Job Openings Senior Manager – Cybersecurity Operations

About the job Senior Manager – Cybersecurity Operations

Why Castelion, Why Now

Castelion is moving incredibly fast to develop and deliver advanced defense systems at a time when execution matters more than ever. We believe focus and technical excellence are decisive advantages - and we are building a team that can deliver real capability, not just concepts.

This is a rare opportunity to join at an early stage, where your work will directly shape critical systems, influence major technical decisions, and have immediate, real-world impact.

Senior Manager – Cybersecurity Operations

We are seeking an experienced Senior Manager – Cybersecurity Operations to join our cybersecurity operations team at Castelion. This critical role will lead defensive security operations, incident response, and threat monitoring, protecting our information systems, intellectual property, product development security, and critical infrastructure from common threat vectors as well as advanced persistent threats (APTs) and nation-state actors.

The ideal candidate will envision security to remain a business enabler and not a blocker, have deep expertise in defensive security operations, SOC leadership, proactive threat hunting, SIEM & SOAR, and incident response within highly regulated environments. Brings a practical, and up-to-date relevant technical understanding of protocols, encryption levels, patch levels, policy & procedure, etc., that are secure in the modern cybersecurity landscape.

Responsibilities:

  • Contribute to and mature our Security Operations Center (SOC) activities and ensure effective threat detection and response
  • Direct threat hunting operations to proactively identify and neutralize threats before impact
  • Lead incident response efforts for security events affecting all our information systems
  • Develop and maintain defensive playbooks, runbooks, and standard operating procedures
  • Coordinate with additional internal teams to conduct exercises that validate defensive posture
  • Design and implement defense-in-depth strategies aligned with NIST, DoD, and intelligence community frameworks
  • Evaluate and deploy advanced security technologies (SIEM, EDR/XDR, SOAR, threat intelligence platforms)
  • Create and maintain security architecture documentation and network defense diagrams
  • Contribute to security roadmap planning
  • Establish and maintain threat intelligence program aligned to aerospace and defense sector threats
  • Analyze threat actor tactics, techniques, and procedures (TTPs) using MITRE ATT&CK framework
  • Produce threat intelligence reports and briefings for technical and executive audiences
  • Collaborate with government agencies and industry partners on threat information sharing
  • Track emerging threats and vulnerabilities relevant to defense systems and aerospace technology
  • Contribute to compliance with NIST 800-171, CMMC, ITAR, DFARS, and other applicable regulations
  • Support security audits, assessments, accreditation activities, and regular penetration testing
  • Partner with IT operations, engineering, and program management teams on security initiatives
  • Coordinate with government customers and oversight bodies on security matters
  • Function as a primary stakeholder and subject matter expert for changes to cyber controls and policies

Required Qualifications:

  • 7+ years of hands-on experience in cybersecurity, with a focus in defensive operations
  • 2+ years in a leadership or team lead capacity
  • Proven experience operating in defense, aerospace, engineering, intelligence, government, or critical infrastructure sectors
  • Experience in regulated environments (DoD, CMMC, NIST 800-171, ISO 27001, etc.)
  • Demonstrated expertise in security monitoring, threat hunting, and incident response
  • Demonstrated understanding of advanced persistent threat (APT) tactics and techniques
  • Hands-on experience with enterprise security tools (SIEM, EDR, IDS/IPS, firewalls, proxies)
  • Expert knowledge of network protocols, security architecture, and system hardening
  • Expert proficiency as both a configurator and a consumer of security information and event management (SIEM) platforms
  • Strong understanding of Windows and Linux security and forensics
  • Experience with endpoint detection and response (EDR) solutions (CrowdStrike, Carbon Black, Defender, SentinelOne, etc.)
  • Proficiency with scripting and automation (Python, PowerShell, Bash)
  • Knowledge of cloud security (AWS, Azure, GovCloud)
  • Understanding of malware analysis, reverse engineering techniques, and penetration testing
  • Experience with threat intelligence platforms and indicator management
  • Deep understanding of security principles, threats, and frameworks (e.g., cyber kill chain, MITRE ATT&CK, NIST, CIS Controls).
  • Strong documentation, troubleshooting, and communication skills.
  • Ability to thrive in fast-paced, high-pressure environments with competing priorities.
  • Analytical mindset with strong problem-solving abilities
  • Commitment to staying current with evolving threat landscape

Preferred Qualifications:

  • Active Security+, CISSP, GIAC, GSOC, GCIA, GCIH, GCFA, CISA, CEH, or similar senior-level certifications
  • Eligibility to keep and maintain a U.S. security clearance.

What We're Looking For:

  • A proactive security professional who sees audits and compliance as opportunities to build better systems – not just check boxes.
  • A disciplined thinker who can balance security, business needs, and regulatory constraints.
  • A calm, solutions-oriented team member who leads by example during assessments, incidents, or high-pressure reviews.
  • A clear communicator who knows how to educate non-technical stakeholders without watering things down.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

Benefits And Perks

All full-time employees are granted meaningful long-term equity, sharing in the company's significant growth trajectory. We offer four (4) weeks of paid time off, ten (10) company-paid holidays, and comprehensive health benefits - including 100% employee-covered medical and strong dependent coverage, along with dental and vision plans. We also provide paid parental leave to support growing families, a $100 monthly fitness stipend to promote health and performance, and onsite EV charging for convenience. In addition, employees enjoy perks like catered meals, company-covered food during high-demand periods, and a fully stocked kitchen to stay fueled throughout the day.

Affirmative Action/EEO Statement

Employment with Castelion is governed on the basis of competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status.