Security Operations Lead

Good co India

United Arab Emirates

On-site

AED 350,000 - 750,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Good co India is seeking a seasoned Security Operations Center (SOC) leader to drive security monitoring, threat detection, and incident response across enterprise environments. You will define strategies, standard operating procedures, and playbooks to ensure continuous protection and rapid containment of incidents.

The role requires hands-on expertise with SIEM/SOAR/EDR, plus experience managing SOC teams and coordinating with MSSPs and vendors.

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or related field.
  • 8 to 13 years of experience in Cybersecurity, Security Operations, SOC Management, Incident Response, or Information Security roles.
  • Proven experience leading Security Operations Center (SOC) teams and enterprise security operations functions.
  • Strong hands-on experience with SIEM, SOAR, EDR/XDR, threat detection, incident response, and security monitoring platforms.
  • Experience with MITRE ATT&CK framework, IOC analysis, attack lifecycle, and security investigation methodologies.

Responsibilities

  • Lead and manage SOC activities including security monitoring, threat detection, incident response, and operational improvements.
  • Define and execute security operations strategy, processes, standards, and best practices aligned with enterprise security objectives.
  • Oversee incident response lifecycle including identification, triage, containment, eradication, recovery, and post-incident analysis.
  • Lead threat hunting activities to identify advanced threats, suspicious behavior, and indicators of compromise (IOCs).
  • Manage and optimize SIEM, SOAR, EDR/XDR, and security monitoring platforms.
  • Develop and improve SOC playbooks, incident response procedures, escalation workflows, and operational runbooks.
  • Mentor SOC analysts and security engineers while building technical capabilities within the team.

Skills

SOC Management
Incident Response
Threat Hunting
Security Monitoring
Security Automation
Team Leadership
Stakeholder Communication
Security Operations

Education

Bachelor's degree in Computer Science / IT / Cybersecurity

Tools

Splunk
Microsoft Sentinel
IBM QRadar
ArcSight
LogRhythm
CrowdStrike
SentinelOne
Microsoft Defender
Palo Alto Cortex XDR

Job description

Role & responsibilities
  • Lead and manage Security Operations Center (SOC) activities including security monitoring, threat detection, incident response, and operational improvements.
  • Define and execute security operations strategy, processes, standards, and best practices aligned with enterprise security objectives.
  • Manage SOC teams, analysts, engineers, and security operations workflows to ensure effective 24x7 security monitoring.
  • Oversee incident response lifecycle including identification, triage, containment, eradication, recovery, and post-incident analysis.
  • Lead threat hunting activities to identify advanced threats, suspicious behavior, and indicators of compromise (IOCs).
  • Manage and optimize SIEM, SOAR, EDR/XDR, and security monitoring platforms.
  • Develop and improve SOC playbooks, incident response procedures, escalation workflows, and operational runbooks.
  • Analyze security alerts, investigate complex incidents, and ensure timely response to cybersecurity threats.
  • Drive security automation initiatives using SOAR platforms, scripting, and workflow optimization.
  • Monitor threat intelligence feeds and integrate threat intelligence into security operations processes.
  • Coordinate vulnerability management activities, security assessments, penetration testing support, and remediation tracking.
  • Ensure effective monitoring of network, endpoint, cloud, and application security environments.
  • Collaborate with infrastructure, cloud, application, compliance, and risk teams to strengthen security posture.
  • Manage relationships with MSSPs, security vendors, and external cybersecurity partners.
  • Establish SOC metrics, KPIs, dashboards, and executive security reports.
  • Support security audits, compliance requirements, and regulatory frameworks including ISO 27001, NIST, PCI DSS, and industry standards.
  • Lead security incident reviews, root cause analysis (RCA), and continuous improvement initiatives.
  • Mentor SOC analysts and security engineers while building technical capabilities within the team.

Preferred candidate profile
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Security, or a related technical discipline.
  • 8 to 13 years of experience in Cybersecurity, Security Operations, SOC Management, Incident Response, or Information Security roles.
  • Proven experience leading Security Operations Center (SOC) teams and enterprise security operations functions.
  • Strong hands-on experience with SIEM, SOAR, EDR/XDR, threat detection, incident response, and security monitoring platforms.
  • Experience managing security tools such as Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, LogRhythm, CrowdStrike, SentinelOne, Microsoft Defender, and Palo Alto Cortex XDR.
  • Strong understanding of incident response processes, threat hunting, malware analysis, digital forensics, and cyber threat intelligence.
  • Experience with MITRE ATT&CK framework, IOC analysis, attack lifecycle, and security investigation methodologies.
  • Strong knowledge of network security, endpoint security, cloud security, IAM, PAM, firewalls, IDS/IPS, WAF, and DLP solutions.
  • Experience monitoring and securing AWS, Microsoft Azure, and Google Cloud environments.
  • Strong understanding of cybersecurity frameworks including ISO 27001, NIST CSF, CIS Controls, PCI DSS, and risk management practices.
  • Experience developing SOC processes, playbooks, automation workflows, and operational documentation.
  • Strong leadership, team management, stakeholder communication, and decision-making skills.
  • Experience working with global teams, auditors, regulators, MSSPs, and security vendors.
  • Ability to manage security incidents under pressure and communicate risks effectively to senior leadership.

Preferred certifications
  • CISSP
  • CISM
  • CCSP
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Security Operations Certified (GSOC)
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • CEH
  • CompTIA CySA+
  • Splunk Core Certified Power User
  • AWS Certified Security Specialty
  • Microsoft Cybersecurity Architect Expert
  • ISO 27001 Lead Implementer / Lead Auditor
  • ITIL Foundation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior SOC Analyst
Senior SOC Analyst

Good co India • United Arab Emirates

On-site
AED 180,000 - 300,000
Cyber Security Lead
Cyber Security Lead

Good co India • United Arab Emirates

On-site
AED 420,000 - 840,000
SOC Team Lead (Tier 1)
SOC Team Lead (Tier 1)

Recenso • Abu Dhabi

On-site
AED 200,000 - 250,000
Professional development opportunities
Leadership roles
Collaborative environment
Senior Cyber Security Engineer
Senior Cyber Security Engineer

MEX Group • Dubai

On-site
Information Security Specialist
Information Security Specialist

NMC GROUP SERVICES. • Abu Dhabi

On-site
AED 100,000 - 130,000
Lead SOC Engineer (SIEM) (CPX)
Lead SOC Engineer (SIEM) (CPX)

CPX • Abu Dhabi

On-site
AED 550,000 - 750,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR Technologies Consulting LLC • Dubai

On-site
AED 250,000 - 420,000
Lead SOC Engineer (Devops)
Lead SOC Engineer (Devops)

CPX • Abu Dhabi

On-site
AED 330,517 - 440,690
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

Qode • Dubai

On-site
AED 312,000 - 502,000
Security Analyst – SOC Operations (Level 2)
Security Analyst – SOC Operations (Level 2)

XAD Technologies • Abu Dhabi

On-site
AED 180,000 - 300,000