We are seeking a highly experienced and technically robust SOC Manager to lead and evolve our Security Operations Center into a mature, engineering-driven, and outcome-focused capability in the AI driven world.
This role requires a hybrid leader who can:
- Drive 24x7 SOC operations excellence
Own SIEM/SOAR engineering detection lifecycle
Collaborate closely with Product Development teams
Influence platform enhancements through operational intelligence
Build and mentor high-performing security teams
Highlight risks and gaps in logging methodologies
Improve security posture across multi-tenant cloud and on-prem environments
Key Responsibilities
SOC Operations Leadership Incident Governance
- Lead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.
Serve as final escalation point (L3/L4) for complex and high-severity incidents.
Define and enforce incident response lifecycle aligned with NIST, ISO 27001, and MITRE ATTCK.
Ensure adherence to SLA / OLA targets (MTTA, MTTR, containment time).
Conduct executive-level incident briefings and publish detailed RCA reports.
Ensure compliance with organizational security policies and audit requirements.
Oversee case quality assurance and investigation standards.
SOC Engineering Detection Engineering
- Own SIEM/SOAR architecture optimization and performance tuning.
Lead log onboarding strategy (cloud, on-prem, hybrid settings).
Ensure proper log normalization, parsing, enrichment, and correlation.
Drive full detection use-case lifecycle:
Threat modelling
Use-case creation
Validation tuning
Performance measurement
Decommissioning of ineffective rules
Reduce alert fatigue through risk-based alerting, contextual enrichment, and behavioural analytics.
Implement detection-as-code practices with version-controlled rule management.
Ensure high ingestion performance and scalable log retention strategies.
Threat Hunting