The SOC Manager leads the Security Operations Center's people, processes, and technology to detect, investigate, and respond to cybersecurity threats across the organization on a 24x7x365 basis. This role owns the SIEM/SOAR platform strategy, drives proactive threat hunting and intelligence integration, and ensures the SOC operates with strong governance, automation, and continuous improvement. The SOC Manager acts as a key crisis leader during security incidents and serves as a trusted communicator to technical teams and executive stakeholders alike.
Key Responsibilities
Security Operations Leadership
- Own and manage 24x7x365 SOC operations, ensuring continuous monitoring, detection, and response coverage across all shifts, including nights, weekends, and holidays.
- Design and maintain shift schedules, staffing models, and follow-the-sun or on-call rotations to guarantee round-the-clock coverage without gaps.
- Lead the SOC's daily operations, including shift coverage, escalation paths, and performance metrics (MTTD, MTTR, alert volume/quality).
- Define and continuously improve SOC processes, playbooks, and standard operating procedures.
- Set strategic direction for the SOC in alignment with overall security and business objectives.
Incident Response & Crisis Management
- Serve as incident commander for high-severity security incidents, coordinating containment, eradication, and recovery.
- Maintain and regularly test the incident response plan, including tabletop exercises and post-incident reviews.
- Coordinate cross-functional crisis response with IT, legal, communications, and executive leadership as needed.
Threat Detection & Hunting
- Direct proactive threat hunting programs to uncover hidden or emerging threats not caught by existing detections.
- Continuously refine detection logic and use cases based on the evolving threat landscape and lessons learned from incidents.
SIEM/SOAR Management
- Own the SIEM and SOAR platforms end to end , architecture, content development, tuning, and health monitoring.
- Partner with engineering to ensure adequate log source coverage, data quality, and retention.
Threat Intelligence
- Integrate internal and external threat intelligence into detection engineering, risk assessments, and briefings.
- Track relevant threat actors, TTPs, and campaigns to inform SOC prioritization.
Cybersecurity Risk Management
- Assess and communicate operational security risks, partnering with stakeholders on remediation prioritization.
- Support exception processes with clear, well-documented rationale.
Security Automation
- Drive automation initiatives (SOAR playbooks, scripting, orchestration) to reduce manual effort and improve response times.
- Identify opportunities to eliminate repetitive analyst tasks through tooling and process redesign.
People & Stakeholder Management
- Hire, coach, and develop SOC analysts and engineers; manage performance, staffing, and shift schedules.
- Build strong partnerships with IT, engineering, legal, and compliance stakeholders.
Security Governance and Compliance
- Ensure SOC operations align with internal policy, regulatory requirements, and audit/compliance obligations.
- Maintain accurate documentation, metrics, and evidence to support audits and governance reviews.
Communication
- Deliver clear, concise incident reports, summaries, and operational updates to technical and non-technical audiences.
- Represent the SOC in cross-functional meetings and executive briefings.
Core Competencies
- Security Operations Leadership - Directs the day-to-day operation of a 24x7x365 Security Operations Center (SOC), setting priorities, shift structures, and performance standards to ensure continuous, high-quality monitoring and defense coverage around the clock.
- Incident Response & Crisis Management - Leads end-to-end incident response for security events, coordinating containment, eradication, and recovery efforts, and acting as incident commander during high-severity or crisis-level events.
- Threat Detection & Hunting - Oversees proactive threat hunting activities and continuously improves detection logic to identify adversary behavior, novel attack techniques, and gaps in existing coverage.
- SIEM/SOAR Management - Owns the SOC's SIEM and SOAR platforms end to end , use-case development, correlation rule tuning, playbook design, and platform health , to maximize detection fidelity and response speed.
- Threat Intelligence - Integrates threat intelligence feeds and analysis into SOC operations to inform detection priorities, risk assessments, and proactive defense measures against relevant threat actors.
- Cybersecurity Risk Management - Evaluates and communicates operational security risk, working with stakeholders to prioritize remediation and ensure risk decisions are made with accurate, timely information.
- Security Automation - Champions automation of repetitive SOC tasks and response workflows to reduce mean time to detect/respond and free analyst capacity for higher-valu