- Lead daily SOC operations and oversee Tier 1 and Tier 2 analysts.
- Serve as the final technical escalation point for high-severity security incidents.
- Review and approve incident investigations before customer communication.
- Manage customer onboarding into the SOC platform.
- Conduct monthly and quarterly security review meetings with customers.
- Develop and maintain detection rules, use cases, and playbooks.
- Continuously tune SIEM, EDR, and XDR detections to reduce false positives.
- Lead threat hunting and post-incident root cause analysis.
- Ensure compliance with customer SLAs and internal response metrics.
- Create and maintain SOC documentation, SOPs, and runbooks.
- Coordinate with customer IT teams during security incidents.
- Track SOC KPIs and prepare executive reports.
- Mentor analysts and oversee technical training.
Operational Responsibilities
- Ensure 24×7 SOC coverage.
- Review all Critical and High severity incidents.
- Maintain detection quality.
- Improve automation.
- Manage analyst schedules.
- Review customer reports before delivery.
- Handle customer escalations.
- Define SOC processes and standards.
Tasks:
- SLA compliance ≥ 99%
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- False positive rate
- Detection coverage improvements
- Customer satisfaction
- Analyst utilization
- Automation rate
- Incident closure time
|
- Expert knowledge of SIEM platforms (Microsoft Sentinel, QRadar, Splunk, Elastic, etc.)
- Experience with Microsoft Defender XDR, CrowdStrike, SentinelOne, or similar EDR platforms.
- Strong understanding of:
- Windows Active Directory
- Microsoft 365
- Azure
- Linux
- Firewalls
- VPNs
- Networking
- DNS
- Email security
- Familiarity with MITRE ATT&CK
- Experience with SOAR automation
- Incident response and forensic fundamentals
- Ability to write detection logic using KQL, AQL, SPL, Sigma, or YARA
|