Security Operations Manager
Security Operations Manager
EmpiRx Health is the leading clinically-driven pharmacy benefits management company. As the pioneer in value-based pharmacy care, EmpiRx Health puts its customers and members first by enabling them to take control of their pharmacy benefits, healthcare outcomes, and financial results.
We place more emphasis on member care than any other PBM by focusing on health outcomes first. Our pharmacists and clinicians are at the center of everything we do―and our population health solution delivers tailored strategies for our clients. Leveraging our newly launched, AI-powered pharmacy care platform, Clinically™, EmpiRx Health’s pharmacists and client experience teams provide the highest quality pharmacy care to our clients and their members. This enables benefits plan sponsors to keep their members healthy, happy, and productive, while substantially reducing prescription drug spending, which has been on an explosive growth trajectory in recent years.
EmpiRx Health is in unprecedented growth, and we're seeking a highly skilled and experienced Security Operations Manager. In this critical role, The Security Operations Manager leads and matures the organization’s Security Operations Center (SOC) function. This role is responsible for ensuring continuous threat detection, incident response, and identity governance across enterprise systems while strengthening the overall security posture. This leader operates at the intersection of operational security, identity controls, and risk management, driving both real-time defense and foundational access governance in a cloud-first environment.
Key Responsibilities:
Security Operations (SOC):
- Lead and oversee 24x7 SOC operations, including internal teams and/or managed security partners.
- Own threat detection, triage, investigation, and response processes.
- Drive improvements in mean time to detect (MTTD), mean time to respond (MTTR), and incident response maturity.
- Define and operationalize SIEM/SOAR use cases, playbooks, and automation.
- Ensure effective monitoring across endpoints, cloud, identity, and network layers.
- Coordinate incident response with internal teams, legal, compliance, and external partners.
- Lead post-incident reviews and continuous improvement programs.
- Develop SOC metrics, dashboards, and executive reporting.
Identity and Access Management (IAM):
- Own the enterprise IAM program, including identity lifecycle processes for joiners, movers, and leavers.
- Drive role-based access control (RBAC) and least-privilege enforcement.
- Implement and manage Privileged Access Management (PAM/PIM).
- Oversee MFA, SSO, conditional access, and authentication standards.
- Lead access governance, certification campaigns, and audit readiness.
- Reduce manual processes through automation and workflow integration, including tools such as ServiceNow.
- Ensure compliance with SOC 2, HIPAA, and regulatory access requirements.
- Partner with application, infrastructure, and business teams on secure access design.
Leadership and Strategy:
- Lead, mentor, and develop security analysts.
- Define the roadmap for SOC and IAM maturity aligned to NIST CSF and Zero Trust principles.
- Partner with IT, Engineering, Compliance, and business stakeholders.
- Translate technical risks into business impact and decision-ready insights.
- Manage vendors, including SOC providers, IAM platforms, and security tools.
Required Qualifications & Experience:
- 5–7+ years of cybersecurity experience, including leadership experience.
- Strong hands-on expertise in SOC operations, including SIEM, EDR, threat detection, threat hunting and incident response.
- Strong hands-on expertise in IAM, including RBAC, SSO, MFA, PAM/PIM, and lifecycle automation.
- Experience with cloud security; Azure and Microsoft ecosystem experience strongly preferred.
- Knowledge of security frameworks and requirements, including NIST CSF, SOC 2, and HIPAA.
- Proven experience managing incident response and access governance programs.
Preferred Qualifications:
- Certifications such as CISSP, CISM, CRISC, or equivalent.
- Experience managing managed SOC, MDR, or MXDR providers.
- Exposure to Zero Trust and identity-first security models.
- Experience in healthcare or other regulated environments.
Work Environment: Remote
Benefits And Perks
Subject to program eligibility, this position qualifies for a robust suite of benefits including: Paid Time Off, a 401(k) program, Health Insurance including Dental & Vision coverage, Student Loan Reimbursement, Health Savings Account, and an Employee Assistance Program.
EmpiRx Health is an Equal Opportunity Employer
At EmpiRx Health, we wholeheartedly embrace the power of diversity and the magic of inclusion. The kaleidoscope of unique perspectives, backgrounds, and talents fuels our innovation and sets us apart. We're on a mission to build a team as diverse as the world we serve, where everyone is welcome and celebrated. We're not just breaking down barriers; we're actively erasing them to create an environment where opportunity knows no bounds. In unity, we find our strength and invite individuals from all walks of life to join us in our exhilarating journey to shape a brighter, more inclusive future together.
Note: This job description is a general outline of responsibilities and qualifications for the role. Additional duties may be assigned, and the position may evolve to meet the organization's needs.