Job Locations
US-IL-Plainfield | US-IL-Chicago
| Category/Function |
Information Technology
|
Position Type |
Regular Full-Time
|
Requisition ID |
2026-20512
|
Workplace Type |
On Site
|
Overview
Old National Bank has been serving clients and communities since 1834. With over $70 billion in total assets, we are a regional powerhouse deeply rooted in the communities we serve. As a trusted partner, we thrive on helping our clients achieve their goals and dreams, and we are committed to social responsibility and investing in our communities through volunteering and charitable giving. We continually seek highly motivated and talented individuals as our people are critical to our success. In return, we offer competitive compensation with our salary and incentive program, in addition to medical, dental, and vision insurance. 401K, continuing education opportunities and an employee assistance program are also included in our benefit suite. Old National also offers a variety of Impact Network Groups led by team members who are passionate about driving engagement, creating awareness of diverse backgrounds and experiences, and building inclusion across the organization. We offer a unique opportunity to join a growing, community and client-focused company that is firmly rooted in its core values.
Responsibilities
We are seeking a hands-on Security Operations Center (SOC) Manager to turn our Microsoft Sentinel and Microsoft Defender XDR foundation into a high-performing, intelligence-driven SOC. This technical leader will guide internal analysts and MSSP-supported operations while improving detection quality, investigation workflows, incident response, automation, telemetry management, KPI/KRI dashboards, and analyst development. The ideal candidate has senior/Tier 3-level SOC experience and is ready to build the operating model, metrics, capabilities, and team culture that take our cyber defense program to the next level. Salary Range The salary range for this position is $98,4/yr - $199,000/yr plus bonus. The base salary indicated for this position reflects the compensation range applicable to all levels of the role across the United States. Actual salary offers within this range may vary based on a number of factors, including the specific responsibilities of the position, the candidate's relevant skills and professional experience, educational qualifications, and geographic location. Key Accountabilities
Lead daily SOC operations across internal and MSSP-supported monitoring, alert triage, investigation, escalation, incident response, threat hunting, and continuous improvement.
- Own and evolve the MSSP relationship, including eyes-on-glass coverage, initial triage, handoffs, escalation quality, shared metrics, service improvement, and alignment to the internal SOC operating model.
- Implement, evaluate, and govern AI-assisted investigation and response capabilities that improve speed, consistency, evidence quality, and analyst effectiveness.
- Ensure appropriate SOC staffing, workload balance, shift handoffs, on-call readiness, and escalation coverage across internal, MSSP-supported, and hybrid operating models.
- Define, visualize, and improve SOC KPIs and KRIs through dashboards and recurring reporting that connect operational performance, control effectiveness, risk trends, and business impact.
- Mature Microsoft Sentinel capabilities, including analytics rules, KQL, workbooks, automation, playbooks, data connectors, parsing, and cost-aware log ingestion decisions that route high-value telemetry to Sentinel and lower-value or historical data to lake, archive, or cold storage.
- Use Microsoft Defender XDR to connect signals across endpoint, identity, email, and cloud app activity, improving incident correlation, advanced hunting, investigation quality, and response speed.
- Improve detection quality through false-positive reduction, coverage-gap closure, MITRE ATT&CK alignment, threat intelligence, hunting, validation testing, and purple-team lessons learned.
- Establish detection and use-case lifecycle governance, including ownership, documentation, testing, tuning, retirement, and periodic coverage reviews.
- Lead, coach, and develop SOC analysts through mentoring, technical reviews, structured training, investigation walk-throughs, tabletop exercises, and hands-on skill development.
- Coordinate major incident response, including playbook execution, escalation paths, evidence handling, executive-ready communications, after-action reviews, and response improvement.
- Partner with infrastructure, cloud, endpoint, identity, vulnerability management, governance, legal, compliance, privacy, and business teams to improve visibility, control effectiveness, and response readiness.
Key Competencies for Position
- Develops Talent - Advocates for talent development as an organizational imperative and develops people according to talent strategy needs cultivating a diverse succession "pipeline". Continuously assesses talent across the bank to develop an understanding of capabilities and potential and leverages talent as a corporate resource to meet needs today and into the future. Cultivates an environment of trust and optimizes others' talents and capabilities across the organization, driving a culture of continuous coaching and feedback. Retains, attracts and recruits top diverse talent leveraging opportunistic hires to meet current and future people needs at Old National.
- Promotes Change - Explains the business need, impact, and anticipated benefits of the change while engaging stakeholders to gain buy-in. Shapes and transforms culture by building an organizational culture of change agility. Manages risk associated with the change through appropriate contingency planning. Promotes change where it is needed to stay relevant and successful while creating conditions for team members to creatively generate new ways to enhance Old National's ability to succeed.
- Strategy in Action - Develops, communicates, and aligns organization with a clear vision and strategy empowering team members to take action. Maintains a strong network of advisors and leverages resources to stay current on emerging trends and market factors that may influence ONB's strategy. Envisions how Old National's responses to trends may impact our longer-term vision and strategy while formulating a clear strategy that will accelerate ONB towards its strategic goals. Challenges the status quo to develop new ways of thinking encouraging curiosity beyond the current state. Conveys opportunities to realize the organization's purpose, strategy, and culture in a way that captures attention, arouses emotion and compels others to act despite obstacles.
- Compelling Communication - Conveys transparent messages logically, simply, succinctly and at the right pace while being in command of the message. Captivates audience through compelling language tailored to the audience's expectations and communication style. Checks for understanding and presents messages in different ways to enhance receiver's understanding. Listens and objectively considers others' ideas and perspectives while encouraging others to do the same while addressing negative reactions to others' ideas that jeopardize this open exchange.
