Support and lead Security Operations Center (SOC) activities to ensure effective 24/7 monitoring, detection, and response to cybersecurity threats. Act as a bridge between analysts and management while driving operational efficiency and incident response maturity.
Key Responsibilities
- Support day-to-day SOC operations (L1/L2 teams)
- Assist in shift scheduling and roster management for 24/7 coverage
- Act as secondary escalation point for security incidents
- Perform incident analysis, triage, and root cause investigation
- Develop and improve SOPs, playbooks, and use cases
- Work on SIEM, EDR/XDR, and alert tuning
- Ensure log monitoring, correlation, and threat detection
- Track and support certification renewals and upskilling for team members
- Assist in team grievance handling and coordination with management
- Prepare incident reports and dashboards
- Support compliance initiatives (ISO 27001, NIST, etc.)
- Contribute to automation and SOC improvement initiatives
Required Skills
- Hands-on experience with SIEM (Splunk, QRadar, Sentinel)
- Knowledge of EDR/XDR, IDS/IPS, firewalls
- Strong incident response and alert triage skills
- Familiarity with MITRE ATT&CK;
- Basic scripting (Python / PowerShell / Bash)
- Valuable communication and team coordination skills
Preferred Certifications
- CEH / GCIH / GCIA
- (CISSP/CISM pursuing or planned is a plus)