SOC Manager

Mobilink Microfinance Bank Ltd

Gadap Town

On-site

PKR 2,500,000 - 3,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mobilink Microfinance Bank Ltd is seeking a Manager SOC to oversee the bank’s Security Operations Center. This role focuses on threat detection and incident response while ensuring compliance with regulations.

The ideal candidate will have 5–7 years of cybersecurity experience with a strong background in SOC operations and team management. Key responsibilities include leading SOC operations, coordinating incident responses, and integrating threat intelligence for proactive risk management.

Qualifications

  • 5–7 years of experience in cybersecurity.
  • Minimum 3+ years in SOC operations or incident response leadership.
  • Strong hands-on experience with SIEM, SOAR, Database Activity Monitoring.

Responsibilities

  • Lead end-to-end SOC operations and manage a team of L1–L3 analysts.
  • Coordinate triage, investigation, containment, and remediation of security incidents.
  • Ensure compliance with SBP’s regulations and cyber incident reporting guidelines.

Skills

Leadership in SOC operations
Incident response management
Cybersecurity tools proficiency
Threat intelligence integration
Team mentoring and training

Education

Bachelor’s or Master’s in Information Security or Computer Science

Tools

SIEM
SOAR
XDR
IDS/IPS

Job description

The Manager SOC will oversee and mature the bank’s Security Operations Center (SOC) operations with a focus on threat detection, incident response, and continuous monitoring. The incumbent will lead the integration, optimization, and operation of key security tools including SIEM, SOAR, DAM, XDR, FIM, IDS/IPS, and Active Directory Monitoring. The role ensures timely detection and response to cyber threats while maintaining compliance with State Bank of Pakistan (SBP) regulations and international best practices.

Responsibilities
  • 1. SOC Leadership & Operations
    • Lead end‑to‑end SOC operations and manage a team of L1–L3 analysts.
    • Ensure 24/7 security event monitoring through IBM QRadar SIEM and log aggregation from critical systems.
    • Coordinate use cases, correlation rules, and dashboards aligned with MITRE ATT&CK.
    • Manager SOC may be required to participate in rotational shifts or cover critical shifts to maintain 24x7 security operations coverage.
  • 2. Security Tools Management
    • Administer and fine‑tune SIEM for optimized event correlation and alerting.
    • Oversee SOAR playbook development and integration with SIEM and incident handling processes.
    • Ensure data activity monitoring via Database activity monitoring across databases and sensitive environments.
    • Manage XDR for endpoint, server, and network telemetry visibility and threat detection.
    • Ensure the effectiveness of File Integrity Monitoring (FIM) for policy and compliance alerts.
    • Operate and monitor Intrusion Detection and Prevention Systems (IDS/IPS) and respond to detected threats.
    • Administer Active Directory Monitoring for identity and privilege‑related event tracking and audit trail reporting.
  • 3. Incident Response & Threat Handling
    • Coordinate triage, investigation, containment, and remediation of security incidents.
    • Maintain and test incident response runbooks, including roles for key bank departments (Legal, HR, Compliance).
    • Collaborate with threat intelligence platforms for proactive risk awareness and TTP mapping.
  • 4. Compliance & Reporting
    • Ensure compliance with SBP’s regulations and cyber incident reporting guidelines.
    • Align SOC controls with ISO 27001 Annex A controls and PCI DSS requirements (e.g., logging, monitoring, IR).
    • Maintain reporting dashboards, incident records, and threat metrics for senior management and regulators.
  • 5. Threat Intelligence & Threat Hunting
    • Integrate internal and external threat intel sources into SIEM and SOAR (e.g., Resecurity, IBM XForce).
    • Lead proactive threat hunting exercises and simulate APT scenarios using MITRE ATT&CK mapping.
    • Generate actionable threat briefings, IoCs, and TTP insights relevant to the financial sector in Pakistan.
  • 6. Process Improvement & Automation
    • Continually improve SOC workflows and automate repetitive tasks using IBM SOAR.
    • Review and refine alert thresholds, correlation rules, and suppression logic to reduce false positives.
    • Conduct lessons learned exercises post‑incident and apply insights to SOC maturity roadmap.
  • 7. Team Development & Stakeholder Engagement
    • Train and mentor SOC analysts on tools, response tactics, and regulatory understanding.
    • Facilitate Red and Purple Teaming coordination with IS or third‑party partners.
    • Engage with IT, Risk, and Audit teams for continuous improvement and stakeholder alignment.
Qualifications
  • Education: Bachelor’s or Master’s in Information Security, Computer Science or related.
  • Certifications:
    • Certified Ethical Hacker (CEH) (Required)
    • CISM/CISA/CISSP (Preferred)
    • IBM QRadar / IBM SOAR Certified Specialist (Preferred)
    • GIAC Certified Incident Handler (GCIH), CompTIA CySA+, or equivalent (Preferred)
    • CSA (EC-Council), or Certified Threat Intelligence Analyst (CTIA) (Preferred)
    • ISO 27001 Lead Implementer/Auditor and PCI DSS awareness is a plus
  • 5–7 years of overall experience in cybersecurity.
  • Minimum 3+ years in SOC operations or incident response leadership.
  • Strong hands‑on experience with:
    • SIEM, SOAR, Database Activity Monitoring
    • XDR and FIM
    • IDS/IPS platforms
    • Active Directory Auditing or similar identity audit solutions
    • Integration and management of threat intelligence feeds
Job Location

Head Office

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Manager - 24/7 Threat Detection & Incident Response Lead
SOC Manager - 24/7 Threat Detection & Incident Response Lead

Mobilink Microfinance Bank Ltd • Gadap Town

On-site
PKR 2,500,000 - 3,500,000
SOC Analyst Intern: Hands-on Security & Incident Response
SOC Analyst Intern: Hands-on Security & Incident Response

Safeaeon • Gilgit Division

On-site
PKR 900,000 - 1,500,000
Karachi-based SOC Engineer for Monitoring, SIEM & IR
Karachi-based SOC Engineer for Monitoring, SIEM & IR

Mobiz IT • Karachi Division

On-site
PKR 150,000 - 230,000
Cyber Security Research Specialist
Cyber Security Research Specialist

HBL People • Pakistan

On-site
PKR 2,500,000 - 6,500,000
Cybersecurity SOC Analyst: Path to Threat Hunting & IR
Cybersecurity SOC Analyst: Path to Threat Hunting & IR

Merik Solutions • Islamabad

On-site
PKR 1,200,000 - 2,400,000
SOC Manager
SOC Manager

Abidisolutions • Islamabad

On-site
PKR 2,000,000 - 2,800,000
SOC Analyst
SOC Analyst

Great Computer Solutions • Lahore

On-site
PKR 900,000 - 1,200,000
SOC Analyst L2
SOC Analyst L2

Alykas • Karachi Division

On-site
PKR 1,800,000 - 3,000,000
Cybersecurity Analyst (SOC)
Cybersecurity Analyst (SOC)

Merik Solutions • Islamabad

On-site
PKR 1,200,000 - 2,400,000
SOC Engineer
SOC Engineer

Mobiz IT • Karachi Division

On-site
PKR 150,000 - 230,000