Posted today · HimalayasSource discovery listing
Senior Manager, Security Operations
Motive
Role details
What you’ll be doing
Who we are: Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. For the first time ever, safety, operations and finance teams can manage their drivers, vehicles, equipment, and fleet related spend in a single system. Combined with industry leading AI, the Motive platform gives you complete visibility and control, and significantly reduces manual workloads by automating and simplifying tasks. Motive serves nearly 100,000 customers – from Fortune 500 enterprises to small businesses – across a wide range of industries, including transportation and logistics, construction, energy, field service, manufacturing, agriculture, food and beverage, retail, and the public sector. Visit to learn more. About the Role: We are hiring a Senior Manager, Security Operations to build, lead and grow Motive 's SOC. This is a founding leadership role — you will shape the team, the tooling, the detection strategy and the operating model rather than inheriting a mature organization and maintaining it. Reporting to the CISO, you will own the full detection and response lifecycle: detection engineering, 24/7 incident response, threat hunting, threat intelligence, security analytics, and endpoint and workload security. The scope spans Motive 's entire estate. Product and production environments cover the cloud infrastructure, services, APIs and data platforms behind Fleet Management, Driver Safety, Spend Management, Workforce Management and AI Vision, plus the connected device fleet. Enterprise and corporate systems cover endpoints, identity and SSO, SaaS applications, network, email and internal tooling. These estates have different telemetry, threat models and response constraints — you cannot contain a production workload the way you isolate a laptop — and a central part of this role is running them as one detection and response capability with one view of the adversary, because real attacks cross the boundary between them. The mandate is coverage: we want to detect everything that goes wrong. That is a deliberately high bar, and it is an engineering problem rather than a staffing problem. We expect this SOC to be built AI-first and data-driven from day one, designed around automation from the start rather than staffing a traditional tiered analyst model and layering automation on later. Success looks like a small, senior, highly leveraged team whose time goes to hard problems, not queue processing. What You’ll Do: Stand up and grow the SOC — operating model, coverage structure, runbooks, escalation paths, hiring and career development for a globally distributed team — and decide the 24/7 coverage model, whether in-house follow-the-sun, MDR-augmented or hybrid Own Motive 's detection strategy and coverage posture across both estates, treating detection content as code and mapping coverage explicitly against MITRE ATT&CK and Motive 's own threat model, with a live view of gaps closed in risk order Extend detection into production and cloud workloads in close partnership with Platform Engineering — the highest-priority coverage expansion for the function — and build detections that span the boundary, since identity compromise on a corporate endpoint pivoting into cloud infrastructure is the attack path that matters most Own 24/7 incident response across product and enterprise environments, serve as incident commander for significant incidents, and be the calm, credible voice to executives when one is underway Own the security telemetry and analytics platform — collection, normalization, enrichment, retention and cost — and instrument the function honestly on MTTD, MTTR, detection coverage, alert precision and automation rate Establish a structured, hypothesis-driven threat hunting program and a threat intelligence capability tailored to Motive 's sector, translating intel into detections, hunts and hardening priorities rather than newsletters Own EDR across the corporate fleet and, with Platform Engineering, runtime and workload protection for production, treating any unmonitored endpoint as an open finding rather than an accepted condition Own the operational side of phishing and social engineering defense — detection, reporting triage, takedown and credential-compromise response — partnering with the Compliance and Trust function, which owns simulation and awareness training Architect the AI-first operating model for the SOC, personally building and iterating on tr