Security Operations Center and Incident Response Manager
Core
Lead and manage an organization's Security Operations Center (SOC), handling incident identification, assessment, reporting, mitigation, and monitoring to protect against threats.
Role type
Manager, Security Operations Center and Incident Response
Builds
SOC operational capabilities, incident response programs, threat detection use cases, and security monitoring dashboards
Domain
Cybersecurity & Privacy
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOC management, incident response management, threat modeling, SIEM integration, vendor management, forensic investigation support, stakeholder liaison, security event logging, cloud monitoring tools implementation, periodic threat simulation
Preferred skills
CISSP, CISM, CEH, GCIH certifications, second degree in related field
Technologies
SIEM, cloud monitoring tools
Responsibilities
Lead and manage the SOC; Identify, assess, quantify, report, communicate, mitigate, and monitor security incidents; Ensure compliance to SLAs and process optimization; Manage team and vendors; Perform threat management and modeling; Integrate logs into SIEM; Create reports and dashboards for executive management; Develop and maintain incident response plans; Implement cloud monitoring tools; Create security rules for alerting; Conduct threat simulation activities; Maintain incident databases; Support forensic investigations; Liaise with stakeholders for IOC isolation and remediation
Seniority
Manager, hands-on leadership with team and vendor management