- Oversee daily SOC operations, including alert monitoring, triage, escalation, and incident tracking.
- Lead and mentor SOC analysts, providing guidance on investigations, threat analysis, and response actions.
- Ensure incidents are handled in accordance with SLAs, escalation matrices, and established security procedures.
- Review and validate incident tickets, case notes, and closure details for completeness and accuracy.
- Coordinate with internal teams and external vendors during security incidents and major outages.
- Monitor SOC tools, firewall, email security, and other security platforms for suspicious activity.
- Improve SOC processes, detection rules, playbooks, and reporting to increase efficiency and response quality.
- Prepare and present operational metrics, incident trends, and security reports to management.
- Support incident response activities, including containment, investigation, remediation, and post-incident review.
- Ensure knowledge transfer, training, and cross-skilling within the SOC team.
Educational Background: Computer Science, ECE, Computer Engineering or any IT related course
Certifications Required: Preferably CEH, CCNA or other certificate related to Network and Security
Relevant Skills: Should have an extensive knowledge of Information Technology systems and a deep understanding of the security risks associated with these technologies.
- Experience in security operations, incident response, or threat monitoring.
- Strong understanding of SIEM, EDR, ticketing systems, and security monitoring tools.
- Knowledge of common attack techniques, malware behavior, and detection methodologies.
- Proven ability to lead analysts, manage priorities, and communicate clearly under pressure.
- Familiarity with reporting, documentation, and process improvement in a SOC environment.
- Strong communication skills for working with technical and non-technical stakeholders.
- Ability to make sound decisions quickly during active security events.
Technology Exposure: Should have experience with any of the following;
- SIEM and SOAR platforms
- EDR/XDR tools, such as SentinelOne, CrowdStrike Falcon, and Microsoft Defender for Endpoint.
- Vulnerability scanners, such as Tenable, Qualys, and Rapid7.
- Threat intelligence platforms
- Network analysis tools, such as Wireshark.
- Log management tools.
- Incident response and case management tools, such as ServiceNow
- Endpoint investigation tools, such as Sysinternals, Autoruns, and Process Explorer.
- Malware analysis and sandbox tools.
- Email security platforms.
Related Work Experience: The candidate should have relevant experience in the following;
- Experience with QRadar, SentinelOne, Splunk, Microsoft Defender, or similar platforms.
- Familiarity with MITRE ATT&CK, incident lifecycle management, and threat hunting.• Strong understanding of and ability to operationalize the MITRE ATT&CK framework to develop detection rules for SIEM, EDR, and other security controls.
- Advanced threat hunting across endpoint, identity, network, email, and cloud environments.
- Strong working experience gathering threat intelligence from different sources, and strong understanding of attacker campaigns.
- Deep understanding of attacker TTPs such as advanced persistence, defense evasion, privilege escalation, lateral movement, and data exfiltration.
- Deep understanding of malware behavior, and common forensic artifacts from different operating systems such as Windows, Unix/Linux, and MacOS.
- Strong working experience conducting root cause analysis and incident analysis report.
- Strong experience working in all incident response stages (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned).