Senior Manager, MXDR (Managed Extended Detection and Response) in Augusta, Georgia at Todyl, Inc.
Explore Related Opportunities
Job Description
At Todyl, we are on a mission to protect small and medium-sized businesses from ever-changing cyber threats. The Todyl platform fully integrates threat, risk, and compliance management to provide exceptional and affordable unified cybersecurity solutions to MSPs (Managed Service Providers) and their end customers.
At the end of the day, we're here to keep our partners and customers safe and help them manage the risks and comply with regulations. Protecting others requires a team that works together with trust and cares deeply about carrying out our mission.
Key Responsibilities- Team Leadership: Manage the full MXDR team — DRAMs and analysts — owning 1:1s, performance, career development, hiring and retention, with a cadence that fits shift work and a dispersed team rather than a 9-to-5 one.
- Coverage & Scheduling: Own shift coverage and scheduling approval across day, evening and overnight rotations and the front-of-week / back-of-week split, including PTO and the coverage math behind it.
- Developing the Leads: Develop the Partner Security Advisor (Lead) and the Detection & Response Operations (Lead), holding the line between lead duties and management responsibilities, and build the bench behind them through rotating floor authority.
- Service Delivery: Own SLA definition and attainment for MXDR, the quality of partner-visible output, and the alert-to-case lifecycle in practice — how alerts are worked, when they become cases, and where the handoffs leak.
- Production Ownership: Run incident review for significant events, set the acceptance bar for detection quality with Detection Engineering, and turn findings into changes that hold rather than action items that expire.
- AI in Security Operations: Decide where AI-assisted triage and tuning belong in our workflows and where a person stays in the loop, set the standards for the workflows our practitioners build themselves, and own how we check the output — including saying no to a capability that cannot clear the bar.
- Security Organization Direction: Partner with Detection Engineering, Threat Intelligence and Security Platform Engineering to set direction for the security organization — shared standards, where investment goes, and how the pieces fit together across our teams.
- Partner Escalation: Act as the escalation backstop when a DRAM cannot resolve a situation, hold the relationship with our largest partners, and feed cross-partner patterns into engineering priorities. Routine service reviews stay with the DRAMs.
- Extreme ownership, particularly when things go wrong or aren't completed on time.
- Intrinsic drive for growth; self-motivated, always learning, and focused on raising the bar for self and team.
- Strong bias for action with impact; make tough decisions quickly, measure results, and iterate with clarity to move the mission forward.
- Experience: 7+ years in security operations, incident response or detection and response, including hands-on time working alerts and running incidents.
- Management: 3+ years managing security or technical teams, with experience managing 10 or more people and developing senior individual contributors into leads or first-line managers.
- Distributed & 24/7 Leadership: Experience leading a dispersed team across sites and shifts — on-call, coverage planning, and the realities of managing people you are not in the room with.
- Education & Certifications: Advanced industry certifications (e.g., GCIH, GCIA, CISSP, CISM) preferred. Bachelor's degree or equivalent experience required.
- Domain Knowledge: Working knowledge of how SOCs operate — how analysts work alerts, hunt, and manage cases — with enough depth in detection and response to judge investigation quality and arbitrate technical trade-offs.
- Delivery Discipline: A track record of holding a quality bar through other people rather than by doing the work yourself, and of running a team through a real incident or a bad quarter.
- AI in Production: Hands-on experience running AI in production security workflows — assisted triage, automated enrichment, or AI-assisted tuning. We're more interested in what you learned when it went wrong than in enthusiasm for where it works.
- Cross-Functional Influence: Comfortable being the operator voice to engineering and the engineering-constraint voice to operators, working across boundaries with teams that do not report to you.
- Communication: Strong written communication — post-incident reviews, standards, escalation policy, decision records — and able to hold a technical conversation with an MSP or MSSP partner under pressure.
- Experience at an MDR, MSSP or security vendor delivering a SOC as a service
- Multi-tenant delivery experience, where one customer's volume can affect another
- MSP/MSSP channel experience, where your customer is itself a service provider
- Background in detection engineering or threat intelligence
- Experience standing up or significantly changing a function mid-formation
- SLA attainment holds across detection, triage, escalation and response, including overnight and weekend shifts
- Partners get consistent, high-quality incident write-ups and recommendations under our name
- Both leads grow in scope, with a visible bench behind them
- The team is retained and healthy through a hard quarter, and 24/7 coverage does not burn the people providing it
- AI is doing real work in production with a quality bar that holds, not just usage numbers
- Health & Wellbeing
- Medical, dental, and vision coverage for you and your family
- HSA/FSA options
- Life insurance and short- and long-term disability coverage
- Financial & Future
- Competitive 401(k) to invest in your future
- Flexibility & Time Off
- Hybrid work schedule
- Flexible PTO + 13 company holidays
- Generous parental leave
Compensation: $160,000–$200,000 annually
he actual annual salary for this role will depend on each candidate's experience, qualifications, and location of work, with most new hires placed near the midpoint of the posted range to ensure fairness and consistency across our team. This role also includes variable compensation tied to the retention and expansion outcomes listed above.
Todyl provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, transgender status, gender identity or expression, national origin, age, disability, marital status, genetic information, military status, or any other status protected by applicable federal, state, or local laws.
We encourage you to apply even if you don't meet every requirement listed. We're looking for the best person for the job, who may bring a unique combination of skills and experiences that makes them exceptional even if they don't check every box.
We are looking for a Senior Manager to lead the team behind our Managed Extended Detection and Response (MXDR) service — the Detection & Response Account Managers who own our partners' security outcomes, and the analysts who work alerts, hunt, and respond around the clock.
This is a people leadership role first, and it owns the service. You will be the manager for the entire MXDR team, and you own SLA attainment, response quality, and what partners actually receive. Two leads sit alongside you as senior practitioners owning escalation and quality for their discipline; they are not managers, and the people work does not get delegated to them.
This role reports to the Security leader. The team is dispersed — some in office and some remote, primarily across our Denver, CO and Augusta, GA areas — running day, evening and overnight shifts with a front-of-week / back-of-week split.