SOC Manager

Noventiq Seven Seas Technology

Dubai Emirate

On-site

AED 500,000 - 700,000

Full time

7 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Noventiq Seven Seas Technology is seeking an experienced SOC Leader to run a 24x7 security operations center in Dubai. You will own monitoring, incident response, and runbooks, while coordinating with IT, legal, and executive stakeholders during incidents.

Lead recruitment and development of L1–L3 analysts, drive detection maturity, and integrate threat intel into content and alerts. Strong collaboration with clients and internal teams is essential.

Qualifications

  • Ten+ years in cybersecurity with leadership in SOC/IR.
  • Proven experience running SOC for 24x7 environments and multiple clients or units.
  • Hands-on SIEM/EDR/XDR and SOAR expertise with metrics to improve outcomes.
  • Demonstrated incident command during major incidents and recovery.
  • Strong understanding of attacker tradecraft and MITRE ATT&CK.

Responsibilities

  • Lead 24x7 SOC operations across all shifts with escalation paths.
  • Define runbooks, SLAs, and quality standards; audit analyst work.
  • Serve as incident commander and coordinate with IT, legal, and execs.
  • Recruit, onboard, and retain L1–L3 analysts; manage rosters and careers.
  • Drive detection maturity with MITRE ATT&CK mapping and SOAR adoption.
  • Engage stakeholders with incident summaries and service performance.

Skills

SOC management
Incident response
24x7 operations
SIEM
EDR/XDR
SOAR
MITRE ATT&CK
Threat intelligence
Cloud security
Stakeholder comms

Tools

Sentinet
Securonix
CrowdStrike
Microsoft Defender
SentinelOne

Job description

Job Responsibilities
Lead the SOC operation
  • Own 24x7 monitoring, triage, investigation, and incident response across all shifts, including escalation paths and on‑call coverage.
  • Define and enforce SOC runbooks, playbooks, SLAs, and quality standards; audit analyst work for consistency and accuracy.
  • Serve as incident commander for P1/P2 security incidents and coordinate with IT, legal, communications, and executive stakeholders through resolution and post‑incident review.
Build and develop the team
  • Recruit, onboard, and retain L1–L3 analysts, threat hunters, and detection engineers; manage shift rosters, capacity, and career paths.
  • Run structured training, tabletop exercises, and purple‑team sessions; set individual performance goals and conduct regular reviews.
  • Create a culture of continuous improvement, documentation, and knowledge sharing.
Drive detection and response maturity
  • Own the detection engineering lifecycle: use‑case development, tuning, false‑positive reduction, and coverage mapping against MITRE ATT&CK and priority threat actors.
  • Lead adoption of SOAR automation to cut manual effort on repetitive triage and enrichment.
  • Integrate cyber threat intelligence into detection content, hunting hypotheses, and client/stakeholder advisories.
  • Evaluate and tune SIEM, EDR/XDR, NDR, email security, and cloud security telemetry to close visibility gaps.
Govern, measure, and report
  • Define and report SOC KPIs and KRIs (MTTD, MTTR, alert fidelity, coverage, SLA adherence, analyst utilization) to leadership and [clients].
  • Maintain SOC documentation and evidence to support audits and frameworks such as ISO 27001, SOC 2, NIST CSF, and [regional regulatory requirements].
  • Manage SOC tooling budget, vendor relationships, licensing, and renewals; build business cases for new capabilities.
Engage stakeholders
  • Present incident summaries, threat briefings, and service performance to senior leadership and [client CISOs / executive sponsors].
  • Act as a trusted advisor on security posture improvements arising from SOC findings.
  • [For MSSPs: support pre‑sales with SOC service scoping, SLAs, and onboarding of new clients.]
What You Bring
Required
  • 10+ years in cybersecurity, with at least 3 years managing or leading a SOC or incident response team in a 24x7 operational environment.
  • Proven experience running a SOC [within an MSSP / for a large enterprise] serving multiple business units or clients.
  • Deep hands‑on background in SIEM (Sentinet, securonix), EDR/XDR (e.g., CrowdStrike, Microsoft Defender, SentinelOne), and SOAR platforms.
  • Demonstrated incident command experience on major incidents (ransomware, business email compromise, insider threat, cloud compromise) from detection through recovery and lessons learned.
  • Strong grasp of attacker tradecraft, MITRE ATT&CK, the cyber kill chain, and threat‑informed defense.
  • Working knowledge of network, endpoint, identity, email, and cloud (Azure/AWS/GCP) security telemetry and log sources.
  • Experience defining and reporting SOC metrics and SLAs to executive audiences.
  • Track record of hiring, developing, and retaining security analysts.
  • Excellent written and verbal communication; able to translate technical detail for non‑technical stakeholders.
Certifications (one or more strongly preferred)
  • GIAC (GCIH, GCIA, GCFA, GMON, GSOM), CISSP, CISM
  • Vendor certifications
Nice to have
  • Experience standing up or transforming a SOC (greenfield build, tool migration, or maturity uplift).
  • Threat hunting and detection‑as‑code experience (Sigma, KQL, SPL, YARA, Git‑based content pipelines).
  • Digital forensics and malware analysis fundamentals.
  • Familiarity with OT/ICS or cloud‑native environments.
  • Experience with regulatory and sector frameworks
  • Scripting or automation skills (Python, PowerShell).

Location: Dubai - SSTC, Dubai, Dubai, United Arab Emirates

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Services Delivery Manager
Services Delivery Manager

Noventiq Seven Seas Technology • Dubai

On-site
AED 280,000 - 520,000
SOC Team Lead (Tier 1)
SOC Team Lead (Tier 1)

Recenso • Abu Dhabi

On-site
AED 200,000 - 250,000
Professional development opportunities
Leadership roles
Collaborative environment
SOC Lead
SOC Lead

spiderSilk • Dubai

Hybrid
AED 240,000 - 360,000
Security Operations Center Analyst L1
Security Operations Center Analyst L1

SecurityHQ • Dubai

On-site
AED 60,000 - 120,000
Lead Analyst SOC Monitoring Emirati
Lead Analyst SOC Monitoring Emirati

Talents Tide • Abu Dhabi Emirate

On-site
AED 300,000 - 520,000
SOC And MSS Consultant - SOC L2
SOC And MSS Consultant - SOC L2

iConnect IT Business Solutions DMCC • Dubai

On-site
AED 180,000 - 300,000
Lead SOC Engineer (Devops)
Lead SOC Engineer (Devops)

CPX • Abu Dhabi

On-site
AED 330,517 - 440,690
SOC Manager (Emirati)
SOC Manager (Emirati)

Talents Tide • Abu Dhabi

On-site
AED 300,000 - 480,000
Cloud Security & SIEM Engineer (SOC)
Cloud Security & SIEM Engineer (SOC)

ITHR 360° CONSULTING FZE • Dubai

On-site
AED 180,000 - 300,000
SOC Specialist - Cyber Threats
SOC Specialist - Cyber Threats

DiceTek UAE • Al Ruways Industrial City

On-site