Is this your next challenge in Security Operations and Incident Management?
Main Purpose of the Role:
This role is responsible for the 24x7 detection, triage, response, and recovery of cybersecurity threats across the enterprise. This leader will build and mature SOC capabilities (people, process, technology), ensure high‑fidelity monitoring and rapid incident response, and partner with business and technology leaders to protect revenue‑generating platforms and critical data. The role spans strategic planning, daily operational leadership, vendor management, budget ownership, and continuous improvement of our cyber defense posture.
Key Responsibilities:
1) Strategy & Governance
- Define and own the SOC strategy, roadmap, and operating model (in-house, hybrid, or MSSP/MDR), aligned to enterprise risk appetite and the CISO’s priorities.
- Establish and maintain SOC governance: runbooks, playbooks, escalation paths, RACI, KPIs/SLAs, and reporting to executive and board audiences.
- Lead threat-driven defense: set intel requirements, prioritize detection engineering based on TTPs, crown-jewel assets, and business processes.
2) Security Monitoring & Detection Engineering
- Oversee 24x7 monitoring across SIEM, EDR/XDR, NDR, cloud telemetry, identity, application, OT/IoT (where applicable), and third‑party feeds.
- Direct a detection engineering function to design, tune, and maintain high‑signal rules, analytics, and ML use cases; reduce false positives.
- Implement purple‑team and adversary emulation to validate detections against prioritized threat scenarios.
3) Incident Response & Crisis Management
- Lead the end‑to‑end incident response lifecycle (prepare, detect, analyze, contain, eradicate, recover, lessons learned).
- Chair cyber incident bridges, coordinate with Legal, Privacy, Comms, HR, and Business Continuity/DR during significant events.
- Maintain executive‑ready incident communications and decision support; ensure regulatory reporting and customer notification obligations are met (as applicable by jurisdiction).
- Own tabletop exercises and post‑incident reviews, driving systemic fixes.
4) Vulnerability, Exposure & Attack Surface Management (in partnership with relevant teams)
- Align vulnerability findings with threat intelligence to risk‑rank remediation; provide dashboards to product/infra owners.
- Oversee continuous attack surface monitoring (external & cloud), and ensure responsive takedowns/mitigations for exposed assets.
5) Tooling, Architecture & Automation
- Own the SOC tech stack lifecycle (SIEM/XDR/SOAR/NDR/TI platform/log pipelines/UEBA/sandboxing), including cost, effectiveness, and scale.
- Expand SOAR automation for enrichment, triage, containment, and ticketing to improve MTTA/MTTR and analyst efficiency.
- Ensure logging and telemetry standards are embedded in platform engineering and DevSecOps pipelines (“secure‑by‑design, observable‑by‑default”).
6) People Leadership & Operating Model
- Build and lead a high‑performing, diverse team across shifts (Tier 1–3 Analysts, Threat Hunters, Detection Engineers, IR Leads).
- Define workforce strategy (follow‑the‑sun vs. on‑call), career paths, coaching, and continuous training (certs, labs, purple team).
- Manage MSSP/MDR relationships, SLAs, and service reviews where hybrid models are used.
7) Risk, Compliance & Audit Readiness
- Ensure SOC controls satisfy internal policies and external obligations (e.g., ISO 27001, NIST CSF/800‑61, PCI DSS, SOX ITGC, privacy/data residency, sector regulations).
- Maintain evidence, run control testing, and support audits and customer due diligence.
Do you have experience in Security Operations and Incident Management?
Role Specific Technical Competencies:
- 8–12+ years in cybersecurity with 5+ years leading SOC/IR functions in medium‑to‑large enterprises or MSSP.
- Demonstrated success running 24x7 operations with measurable improvements in detection and response outcomes.
- Hands‑on familiarity with modern SOC tooling (one or more of: Microsoft Sentinel/Defender XDR, Splunk, CrowdStrike, Palo Alto, Google Chronicle, Elastic, Darktrace, Vectra, Wiz/Prisma, Netskope/Zscaler, Mimecast/Proofpoint, Recorded Future/Anomali).
- Strong incident commander experience—coordinating technical, legal, privacy, and executive stakeholders under pressure.
- Expertise in cloud and identity detections (Azure AD/Entra ID, AWS, GCP; SSO/MFA/IGA), and endpoint telemetry.
- Excellent communication—clear writing, exec storytelling, and data‑driven decision making.
Personal attributes:
- Good verbal and written English,
- Communication skills across all levels of personnel; to adequately represent IT and business in articulating implications during an Audit and /or Cybersecurity incident.
- High engagement and Can‑do attitude
- Detective mindset driven to find the root cause or threat actor
- Critical thinking skills with strong attention to detail and follow up
- Demonstrated ability to self‑managing/balancing multiple priorities/responsibilities which may change from time to time
- Strong analytical and problem‑solving skills
- High degree of professionalism and personal integrity
- Ability to work with a high degree of independence
- Collaborative team player
- Possess strong systematic problem‑solving experience, a sense of accountability, ownership and drive
- Maturity, high judgement, negotiation skills, and ability to influence
- Expert in collaboratively managing diverse relationships across geography and culture