- Makes Decisions & Solves Problems - Analyzes, contrasts, combines and compares data to define the most relevant organizational problems and opportunities and gain clarity on potential impact. Creates sound strategies by gathering information through listening, deep questions, challenging assumptions and collaborating with networks in and outside of Old National. Aligns efforts and resources around blue chips and formulates decisions on relevant factors (e.g., costs, benefits, buy-in, risks) with the greatest potential for positive impact. Sets strategic direction for short-and long-term goals while remaining agile to adjust plans to close current gaps, modifying priorities as circumstances change.
- Delights Clients - Cultivates an environment where team members passionately serve internal/external clients with excellence. Promotes a growth mindset culture by keeping current with development and trends in industry and sharing information to build knowledge base of organization and net promotor score. Understands data, metrics and/or financial information and how they tie to clients, business outcomes, organization and industry. Empowers a culture of accountability across the organization where all team members nurture client relationships by listening, prioritizing, and acting responsibly to meet client needs, mitigate risk and add shareholder value.
- Leads Inclusively - Advocates the value of diversity as a competitive advantage and initiates and champions inclusive recruiting and development processes that challenge the status quo, when necessary, to increase diversity in the workplace. Sets up outreach systems and processes that seek ideas, opinions, and insights from diverse sources and while optimizing effectiveness by aligning individuals' unique talents, interests and abilities with the most relevant roles and responsibilities. Thinks with an inclusive lens promotes inclusion by actively leading DEI initiatives while encouraging all team members to engage in DEI experiences. Demonstrates self-awareness, admits mistakes and seeks feedback from all levels within Old National while acknowledging and challenging bias (conscious and unconscious) and exclusionary behavior.
- Personifies ONB Culture - Instills confidence in one's actions and outcomes consistent with Old National's culture. Promotes the organization's vision, strategy, and values while recognizing behavior that supports the vision and values. Conveys opportunities to realize the organization's purpose, strategy, and culture in a way that captures attention, arouses emotion and compels others to take action despite obstacles. Inspires others to personally contribute to the organization's success for the long term by investing time, heart, and expertise to help clients and communities thrive.
Required Qualifications and Education Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent hands-on experience.
- 7+ years of hands-on cybersecurity operations experience, including at least 2 years in a SOC manager, SOC lead, or senior/Tier 3 technical SOC role.
- Experience managing SOC staffing, coverage models, shift handoffs, on-call expectations, workload distribution, or capacity planning in an internal, MSSP-supported, or hybrid SOC environment.
- Experience hiring, onboarding, coaching, and performance-managing SOC analysts or security operations team members.
- Strong hands-on experience with Microsoft Sentinel and log pipeline tooling such as Cribl, including KQL, analytics rules, incidents, workbooks, automation, parser development, SIEM tuning, and cost-aware telemetry decisions that shape, filter, enrich, route, and optimize security logs before they reach Sentinel or longer-term storage.
- Strong hands-on experience with Microsoft Defender XDR and related Defender products, especially endpoint, identity, email, cloud app, incident correlation, advanced hunting, and response workflows.
- Demonstrated ability to build, track, visualize, and improve SOC KPIs, KRIs, dashboards, and operational reporting that show security value, risk reduction, and team effectiveness.
- Deep understanding of incident response, security monitoring, telemetry, identity-based attacks, cloud security, malware behaviors, adversary tactics, and the development of playbooks, escalation models, detection logic, threat hunting methods, and analyst enablement materials.
- Experience with scripting or automation using PowerShell, Python, KQL, Logic Apps, APIs, or similar tools.
- Familiarity with MITRE ATT&CK, threat modeling, cyber kill chain concepts, and mapping detections to adversary behaviors.
- Experience managing or partnering with an MSSP, MDR provider, or outsourced SOC function, including service expectations, escalation quality, operational handoffs, continuous improvement, shared metrics, and vendor accountability.
- Ability to set clear expectations, prioritize work, hold teams accountable, and create a culture of operational excellence and continuous improvement.
- Strong communication skills with the ability to explain technical findings, operational risk, and incident status to technical teams, business stakeholders, and leadership.
Preferred Qualifications
- Experience leading SOC modernization, SIEM migration, Defender XDR rollout, Sentinel detection content lifecycle management, or security automation initiatives.
- Experience in financial services, banking, regulated environments, or organizations with mature governance, risk, compliance, audit, and privacy expectations.
- Relevant certifications such as CISSP, GCIH, GCIA, GCFA, GNFA, GMON, SC-200, AZ-500, MS-500, OSCP, or equivalent practical experience.
- Experience with cloud security across Azure, AWS, or GCP, including cloud logging, identity, workload protection, and incident response.
- Experience designing purple-team scenarios, validating detections, and turning exercise results into measurable improvements.
- Experience with malware analysis, forensics, endpoint investigation, memory analysis, or advanced incident response techniques.
- Knowledge of regulatory and control frameworks such as NIST CSF, NIST 800-53, FFIEC, ISO 27001, PCI DSS, CIS Controls, or related guidance.
Old National is proud to be an equal opportunity employer focused on fostering an inclusive workplace and committed to hiring a workforce comprised of diverse backgrounds, cultures and thinking styles. As such, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, status as a qualified individual with disability, sexual orientation, gender identity or any other characteristic protected by law. We do not accept resumes from external staffing agencies or independent recruiters for any of our openings unless we have an agreement signed by the Director of Talent Acquisition, SVP, to fill a specific position. Our culture is firmly rooted in our core values. We are optimistic. We are collaborative. We are inclusive. We are agile. We are ethical. We are Old National Bank. Join our team!
|