Back to search
Agora Linkedin · Posted yesterday

Sr. Security Operations Manager (Global SecOps)

Shanghai

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Role Overview

We are looking for a Senior Security Operations Manager to support and scale Agora’s global SecOps function.


This role will serve as a key regional anchor for 24/7 security operations, helping ensure seamless coverage across time zones while driving incident response, detection engineering, operational maturity, and continuous security improvement.


You will work closely with global teams across security, engineering, infrastructure, and compliance to ensure security operations are consistent, measurable, and aligned with business and regulatory requirements, while also supporting broader operational security programs, including vulnerability management, bug bounty, and penetration testing.


Key Responsibilities

1. Global Security Operations Execution

  • Act as the lead for global SecOps coverage, enabling a follow-the-sun operating model
  • Execute and continuously improve SOC operations, monitoring workflows, escalation paths, and response procedures
  • Partner with global security leadership to implement standardized operating procedures, controls, and reporting

2. Incident Response & Threat Management

  • Lead incident detection, triage, investigation, containment, and response coordination across global environments
  • Serve as a primary responder during APAC hours, ensuring effective coordination and handoff with other regions
  • Drive threat intelligence integration and proactive threat hunting
  • Maintain and improve incident response playbooks, runbooks, and response readiness

3. Detection & Security Tooling

  • Operate and optimize SIEM, SOAR, EDR/XDR, and cloud security tooling
  • Improve alert quality, detection coverage, signal-to-noise ratio, and response automation
  • Partner with engineering teams to enhance security telemetry and logging coverage across infrastructure, APIs, RTC platforms, and AI-related environments

4. Security Monitoring, Metrics & Reporting

  • Develop and maintain operational dashboards and reporting for:
  • Incident trends
  • Detection effectiveness
  • Response performance
  • Security posture metrics
  • Track and report key performance indicators such as MTTD, MTTR, escalation trends, and remediation status
  • Provide regular updates to global security leadership and relevant stakeholders

5. Offensive Security & Exposure Management Support

  • Support and help operationalize bug bounty, vulnerability disclosure, and penetration testing programs
  • Coordinate triage, validation, prioritization, and remediation follow-up for externally identified security findings
  • Partner with internal teams and external vendors to support application, infrastructure, cloud, and product penetration testing
  • Help ensure findings from bug bounty, pentests, and scans are properly tracked, communicated, and remediated
  • Contribute to improving the overall security testing lifecycle by feeding lessons learned back into detections, hardening, and response processes

6. Operational Security & Compliance Support

  • Support:
  • Vulnerability management and remediation tracking
  • Cloud security monitoring
  • Secure configuration and hardening efforts
  • Business continuity and incident readiness
  • Security controls required for SOC 2, HIPAA, and related frameworks
  • Contribute to evidence collection and control operation for audits and compliance reviews

7. Team Development

  • Mentor and guide SecOps analysts and engineers as the function scales
  • Promote operational discipline, accountability, and continuous improvement
  • Act as a strong bridge between regional operations and global security leadership


Qualifications

  • 12-15+ years of experience in cybersecurity
  • 8+ years in SecOps, SOC, incident response, or related security operations role, with leadership or senior-level responsibility
  • Strong hands-on experience with:
  • SIEM platforms such as Splunk, Microsoft Sentinel, or equivalent
  • EDR/XDR tools such as Microsoft Defender or CrowdStrike
  • Cloud environments, preferably AWS
  • Strong understanding of:
  • Incident response, threat detection, and security monitoring workflows
  • Network protocols, system logs, and forensic investigation techniques
  • Threat modeling and attack frameworks such as MITRE ATT&CK and cyber kill chain
  • Strong analytical and problem-solving skills, with the ability to manage multiple priorities under pressure

Preferred Experience

  • Experience supporting global or distributed 24x7 security operations
  • Experience with bug bounty, vulnerability disclosure handling, or pentest coordination
  • Exposure to real-time platforms, large-scale distributed systems, or AI/ML environments
  • Familiarity with SOC 2, HIPAA, or similar security/compliance frameworks
  • Experience in high-growth or pre-IPO environments

Certifications (Preferred)

  • CISSP, GCIH, GCIA, CEH, or equivalent
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search