Manager, Cyber OT SecOps

United StatesFull-timePosted Aug 7, 2026

Job Description Summary:

Manager, Cyber OT SecOps 

Overview 

The Manager, Cyber OT SecOps is The Coca-Cola Company's operational leader for monitoring, detecting, and responding to cyber threats targeting the industrial control systems and manufacturing technology that keep Coca-Cola production running. This role sits within Cybersecurity Operations and owns the SOC-side of OT security — ensuring that threats to plant floor systems are detected, triaged, investigated, and resolved with the speed and manufacturing context required to protect production, safety, and product quality. 

Reporting to the Senior Director, Cybersecurity Operations, this is an individual-contributor role that also provides day-to-day operational leadership of the managed security service provider (MSSP) SOC analysts supporting OT environments. The Manager builds deep relationships with plant teams to understand how manufacturing operations work, designs detection playbooks calibrated to OT realities, and partners with the OT Cybersecurity engineering team to ensure the right monitoring and detection mechanisms are in place. The role bridges the gap between traditional IT-centric SOC operations and the unique requirements of operational technology environments. 

Key Responsibilities 

OT Security Monitoring & Detection 

  • Own the OT security monitoring and detection capability within the SOC, ensuring comprehensive visibility into threats targeting industrial control systems, SCADA, HMIs, PLCs, historians, and manufacturing networks. 

  • Design, tune, and maintain OT-specific detection rules, alerts, and use cases across OT monitoring platforms (such as Claroty or Microsoft Defender for IoT), EDR, network monitoring (such as Palo Alto), and SIEM. 

  • Continuously evaluate and improve detection coverage for OT-relevant threats, including unauthorized access, network anomalies, configuration changes, and lateral movement between IT and OT environments. 

  • Partner with the OT Cybersecurity engineering team to ensure monitoring tools are properly deployed, configured, and maintained across manufacturing sites. 

OT Incident Triage & Response 

  • Lead the triage, investigation, and response to security events and incidents in OT environments, providing manufacturing context and ensuring response actions account for safety, uptime, and operational continuity. 

  • Develop and maintain OT-specific incident response playbooks, escalation procedures, and communication templates in partnership with SOC leadership and plant teams. 

  • Coordinate with IT SOC, Incident Response, and OT engineering teams during cross-domain incidents that span IT and OT boundaries. 

  • Conduct post-incident reviews and drive lessons learned into improved detection, response, and prevention capabilities. 

Plant Partnerships & OT Context 

  • Build and maintain trusted relationships with plant leadership, plant engineers, and operations teams to understand manufacturing processes, control system architectures, and operational constraints. 

  • Translate plant floor operational knowledge into SOC detection playbooks and triage procedures that reduce false positives and improve response relevance. 

  • Educate SOC analysts and MSSP team members on OT-specific concepts, protocols, and operational considerations. 

  • Support plant visits and site assessments to evaluate monitoring effectiveness and identify coverage gaps. 

MSSP SOC Team Leadership 

  • Provide day-to-day operational direction to MSSP SOC analysts supporting OT monitoring, setting priorities, reviewing alert quality, and maintaining service-level expectations. 

  • Define standard operating procedures, detection playbooks, and training materials for the MSSP team specific to OT environments. 

  • Monitor MSSP performance and drive continuous improvement in OT alert handling, triage accuracy, and escalation quality. 

Reporting & Continuous Improvement 

  • Provide clear, executive-framed reporting to Cybersecurity Operations leadership on OT security monitoring posture, incident trends, detection coverage, and key risks. 

  • Track and report on OT SOC metrics, including alert volume, triage times, detection coverage, and incident outcomes. 

  • Continuously improve OT monitoring capabilities, detection logic, and SOC processes based on evolving threats, plant feedback, and lessons learned. 

  • Support new plant projects, expansions, and technology changes with monitoring requirements and detection design. 

Qualifications 

  • Minimum 6–10 years of progressive cybersecurity experience, with significant focus on security operations and hands-on experience with OT/ICS cybersecurity in manufacturing, industrial, or critical infrastructure environments. 

  • Demonstrated experience operating or leading SOC functions with OT/ICS monitoring responsibilities, including alert triage, incident investigation, and escalation. 

  • Hands-on familiarity with OT monitoring and detection platforms such as Claroty, Microsoft Defender for IoT, or similar, as well as traditional security tools (EDR, SIEM, network monitoring). 

  • Working knowledge of industrial control systems (PLC, HMI, SCADA, historians, DCS) and manufacturing network architectures, including the Purdue Model. 

  • Familiarity with cybersecurity frameworks applicable to OT environments, including NIST CSF, NIST SP 800-82, and ISA/IEC 62443. 

  • Experience providing operational direction to managed service providers or distributed SOC teams. 

  • Strong understanding of IT/OT convergence challenges and the ability to operate effectively at the boundary between IT security operations and plant floor operations. 

  • Excellent communication skills, with the ability to translate OT security risks and incidents into clear language for plant leaders, SOC leadership, and senior executives. 

  • Relevant certifications such as GICSP, GRID, CISSP, CISM, or GCIH are preferred. 

  • Willingness to travel to manufacturing sites to build plant relationships and evaluate monitoring effectiveness. 

Education 

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related field required. 

  • Master's degree or relevant professional certification (GICSP, CISSP, CISM, or equivalent) highly desirable. 

Reporting Relationship 

Reports to the Senior Director, Cybersecurity Operations, within the Chief Information Security Office (CISO) organization. 

No direct reports. Provides day-to-day operational leadership of MSSP SOC analysts supporting OT environments. 

Location 

Atlanta, GA (Global Headquarters) 

Travel 

Estimated up to 20% travel, primarily to Coca-Cola manufacturing sites across North America, with occasional travel to other Company facilities and industry events.

The Coca-Cola Company will not offer sponsorship for employment status (including, but not limited to, H1-B visa status and other employment-based nonimmigrant visas) for this position. Accordingly, all applicants must be currently authorized to work in the United States on a full-time basis and must not require The Coca-Cola Company's sponsorship to continue to work legally in the United States.

Skills:

Pay Range:

United States of America: 124,600 USD - 148,200 USD

Base pay offered may vary depending on geography, job-related knowledge, skills, and experience. A full range of medical, financial, and/or other benefits, dependent on the position, is offered.

Annual Incentive Reference Value Percentage:

15

Annual Incentive reference value is a market-based competitive value for your role. It falls in the middle of the range for your role, indicating performance at target.

Location(s):

United States of America

City/Cities:

Atlanta

Travel Required:

00% - 25%

Relocation Provided:

No

Job Posting End Date:

August 14, 2026

Our Purpose and Growth Culture:

We are taking deliberate action to nurture an inclusive culture that is grounded in our company purpose, to refresh the world and make a difference. We act with a growth mindset, take an expansive approach to what’s possible and believe in continuous learning to improve our business and ourselves. We focus on four key behaviors – curious, empowered, inclusive and agile – and value how we work as much as what we achieve. We believe that our culture is one of the reasons our company continues to thrive after 130+ years. Visit Our Purpose and Vision to learn more about these behaviors and how you can bring them to life in your next role at Coca-Cola.

We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity and/or expression, status as a veteran, and basis of disability or any other federal, state or local protected class. When we collect your personal information as part of a job application or offer of employment, we do so in accordance with industry standards and best practices and in compliance with applicable privacy laws.

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free