StoneX

Security Operations Center Manager - Americas

Job Locations US-IL-Chicago
Requisition ID 2026-16469
Category (Portal Searching)
Information Technology
Position Type (Portal Searching)
Experienced Professional

Overview

Connecting clients to markets – and talent to opportunity.

With 5,400+ employees and over 80,000 institutional, commercial, and payments clients, we operate from more than 80 offices spread across six continents. As a Fortune 100, Nasdaq-listed provider, we connect clients to the global markets – focusing on innovation, human connection, and providing world-class products and services to all types of investors.

Whether you want to forge a career connecting our retail clients to potential trading opportunities, or ingrain yourself in the world of institutional investing, StoneX Group is made up of four business segments that offer endless potential for progression and growth.

 

Corporate: Engage in a deep variety of business-critical activities that keep our company running efficiently. From strategic marketing and financial management to human resources and operational oversight, you’ll have the opportunity to optimize processes and implement game-changing policies.

Responsibilities

Job Purpose: At StoneX, our Security Operations Center is more than a place where alerts are monitored—it’s where people, technology, intelligence, and increasingly AI come together to protect the business. As the Security Operations Center Manager - Americas, you’ll lead day-to-day security monitoring and response operations while helping shape the next generation of how security operations are performed at StoneX. 

Your mission is to build a Security Operations Center that is operationally strong, continuously improving, and sustainable for the people who work within it. A key part of that mission will be helping build and operationalize StoneX’s agentic Security Operations platform, using AI and automation to transform how we triage alerts, investigate threats, enrich information, orchestrate workflows, and support analyst decision-making. You’ll work closely with our AI, Detection Engineering, Threat Intelligence, and Security Engineering teams to turn emerging capabilities into practical improvements in how we defend the organization.

 

 Primary responsibilities will include: 

  • Operational Leadership: Lead Security Operations Center activities, ensuring monitoring, triage, investigation, escalation, and response processes are consistent, measurable, and aligned with established procedures and service expectations. 

  • AI & Agentic Security Operations: Help shape, build, and operationalize StoneX’s agentic Security Operations platform, partnering with AI engineers and security teams to apply AI and automation across triage, investigation, enrichment, orchestration, and analyst decision support. Ensure capabilities deliver measurable operational value while maintaining appropriate human oversight, governance, and accountability. 

  • People & Culture: Build a healthy, accountable, and sustainable team environment where analysts can perform at a high level without burnout becoming an accepted cost of operating a security function. 

  • Developing People: Coach and develop analysts, providing regular feedback, clear expectations, growth opportunities, and support that strengthens technical capability, judgment, and confidence. 

  • Incident Coordination: Manage escalations and coordinate response activities during priority cybersecurity events, ensuring the right teams and stakeholders are engaged when needed. 

  • Operational Continuity: Ensure effective documentation, communication, and handoffs across regions and time zones so important context and accountability aren’t lost between teams. 

  • Investigation Quality: Drive consistency and quality across investigations, documentation, and reporting through coaching, review, and clearly defined expectations. 

  • Partnership: Work closely with Threat Intelligence and Engineering teams to validate alerts, test detection use cases, improve processes, and strengthen overall detection and response capabilities. 

  • Continuous Improvement: Use operational metrics, team feedback, AI, and automation to improve alert quality, reduce unnecessary noise and repetitive work, strengthen processes, and continuously improve both security outcomes and the analyst experience. 

As the Security Operations Center Manager, a typical week might include the following: 

  • Spending at least four days in the office engaging directly with analysts, security partners, and other stakeholders. 

  • Meeting with analysts to review investigations, operational priorities, challenges, workload, and development opportunities. 

  • Reviewing escalations and priority incidents while helping the team make sound decisions and coordinate response activities. 

  • Coaching analysts through complex investigations and helping strengthen their technical judgment, documentation, and decision-making. 

  • Reviewing operational handoffs and documentation to ensure continuity across regions and time zones. 

