19 Aug
|
Teamficient
|
India
SOC Manager
Location: Remote (Global)
Employment Type: Full time
Compensation: $1000 - $1500 (negotiable for highly experienced)
Position Overview
We are seeking an experienced Security Operations Center (SOC) Manager to lead and strengthen our cybersecurity operations. The SOC Manager will be responsible for overseeing day-to-day security monitoring, incident detection and response, threat analysis, team performance, and continuous improvement of SOC processes and capabilities.
This role requires a strong combination of technical cybersecurity expertise, incident management experience, leadership, and operational discipline. The ideal candidate can effectively manage a team of security analysts while also working closely with customers, engineering teams, leadership, and other stakeholders during security incidents.
What You'll Do
Operations & Incident Response
- Own daily SOC operations and ensure monitoring/response coverage meets SLA commitments (including after-hours and weekend coverage as needed).
- Set escalation criteria and ensure incidents are triaged, investigated, contained, and resolved appropriately across Tier 1–3.
- Act as the senior escalation point for high-severity or ambiguous incidents, coordinating across internal teams, customers, and vendors.
- Ensure every incident is documented to a standard that supports post-incident review, compliance evidence, and customer reporting.
Detection & Threat Management
- Partner with detection engineering to tune SIEM correlation rules, reduce false positives, and close detection gaps.
- Oversee or perform threat hunting, malware analysis, and threat intelligence integration.
- Track detection coverage against MITRE ATT&CK; and drive prioritized improvements.
Process & Reporting
- Build and maintain SOC playbooks, SOPs, and incident response plans — and keep them current as the threat landscape and tooling change.
- Own SOC KPIs (MTTD, MTTR, SLA adherence, false-positive rate, alert-to-incident conversion) and report on them to leadership and customers.
- Run post-incident reviews and ensure findings actually get incorporated into controls and playbooks, not just documented.
- Support customer onboarding: establishing monitoring scope, alerting thresholds, and escalation paths for each new environment.
Team Leadership
- Manage, coach, and develop a team of Tier 1–3 analysts: set expectations, run 1:1s and performance reviews, and build career-growth plans.
- Own scheduling, workload distribution, and on-call rotation across a distributed, global team.
- Identify skill gaps and support hiring and interviewing as the team grows.
Required Qualifications
- 5+ years in cybersecurity, security operations, or incident response.
- 2+ years managing or leading SOC analysts or a security team.
- Hands-on experience with SIEM platforms (Wazuh, Microsoft Sentinel, Splunk, and Elastic Security).
- Experience with EDR/XDR tooling (Microsoft Defender, CrowdStrike, SentinelOne, or similar).
- Solid understanding of network, endpoint, identity, and cloud security, and common attacker techniques.
- Working knowledge of MITRE ATT&CK; applied to real investigations.
- Track record building or improving IR procedures, playbooks, and escalation processes.
- Ability to explain a complex incident clearly to both an engineer and a non-technical customer.
- Strong written English — you'll be producing incident write-ups and executive summaries regularly.
Preferred Qualifications
- Experience at an MSSP, MDR provider, or managed services organization, ideally supporting multiple customer environments simultaneously.
- Relevant certifications: CISSP, CISM, GIAC (GCIH/GCIA), CySA+, Security+, or SC-200.
- Experience with AWS, Azure, and/or GCP security.
- Experience with SOAR platforms and security automation.
- Familiarity with NIST CSF, NIST 800-61, ISO 27001, SOC 2, PCI DSS, or CIS Controls.
- Experience running tabletop exercises or acting on pentest findings.
Key Performance Indicators
Success in this role may be measured through:
- MTTD / MTTR trends
- SLA compliance
- False-positive reduction and alert-to-incident conversion
- Incident resolution quality and post-incident corrective action completion
- Customer satisfaction
- Analyst retention and growth
- Detection coverage and playbook maturity
Core Competencies
- Cybersecurity Operations Leadership
- Incident Response
- Threat Detection and Analysis
- Security Monitoring
- Team Development and Coaching
- Customer and Stakeholder Communication
- Process Improvement
- Security Automation
- Risk Management
- Technical Troubleshooting
- Decision-Making Under Pressure
- Documentation and Reporting
Pay: ₹95,783.55 - ₹143,675.33 per month
Work Location: Remote
📌 Cybersecurity SOC Manager (India)
🏢 Teamficient
📍 India