Security Operations Center Lead
Core
Lead global SOC operations including monitoring, alert triage, incident response coordination, and process maturity across multiple time zones.
Role type
Senior IC Security Operations Center Lead
Builds
Production security monitoring, detection use cases, incident response playbooks, and SOC performance metrics
Domain
Cybersecurity / Security Operations
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
SOC operations leadership, incident response coordination, SIEM/SOAR/EDR/XDR management, detection engineering, threat intelligence integration, security metrics analysis, regulatory compliance alignment
Preferred skills
Global SOC transformation, Incident Commander experience, Microsoft Sentinel/Defender XDR/KQL/UEBA, cloud security monitoring (Azure/AWS/GCP), threat hunting, purple-team collaboration, managed security provider management, GenAI-assisted SOC workflows
Technologies
SIEM, SOAR, EDR/XDR, Microsoft Sentinel, Microsoft Defender XDR, KQL, UEBA, Azure, AWS, GCP
Responsibilities
Lead daily SOC operations across monitoring, alert triage, investigation, escalation, and incident response coordination; Own and mature SOC operating procedures including incident intake, severity classification, escalation paths, response playbooks, and post-incident reviews; Build, tune, and continuously improve detection use cases aligned to enterprise risks and MITRE ATT&CK techniques; Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations; Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, and unauthorized access attempts; Establish SOC performance metrics and reporting including alert volumes, false-positive rates, SLA adherence, mean time to detect/acknowledge/contain, and incident trends; Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews; Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions; Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks; Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned; Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready
Seniority
Senior, hands-on IC with leadership responsibilities