Security Operations Centre Manager
Core
Lead the operational performance of a 24x7x365 Security Operations Centre (SOC), managing analyst teams (L1-L3), workflow automation, and incident response for Managed Detection & Response (MDR) services.
Role type
Senior IC Security Operations Centre Manager
Builds
Operational readiness and service delivery for MDR clients
Domain
Cybersecurity / Managed Detection & Response (MDR)
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOC operations management, team leadership (L1-L3), rostering and capacity planning, incident response coordination, workflow and triage automation strategy, SIEM/SOAR/EDR technical understanding, risk assessment, compliance management (ISO 20001/27001/SOC 2), client escalation handling
Preferred skills
Experience with MSSP environments, knowledge of DFIR processes, ability to mentor analysts into engineering specializations
Technologies
SIEM, SOAR, EDR
Responsibilities
Lead, coach, and manage SOC analysts across L1 to L3 tiers; own rostering, scheduling, and capacity for 24x7x365 operations; drive the SOC automation roadmap and review playbook logic; ensure day-to-day operations meet SLAs and KPIs; act as senior escalation contact for key MDR clients; maintain SOC processes aligned with ISO standards; drive incident simulation planning and post-incident reviews; define operational requirements for SOC tooling and workflow; partner with Platform Engineering on detection improvements and feedback loops.
Seniority
Senior, hands-on IC