Job Responsibilities
Lead the SOC operation
- Own 24x7 monitoring, triage, investigation, and incident response across all shifts, including escalation paths and on‑call coverage.
- Define and enforce SOC runbooks, playbooks, SLAs, and quality standards; audit analyst work for consistency and accuracy.
- Serve as incident commander for P1/P2 security incidents and coordinate with IT, legal, communications, and executive stakeholders through resolution and post‑incident review.
Build and develop the team
- Recruit, onboard, and retain L1–L3 analysts, threat hunters, and detection engineers; manage shift rosters, capacity, and career paths.
- Run structured training, tabletop exercises, and purple‑team sessions; set individual performance goals and conduct regular reviews.
- Create a culture of continuous improvement, documentation, and knowledge sharing.
Drive detection and response maturity
- Own the detection engineering lifecycle: use‑case development, tuning, false‑positive reduction, and coverage mapping against MITRE ATT&CK and priority threat actors.
- Lead adoption of SOAR automation to cut manual effort on repetitive triage and enrichment.
- Integrate cyber threat intelligence into detection content, hunting hypotheses, and client/stakeholder advisories.
- Evaluate and tune SIEM, EDR/XDR, NDR, email security, and cloud security telemetry to close visibility gaps.
Govern, measure, and report
- Define and report SOC KPIs and KRIs (MTTD, MTTR, alert fidelity, coverage, SLA adherence, analyst utilization) to leadership and [clients].
- Maintain SOC documentation and evidence to support audits and frameworks such as ISO 27001, SOC 2, NIST CSF, and [regional regulatory requirements].
- Manage SOC tooling budget, vendor relationships, licensing, and renewals; build business cases for new capabilities.
Engage stakeholders
- Present incident summaries, threat briefings, and service performance to senior leadership and [client CISOs / executive sponsors].
- Act as a trusted advisor on security posture improvements arising from SOC findings.
- [For MSSPs: support pre‑sales with SOC service scoping, SLAs, and onboarding of new clients.]
What You Bring
Required
- 10+ years in cybersecurity, with at least 3 years managing or leading a SOC or incident response team in a 24x7 operational environment.
- Proven experience running a SOC [within an MSSP / for a large enterprise] serving multiple business units or clients.
- Deep hands‑on background in SIEM (Sentinet, securonix), EDR/XDR (e.g., CrowdStrike, Microsoft Defender, SentinelOne), and SOAR platforms.
- Demonstrated incident command experience on major incidents (ransomware, business email compromise, insider threat, cloud compromise) from detection through recovery and lessons learned.
- Strong grasp of attacker tradecraft, MITRE ATT&CK, the cyber kill chain, and threat‑informed defense.
- Working knowledge of network, endpoint, identity, email, and cloud (Azure/AWS/GCP) security telemetry and log sources.
- Experience defining and reporting SOC metrics and SLAs to executive audiences.
- Track record of hiring, developing, and retaining security analysts.
- Excellent written and verbal communication; able to translate technical detail for non‑technical stakeholders.
Certifications (one or more strongly preferred)
- GIAC (GCIH, GCIA, GCFA, GMON, GSOM), CISSP, CISM
- Vendor certifications
Nice to have
- Experience standing up or transforming a SOC (greenfield build, tool migration, or maturity uplift).
- Threat hunting and detection‑as‑code experience (Sigma, KQL, SPL, YARA, Git‑based content pipelines).
- Digital forensics and malware analysis fundamentals.
- Familiarity with OT/ICS or cloud‑native environments.
- Experience with regulatory and sector frameworks
- Scripting or automation skills (Python, PowerShell).
Location: Dubai - SSTC, Dubai, Dubai, United Arab Emirates