  • Partnering with Threat Intelligence and Engineering teams to validate detections, investigate recurring issues, and identify opportunities to improve alert quality. 

  • Partnering with AI engineers, Detection Engineering, and other security teams to identify, test, and operationalize agentic workflows that reduce manual effort, accelerate investigations, and improve analyst decision-making. 

  • Reviewing alert volumes, workloads, operational trends, and team feedback to identify sources of unnecessary friction or fatigue and opportunities where AI, automation, or process improvements can make the team more effective. 

  • Contributing to Security Operations Center reporting, metrics, and continuous improvement initiatives. 

  • Participating in an on-call rotation and providing after-hours leadership support during major cybersecurity incidents or significant operational events. 

  • Occasionally traveling for team meetings, leadership gatherings, or other business needs. 

This job might be for you if: 

  • You’re people-centered – you understand that protecting the business starts with taking care of the people doing the work, and you pay attention to workload, operational pressure, alert fatigue, development, and team wellbeing. 

  • You’re culture-driven – you want to build a team where people feel supported, accountable, comfortable raising concerns, and excited to continue developing their careers. 

  • You’re calm under pressure – when an investigation or incident becomes challenging, people look to you for clarity, direction, and steady leadership. 

  • You’re a coach – you enjoy helping analysts strengthen their technical skills, judgment, confidence, and ability to operate independently. 

  • You’re operationally minded – you value consistency, strong processes, clear handoffs, measurable outcomes, and disciplined execution. 

  • You’re collaborative – you know effective cyber defence depends on strong partnerships between Security Operations, Threat Intelligence, Engineering, and other technology teams, and you’re comfortable working with diverse teams and perspectives across the globe. 

  • You’re excited about what’s next – you want to be at the forefront of how AI and agentic technologies are changing security operations, and you’re energized by turning emerging technology into practical capabilities that make analysts and defenders more effective. 

  • You’re comfortable making decisions – you can assess the information available, make sound decisions quickly, and adjust as circumstances change. 

  • You’re improvement-focused – you challenge unnecessary noise, repetitive work, and inefficient processes rather than accepting burnout and constant firefighting as simply part of security operations. 

Qualifications

To land this role: 

  • 3+ years of Security Operations Center or incident response experience, with demonstrated leadership, mentoring, or people management experience. 

  • Strong experience triaging security alerts, investigating incidents, and interpreting detection content. 

  • Strong communication skills with the ability to coach others, lead during high-pressure situations, and document investigations clearly. 

  • Experience monitoring and investigating threats across cloud and on-premises environments. 

  • Familiarity with scripting or security query languages such as SPL, KQL, or similar technologies. 

  • Ability to make sound decisions quickly, manage shifting priorities, and positively influence team performance during critical situations. 

 

what will make you stand out:

  • Experience with MITRE ATT&CK, threat hunting, or detection engineering concepts and practices. 

  • Experience with security orchestration, automation, and response platforms. 

  • Familiarity with metrics-driven Security Operations Center management and continuous improvement practices. 

  • Experience applying AI, automation, or emerging technologies to security operations, including areas such as alert triage, investigation, enrichment, analyst decision support, or workflow orchestration.  

  • Familiarity with agentic AI concepts, responsible AI practices, and the opportunities and risks associated with introducing autonomous or semi-autonomous capabilities into security operations. 

  • Formal leadership training or experience managing geographically distributed teams. 

  • Associate’s or bachelor’s degree in Cybersecurity, Information Technology, or a related field. Equivalent professional experience and non-traditional paths are welcomed. 

  • Certifications such as GCIH, GCIA, SC-200, or similar practitioner-level credentials. 

Working Environment: 

  • 4 days in office per week

 

Hiring Salary Range $150,000 - $180,000. Salary to be determined by the education, experience, knowledge, skills and abilities of the applicant, internal equity and alignment with market data.)   Subject to business performance and recommendations of management, this role may be eligible to participate in an incentive compensation plan.  This compensation package, in addition to a full range of medical, financial, and/or other benefits, dependent on the position, is offered. 

 

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed