Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
KPMG R.G. Manabat & Co. is seeking a Security Operations Manager to lead the SOC Analysts and ensure 24x7 monitoring, escalation, and incident response. The role coordinates analysts, processes, and technology to meet security objectives and SLAs.
You will oversee SOC engineering, incident response liaison, and deployment of security tools while maintaining KPIs and governance. Strong SIEM/IDS/IPS experience is required, along with ITIL‑based operations discipline.
Roles and Responsibilities:
The Security Operations Manager is responsible for leading the day‑to‑day operations of the SOC Analyst staff. The role coordinates and works with the SOC Analysts to make sure that the analysts, processes, and technology are meeting the SOC security monitoring, analysis, and escalation objectives, organization service level agreements, objectives, and metrics. They are also responsible for communicating with the executive level management team (when deemed necessary) and serving as the principle liaison coordinating incident response functions.
In addition, the SOC Manger will:
Lead the 24x7 delivery team, foster innovation, and drive accountability within SOC engineering.
Oversee the daily activities of the SOC to ensure the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies.
Ensure escalation of cases to the appropriate teams.
Conduct follow-up meetings of escalated or noteworthy cases and modify SOPs and playbooks based on policies, standards and best practices learned from previous cases.
Provide technical oversight for security tool deployment and implementation.
Continuously monitor levels of service as well as interpret and prioritize threats through use of intrusion detection systems, firewalls and other boundary protection devices, and any security incident management products deployed.
Recognize potential, successful, and unsuccessful intrusion attempts and compromises thorough review and analyses of relevant event detail and summary information.
Monitor and proactively mitigate information security risks.
Coordinate shift schedule and deployment of staffing within the established structure.
Manage regular, holiday, illness, vacation and emergency scheduling.
Keep current with the latest vendor updates, expansion opportunities, and technology directions, utilized in the Clients environment.
Ensure daily operational processes effectively support SOC operations objectives.
Ensure the Director of Cybersecurity Services is aware of any issues or incidents.
Own the successful completion of all daily operational processes and procedures.
Ensure analysts follow existing procedures and all procedures are documented in accordance with local guidelines.
Establish operational foundations, defining metrics and KPIs to drive governance, quality, and efficiency. Influence and improve existing processes through innovation and operational change.
Manage staffing, including recruitment, supervision, scheduling, development, evaluation, and disciplinary actions.
Required Technical skills:
Minimum 7 years Security leadership, with experience building long-term career development plans for team members at all levels.
Exceptional operational rigor with extensive real-world experience in ITIL methodologies and frameworks for IT operations.
Experience in designing, implementing and measuring relevant security and technology management critical success factors, key performance indicators, and metrics.
Ability to create shift schedules to ensure 24x7 coverage by support personnel.
In-depth knowledge of modern security concepts and how to apply Advanced scripting knowledge with languages like PowerShell, bash/ksh/sh, Cisco IOS.sh, JunOS sh/csh, Perl, Tcl, Lua.
Familiarity with Azure Sentinel.
Familiarity with common network vulnerability/penetration testing tools including, but not limited to, Metasploit, vulnerability scanners, Kali Linux, and Nmap.
4-6 years’ experience with SIEM tools (Sentinel, Splunk, LogRhythm, etc.).
Familiarity with common IDS/IPS and Firewalls (Snort, Cisco, FortiGate, Sourcefire).
4-6 years’ experience with Incident Response activities .
Company Benefits
HMO with 2 Free Dependents
Communication Allowance
Rice Allowance
Clothing Allowance
Christmas/Holiday Gift (Christmas Cash Gift)
Group Personal Accident Insurance
Life Insurance
Optical/Medicine/Dental Allowance
Bereavement Assistance