Senior Security Incident Response Lead

WE Soda

Çankaya

On-site

TRY 400,000 - 800,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

WE Soda is seeking a hands-on Senior Security Specialist to act as the primary internal liaison with our MSSP/SOC, driving cybersecurity incidents from detection through to resolution. You will coordinate with Group IT, Türkiye IT, US IT and external providers to validate alerts, escalate investigations, and document outcomes.

The role requires clear communication with both technical and non-technical stakeholders, decision-making during live events, and turning MSSP/SOC escalations into

Qualifications

  • Minimum 5 years in Security Operations, SOC, or Cybersecurity Operations.
  • Minimum 3 years hands-on investigating and responding to cybersecurity incidents.
  • Direct experience working with, or within, an MSSP/SOC environment.
  • Hands-on experience with LogRhythm SIEM.
  • Experience with EDR tools such as SentinelOne, Microsoft Defender for Endpoint, CrowdStrike, or similar.
  • Good understanding of Microsoft 365 security, Entra ID, MFA, conditional access, and sign-in log analysis.
  • Experience investigating phishing and email security events using Proofpoint, Defender for Office 365, Mimecast, or similar.
  • Good understanding of Windows endpoints, Active Directory, PowerShell basics, firewall logs, VPN logs, DNS, proxy logs, and network security fundamentals.
  • Experience using ITSM tools such as 4me/Xurrent, ServiceNow, Jira Service Management, or similar.
  • Experience working across international teams and multiple time zones is strongly preferred.
  • Exposure to industrial, manufacturing, mining, chemicals, or OT/ICS environments would be advantageous.

Responsibilities

  • Act as the main contact for MSSP/SOC escalations.
  • Review, validate, and challenge security alerts and investigations.
  • Coordinate response to incidents including phishing, malware, ransomware, account compromise, data leakage, insider risk, and third-party security events.
  • Drive containment actions such as endpoint isolation, account disablement, MFA review, email purge, access revocation, and escalation to IT teams.
  • Use LogRhythm SIEM for alarm review, log searches, evidence validation, case support, correlation rules, reporting, and detection tuning.
  • Work with EDR, Microsoft 365 / Entra ID, email security, identity, endpoint, and network security tools.
  • Maintain clear, audit-ready incident records in 4me/Xurrent, including timelines, evidence, actions, decisions, and post-incident reviews.
  • Support improvement of SOC performance, detection use cases, SIEM tuning, and incident response processes.
  • Lead or participate in incident calls across different regions and time zones.

Skills

Security Operations
Incident Response
MSSP/SOC Coordination
LogRhythm SIEM
EDR Tools
Cross-regional Collaboration
English Communication

Tools

LogRhythm SIEM
SentinelOne
Microsoft Defender for Endpoint
CrowdStrike
Proofpoint
Defender for Office 365
Mimecast
4me/Xurrent
ServiceNow
Jira Service Management

Job description

WE Soda is seeking a hands-on Senior Security Specialist to act as the primary internal liaison with our MSSP/SOC, driving cybersecurity incidents from detection through to resolution. You will coordinate with Group IT, Türkiye IT, US IT and external providers to validate alerts, escalate investigations, and document outcomes.

The role requires clear communication with both technical and non-technical stakeholders, decision-making during live events, and turning MSSP/SOC escalations into

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Specialist
Senior Information Security Specialist

WE Soda • Çankaya

On-site
TRY 400,000 - 800,000
Senior Security Leader: Operations & Technical Solutions
Senior Security Leader: Operations & Technical Solutions

DP World • Fatih

Hybrid
TRY 4,233,000 - 6,586,000
Lead Splunk Security Architect — Hybrid (Istanbul)
Lead Splunk Security Architect — Hybrid (Istanbul)

SoftwareOne • Fatih

Hybrid
TRY 600,000 - 900,000
Enterprise-level projects
International environment
Learning opportunities
+1
Security Operations Engineer: Defenses & Incident Response
Security Operations Engineer: Defenses & Incident Response

GİZLİ • Fatih

On-site
TRY 350,000 - 550,000
SOC Analyst: Threat Detection & Incident Response
SOC Analyst: Threat Detection & Incident Response

Paribu • Fatih

On-site
TRY 240,000 - 360,000
Meal allowance
Private health insurance
Commuting support
+8
Senior Cybersecurity & ISMS Lead
Senior Cybersecurity & ISMS Lead

CoreX Holding BV • Sarıyer

On-site
TRY 500,000 - 700,000
Global Cloud Solutions Engineer: Incident Response & HA/DR
Global Cloud Solutions Engineer: Incident Response & HA/DR

Sailglobal • Fatih

On-site
TRY 300,000 - 420,000
IT Infrastructure & Security Operations Specialist
IT Infrastructure & Security Operations Specialist

Nobel Ilac A.S • Ümraniye

On-site
TRY 240,000 - 360,000
SOC Incident Response & Digital Forensics Engineer L3
SOC Incident Response & Digital Forensics Engineer L3

Talentra • Fatih

On-site
TRY 300,000 - 540,000
Senior Information Security Specialist
Senior Information Security Specialist

Pazarama • Kartal

Hybrid
TRY 420,000 - 700,000