Principal Mission
The SOC Manager is responsible for leading and managing the organizations security operations function, ensuring the effective detection, investigation, response and mitigation of cybersecurity threats. This position provides strategic and operational leadership to SOC personnel, oversees security monitoring and incident response and works closely with IT leadership to protect the organization's technology environment.
Major Responsibilities
• Manage the day-to-day operations of the Security Operations Center.
• Re-establish staffing models, schedules, escalation procedures and operational standards.
• Monitor SOC performance metrics and service level objectives.
• Ensure consistent execution of security monitoring, alert triage, investigation and incident response processes.
• Maintain SOC procedures, playbooks, runbooks and documentation
Monitoring & Incident Response
• Oversee the monitoring and analysis of security events and alerts.
• Direct investigation and response to cybersecurity incidents.
• Coordinate incident escalation and communication with technical teams and management.
• Ensure timely containment, eradication, and recovery from security incidents.
• Coordinate major incident response activities with internal and external stakeholders.
Security Technologies
• Manage and optimize SOC technologies, including:
o SIEM platforms
o SOAR platforms
o Endpoint Detection and Response (EDR)
o Threat intelligence platforms
o Security monitoring and logging technologies
• Evaluate new security technologies and recommend improvements.
• Ensure appropriate security logging, alerting, and monitoring coverage across the enterprise.
• Work with infrastructure and application teams to onboard new systems into security monitoring.
Threat Intelligence & Detection
• Establish processes for identifying emerging threats and vulnerabilities.
• Incorporate threat intelligence into monitoring and detection strategies.
• Develop and improve detection rules, use cases, and correlation logic.
• Conduct threat hunting activities and oversee proactive identification of potential threats.
• Monitor industry trends and emerging attack techniques.
Risk, Compliance & Governance
• Ensure SOC processes align with organizational security policies and regulatory requirements.
• Support internal and external security audits.
• Maintain appropriate documentation and evidence for compliance requirements.
• Partner with the Risk and Compliance teams to address security findings.
• Ensure security incidents are properly documented, tracked, and reported.
Reporting & Management
• Provide regular SOC performance and security-risk reporting to senior leadership.
• Develop dashboards and metrics covering incidents, alerts, response times, trends, and operational performance.
• Communicate significant cybersecurity events and risks to executive management.
Required Qualifications
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent experience.
• 7+ years of experience in cybersecurity, security operations, or related IT security roles.
• 3+ years of experience managing or leading a SOC or security operations team.
• Strong knowledge of security monitoring, incident response, threat detection, and cybersecurity operations.
• Experience with SIEM, EDR, and security monitoring technologies.
• Experience developing security operations processes, procedures, and incident response playbooks.
• Excellent leadership, communication, problem-solving, and organizational skills.
#PFFCUBO