Tenet Healthcare Corporation
Manager, Detection & Investigative Operations - Remote based in the US
Tenet Health is seeking a Manager of Detection & Investigative Operations with previous Information Security experience to work in our Dallas, TX corporate office on a hybrid schedule or remotely if outside DFW. Below is a brief outline of what Tenet is seeking for this role.
Reporting to the Director of Detection and Response within the enterprise Cybersecurity organization, the Manager of Detection & Investigative Operations will oversee the activities of the 24x7 Detection and Response Center and all analysts and engineers, ensuring that Detection and Response operations are performed in accordance to policy, standards and security best practices. This role has direct responsibility for the effective and efficient operations of the Detection and Response Center including security monitoring, detection, triage, initial response, escalation handoffs, and threat intelligence to the Incident Response team.
The position will be responsible for driving transformation and maturity of processes, workflows, and overall capabilities, process refinement and implementation, cross-team discipline collaboration, maintenance of internal and external stakeholder relationships, and supervision of staff. The Manager of Detection & Investigative Operations will work closely with the Managed Security Service Provider to ensure the continuous improvement of the Detection and Response capabilities and that SLAs, SOPs, Events and Alert Management are all in line with the standards of Tenet. The Manager of Detection & Investigative Operations will work closely with their peer, the Incident Response Manager, on investigations, incidents, and threat hunting as needed. Equally, the Manager of Detection & Investigative Operations will work to ensure there are clear processes and escalation points to hand off alerts/events from the Detection and Response team to the IR Team as deemed appropriate based on the security and scope of the event. The Manager of Detection & Investigative Operations will manage and mature the Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) platforms. Lastly, the Manager of Detection & Investigative Operations will lead a transformative effort to embed automation and AI across the analyst and engineering workflows.
ResponsibilitiesDuties include but are not limited to the following:
- Lead Detection and Response team in support of all designated Security Operations and Incident Response investigations, as needed
- Drive a transformation to embed AI into the triage, enrichment, and containment workflows of the Detection and Response Center
- Embrace automation and AI across all areas including the analyst and SIEM/SOAR platform engineering teams
- Analyze security indicators of compromise and alert data and take appropriate investigative actions
- Develop and execute on strategic plans and projects to meet SOC goals and objectives and to mature, design, and implement improvements to the security operations program
- Work with security engineering, infrastructure security, and security architecture to operationalize newly installed security tools
- Maintain an understanding of the current threat intelligence, detective controls, vulnerabilities, response, and mitigation strategies used in security operations
- Manage the resources in the SOC with regards to detection, response, mitigation, and reporting of cyber threats
- Provide technical guidance to team members in areas of cyber security
- Develop and track security operations metrics
- Manage individual and team performance to consistently meet performance standards
- Develop a deep understanding of operational risks and drive the response process in order to minimize the impact of these risks
- Conduct after-action reviews to identify lessons learned and best practices
Skills, Experience & Competencies
- BS/BA in Computer Science, Computer Engineering, Network Security, Information Security, Information Technology or equivalent work experience
- 3+ years leadership experience within a SOC or MSSP
- 5+ years of experience in information security
- Experience in a leadership position within a Security Operations Center preferred
- Experience working with Security Information Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Endpoint Detection and Response (EDR), Email Security, Threat Intelligence, Firewalls, Web Application Firewalls, Incident Response, Digital Forensics, and/or Threat Modeling is preferred
- Ability to develop and track key performance indicators (KPIs) and metrics for operational success
- Proven leadership skills including effective oral and written communication, performance management, issue resolution, negotiation, motivating team members, forecasting, and planning
- Experience in a security role with strong working knowledge and understanding of information security framework, incident management, operations and application security best practices
- Possession of industry certifications preferred (GIAC, CISSP, CISA, CISM, etc.)
- Experience with staff performance plan development, situational leadership and management responsibilities
- Must be a self-starter with the ability to lead and develop a team of analysts with minimal supervision
Compensation
- Base pay: $120,000 - $165,000 annually. Compensation depends on location, qualifications, and experience.
- Position may be eligible for an Annual Incentive Plan bonus of 10%-50% depending on role level.
- Management level positions may be eligible for sign-on and relocation bonuses.
Benefits
The following benefits are available, subject to employment status:
- Medical, dental, vision, disability, AD&D, and life insurance
- Manager Time Off – 20 days per year
- Discretionary 401k match
- 10 paid holidays per year
- Health savings accounts, healthcare & dependent flexible spending accounts
- Voluntary benefits include pet insurance, legal insurance, accident and critical illness insurance, long term care, elder & childcare, auto & home insurance.
- For Colorado employees, paid leave in accordance with Colorado’s Healthy Families and Workplaces Act is available.
Similar Jobs
What you need to know about the Colorado Tech Scene
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute


