineering across all ... Echo Global Logistics is a leading provider of technology-enabled transportation management ...

Security Engineer

Chicago, IL · On-site

$97K - $142K/yr

Maintain the SOC technology stack: integrations, health, and content engineering across all ... Echo Global Logistics is a leading provider of technology-enabled transportation management ...

New

This role reports to Information Security Engineering Manager This is a hybrid position and ... SOC platform, including the migration of existing Splunk SOAR playbooks. Build agentic workflows ...

next page

Showing results 1-20

Soc Engineering Manager information

See Batavia, IL salary details

$47.4K

$149.7K

$177.4K

How much do soc engineering manager jobs pay per year?

As of Sep 12, 2026, the average yearly pay for soc engineering manager in Batavia, IL is $149,717.00, according to ZipRecruiter salary data. Most workers in this role earn between $118,800.00 and $176,400.00 per year, depending on experience, location, and employer.

What is a SOC engineering manager?

SOC Engineering Managers are professionals responsible for overseeing the technical teams and operations within a Security Operations Center (SOC). They lead and manage security engineers, analysts, and other staff to ensure the organization's IT infrastructure is protected from cyber threats. Their role includes developing security strategies, implementing security technologies, managing incident response, and ensuring compliance with security policies. They also collaborate with other departments to enhance overall security posture and may be involved in hiring and training SOC personnel.

What are the key skills and qualifications needed to thrive as a SOC engineering manager?

To thrive as a SOC Engineering Manager, you need a strong background in cybersecurity, network engineering, and incident response, typically supported by a degree in computer science or a related field and relevant certifications like CISSP or CISM. Familiarity with SIEM tools, intrusion detection systems, and security automation platforms is essential. Leadership, effective communication, and problem-solving skills are crucial for managing teams and coordinating with stakeholders. These skills ensure effective oversight of security operations, timely threat mitigation, and the alignment of security strategies with organizational objectives.

What are common challenges faced by SOC engineering managers when overseeing cross-functional teams?

SoC Engineering Managers often navigate challenges related to coordinating diverse engineering teams, such as digital, analog, verification, and software groups. Balancing project timelines, managing resource allocation, and ensuring clear communication among stakeholders are key hurdles. Additionally, they must stay updated on rapidly evolving technology trends and standards while addressing technical bottlenecks and aligning team goals with broader business objectives. Effective management requires strong leadership, adaptability, and a collaborative mindset.

Cyber - Google SecOps - Manager

Chicago, IL • On-site

Deloitte
Finance and Insurance • 10K+ employees

Full-time

Re-posted 13 days ago


Key responsibilities

  • Design, implement, and optimize secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities.

  • Collaborate with SOC analysts and threat detection engineers to develop, tune, and maintain threat detection rules and translate SOC processes into automation playbooks.

  • Lead and mentor junior team members in SOC engineering, including SIEM, SOAR, and process development.


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 93 frontline employees who took The Breakroom Quiz


Job description

Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:

  • Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
  • Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
  • Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
  • Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
  • Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
  • 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
  • Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
  • Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
  • Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
  • Experience facilitating scope or build requirement discussions with internal or external stakeholders
  • Experience with threat hunting or cyber threat intelligence fundamentals
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

Deloitte's Cyber team helps clients address evolving cybersecurity challenges and opportunities by delivering solutions and managed services that reduce complexity, strengthen resilience, and support confident growth. As a Google SecOps Manager supporting Google SecOps engagements, you will contribute to high-visibility projects by applying advanced SOC engineering experience and knowledge of Google SecOps, threat detection engineering, SIEM, SOAR, and automation development. You will design, implement, and optimize secure, outcome-focused solutions while collaborating across teams to deliver reliable and efficient security operations capabilities. In this role, you will also mentor practitioners and help advance modern Google SecOps methods across the team.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Google SecOps Manager on the Cyber Defense & Resilience team, you will be responsible for:

  • Leading the design and implementation of secure, scalable Google SecOps architectures, including SIEM and SOAR capabilities aligned to client security requirements and regulatory obligations such as General Data Protection Regulation (GDPR) and Payment Card Industry Data Security Standard (PCI DSS)
  • Leading end-to-end deployment of log ingestion pipelines using data fabric technologies and integrations such as Bindplane, Cloud Feeds, and application programming interfaces (APIs)
  • Collaborating with security operations center (SOC) analysts and threat detection engineers to prioritize, develop, tune, and maintain threat detection rules in Google SecOps to identify malicious behavior across enterprise environments
  • Translating SOC processes into SOAR automation playbooks to reduce alert fatigue and scale alert triage and response
  • Developing and managing integrations across third-party platforms, security tools, and Google SecOps to support automated data ingestion, alert enrichment, response actions, and case management workflows
  • Leading and mentoring junior team members in SOC engineering, including SIEM, SOAR, and process development

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to mentor and provide clear guidance to others

The team

Our Cyber Defense & Resilience offering helps organizations defend against advanced threats by transforming security operations, monitoring technologies, data analytics, and threat intelligence capabilities. The team supports clients in managing and protecting dynamic attack surfaces while providing rapid crisis and cyber incident response. Through this work, we help clients strengthen readiness, response, and recovery across business disruptions.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or another technical field, or equivalent work experience
  • 9+ years of experience in security operations, threat detection engineering, or enterprise information technology security
  • Experience with Google Cloud SecOps tool stack and architecture, including Google Chronicle SIEM, Google SecOps SOAR, Google Siemplify SOAR, threat detection engineering, and security operations center workflows
  • Experience with Python scripting and GoStash or Logstash for automation, integration development, log normalization, and parsing, as well as with extract, transform, load (ETL) pipelines and technologies such as Cribl, Bindplane, NXLog, Kafka, Cloud Feeds, and APIs
  • Experience with MITRE ATT&CK, the Cyber Kill Chain, VirusTotal, Mandiant, Google Threat Intelligence, Splunk, Cortex XSOAR, and AI agentic frameworks, including Model Context Protocol (MCP) or Agent Development Kit (ADK), for workflow development or integration across security information and event management (SIEM), security orchestration, automation, and response (SOAR), Google Threat Intelligence (GTI), or attack surface management (ASM)
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Certifications such as Google Cloud Professional Cloud Architect, Google Cloud Professional Security Engineer, or Certified Cloud Security Professional (CCSP)
  • Experience monitoring cybersecurity threats, vulnerabilities, or compliance trends to support security operations or security engineering activities
  • Experience facilitating scope or build requirement discussions with internal or external stakeholders
  • Experience with threat hunting or cyber threat intelligence fundamentals
  • Experience with data fabric technologies such as Bindplane or Cribl
  • Experience with infrastructure and networking concepts such as internet protocol (IP) networking, virtual private networks (VPNs), domain name system (DNS), load balancing, firewall technologies, or cloud environments such as Amazon Web Services (AWS) or Microsoft Azure

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $134,500 to $265,100.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom