Manager - Security Operations
Job Title: Manager - Security Operations
Role Summary:
We are looking for an experienced SOC Manager to lead and mature the organization's Security Operations capability. The role will be responsible for SOC operations, threat detection, incident response, threat hunting, threat intelligence, SOAR automation, insider threat monitoring and security scripting. The ideal candidate should have a strong combination of people leadership and hands-on technical expertise, with the ability to lead analysts while personally driving complex investigations, threat hunts, automation and detection improvements.
Key Responsibilities:
- Lead day-to-day SOC operations and security monitoring.
- Manage L1/L2/L3 SOC analysts, and threat hunters.
- Lead incident bridges during major cyber incidents.
- Conduct root-cause analysis and post-incident reviews.
- Develop lessons learned and preventive controls.
- Manage staffing, shift planning, training and technical development.
- Ensure adherence to SOC SLAs, KPIs and operational objectives.
- Act as the escalation point for P1/P2 (Major) security incidents.
- Drive continuous improvement of SOC maturity and operational efficiency.
- Establish and lead a proactive Threat Hunting program.
- Develop hypothesis-driven hunts based on adversary behavior and emerging threats.
- Consume and analyze external/internal intelligence feeds.
- Develop threat actor profiles and campaign assessments.
- Automate repetitive SOC analyst activities.
- Develop automated enrichment and response workflows.
- Establish and mature the Insider Threat Detection & Response capability.
- Develop insider-threat detection use cases.
- Support insider-risk investigations while maintaining privacy and compliance requirements.
Required Skills/Qualifications:
- Strong people leadership, mentoring and team-building skills.
- Strong stakeholder-management and cross-functional collaboration skills.
- Ability to balance strategic SOC transformation with hands-on technical execution.
- Experience with SIEM and SOAR platforms, such as CrowdStrike Falcon Next-Gen SIEM and Palo Alto Network Cortex XSOAR.
- Hands-on experience with EDR/XDR solutions, like CrowdStrike Falcon.
- In-depth knowledge of Windows, Linux, Active Directory/Entra ID, Azure Cloud Platform, and networking protocols (DNS, HTTP(s), SMTP, LDAP, TCP/IP).
- Hands-on scripting experience using Python, PowerShell, Bash/Shell, KQL, REST APIs, JSON and Regex.
Preferred Qualifications:
- 9-13 years of experience in cybersecurity, with at least 3 years in threat hunting.
- Relevant certifications such as GIAC Certified Threat Hunter (GCTI/GCTH), GIAC Certified Forensic Analyst (GCFA/GNFA), CISSP, CISA or equivalent certifications.