Manager SOC - Cyber Security

KPMG

• $73K — $122K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of technical experience in a SOC environment
  • Relevant security certifications (CISSP, CISM, SANS, CISA, etc.)
  • Hands-on experience with Microsoft Sentinel or similar SIEM technologies
  • Expertise in cloud transformation and security operations
  • Strong communication and mentorship skills.

Responsibilities

  • Serve as primary contact during high-severity incidents, ensuring swift resolution
  • Assess escalated issues for business risk
  • Review and enhance threat detection rules based on log data
  • Collaborate with SIEM Engineers on security event improvements
  • Develop and maintain incident response playbooks
  • Work with CTI teams to refine threat detection and use case development
  • Analyze incidents for process improvements and effectiveness

Benefits

  • Comprehensive and competitive Total Rewards program
  • Opportunities for career advancement within a growing practice
  • Supportive culture for entrepreneurial and dynamic professionals
  • Engagement in a leading cyber security consulting team
Full Job Description
The opportunity We are looking for a dynamic, experienced Cyber security professional to join our growing Cyber Security Services team as Senior Consultant KPMG's leading cyber security practice provides a comprehensive suite of cyber security services, from cyber governance, strategy, defense and response, through to complete end-to-end cyber security transformation services. This is an exciting opportunity for talented, energetic people to join a practice that is experiencing significant growth. We are looking for candidates who have demonstrated academic, business and technical excellence, strong all-around capabilities, and fit with our culture. Individuals who can work in a dynamic, fluid and entrepreneurial environment will excel, and will find a wide range of opportunities within our growing practice. It is an excellent opportunity for those that are looking to work in a firm and department with great career progression opportunities and wanting to be part of building a premier cyber consulting team. Value to the Team: I contribute a substantial amount of practical experience to the team, specifically in the field of cybersecurity and incident response. My adeptness in Azure Sentinel, combined with my proficiency in KQL queries and Threat Use Cases Logic, establishes me as a significant resource. I excel in Incident Response and possess the capability to guide a team of SOC experts as an Incident Commander. Furthermore, I am skilled at clearly communicating the root cause and containment measures to external clients. I am well-versed in playbook automation, adept at crafting effective threat hunting queries, and familiar with EDR/XDR toolsets. Moreover, my background includes hands-on experience in tabletop exercises and collaboration with CSIRT teams. Please note that this role may involve off-hours shift coverage, rotations, or on-call duties. What you will do - Serve as the primary point of contact during high-severity incidents, ensuring swift containment and resolution in collaboration with the CSIRT team, if necessary. - Assess escalated issues from L2 SOC analysts to determine increased risk to the business. - Review log data against security technology rules, proposing enhancements to threat detection. - Collaborate with SIEM Engineers to fine-tune security events and improve alert detection rates. - Develop and maintain incident response playbooks, identifying areas for improvement and suggesting task automation. - Work closely with CTI teams to enhance our threat detection, suggesting threat use cases development based on Tactics, Techniques, Procedures (TTPs). - Analyze critical events and security tickets to evaluate the effectiveness of incident management processes and suggest improvement plans. - Stay updated on security threats, countermeasures, security tools, and advancements in Cloud Security and SaaS technologies. - Track incidents against frameworks such as SANS and MITRE ATT&CK. - Provide technical and thought leadership within the SOC, guiding and teaching other analysts. What you bring to the role - Over 7 years of highly technical experience in a SOC environment. - Relevant certifications such as CISSP, CISM, SANS, CISA, CompTIA Security+, or CompTIA CySA+, GIAC. - Hands-on experience with Microsoft Sentinel or other SIEM and SOAR technologies. - Proficient in Microsoft Defender Endpoint, CSPM/CWP, or similar technologies, with a focus on vulnerability assessment and recommendation. - Experience in malware analysis and reverse engineering. - Business development expertise, including research, analysis, and proposal writing. - Evaluation of control frameworks, risk assessment, and opportunities for enhancement. - Enterprise asset lifecycle management knowledge, including patch management, vulnerability management, security architecture, and endpoint management. - Expertise in cloud transformation, architecture, and security operations. - Leadership experience in managing complex projects. - Strong communication skills, effectively presenting strategies, solutions, and insights to stakeholders. - Leadership role experience, providing mentorship and knowledge sharing to the team and junior/intermediate analysts. KPMG Ontario Region Pay Range Information The expected base salary range for this position is $73,500 to $122,500 and may be eligible for bonus awards. The determination of an applicant's base salary within this range is based on the individual's location, skills & competencies, and unique qualifications. In addition, KPMG offers a comprehensive and competitive Total Rewards program.

Similar Jobs

More Jobs at KPMG

More Information Technology Jobs

Find similar Manager SOC - Cyber Security jobs: