Cyber Manager - AI SOC at Deloitte
Charlotte, NC
$134,500–$265,100from the description
Jul 29, 2026
Charlotte, NC
Sep 24, 2026
What this job asks for AI summary
A client-facing security engineering manager role at Deloitte's Cyber Defense & Resilience practice, embedded with enterprise clients to design, deploy, and optimize SIEM, SOAR, detection engineering, and AI-assisted security operations workflows. The position involves translating operational requirements into production-ready integrations and automations, mentoring junior practitioners, and leading delivery workstreams across live client environments. Suits an experienced security engineer comfortable with both hands-on technical work and stakeholder engagement.
Senior level · 10+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 5 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 1, 2026. It is a model, not a headcount.
Why we read it this way (6)
The title 'Manager' here is a consulting grade at Deloitte, not a people-management title in the traditional sense — the JD describes a hands-on engineering lead with mentoring responsibilities rather than a team manager with direct reports and budget ownership, which is why this is classified as an individual-contributor security analyst/engineer role rather than 11-3021.
The SOC classification is a genuine judgment call: the role is primarily security analysis and operations engineering (15-1212), but the heavy emphasis on building integrations, automations, and AI-enabled workflows also pulls toward 15-1252 Software Developers.
The degree requirement accepts 'equivalent work experience' in lieu of a Bachelor's degree, so no minimum degree is hard-gated.
Detection engineering is listed as a required area of experience but names no specific platform beyond the general SIEM/SOAR categories; it is captured as a skill reflecting the concrete discipline rather than a generic concept.
Preferred certifications (Security+, GIAC GSES, GCIA, GCIH, CISSP, CCSP, Splunk, cloud security) are listed under Preferred qualifications; Splunk is the only named product among them and is captured as preferred.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): detection engineering.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.