Security Operations Center Lead
Summary
Lead a global Security Operations Center, overseeing 24/7 monitoring, incident response, and threat detection using SIEM/SOAR/EDR/XDR tools to protect enterprise assets across cloud and on-prem environments.
Job Details:
Job Description:
Key Responsibilities
- Lead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.
- Own and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.
- Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.
- Build, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.
- Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.
- Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.
- Establish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.
- Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.
- Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.
- Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.
- Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.
- Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.
- Serve as a security operations lead for global SOC coverage and cross-functional collaboration.
Qualifications:
Minimum Qualifications
- Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, or a related field, or equivalent practical experience.
- 5+ years of progressive cybersecurity experience, including significant hands-on experience in security operations, incident response, threat detection, or SOC leadership.
- 3+ years of experience leading SOC analysts, incident response teams, managed security operations, or cross-functional cyber defense workflows.
- Strong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and incident response processes.
- Demonstrated experience building or improving detection use cases, alert triage workflows, response playbooks, escalation procedures, and SOC metrics.
- Experience coordinating investigations involving phishing, malware, endpoint compromise, suspicious authentication, privileged access misuse, data exposure, and cloud security events.
- Familiarity with frameworks and standards such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls, or equivalent cyber defense frameworks.
- Ability to communicate clearly with technical teams, business stakeholders, senior leadership, and external partners during security incidents.
- Strong analytical, documentation, prioritization, and decision-making skills in high-pressure operational environments.
- CISSP, Security+, or equivalent industry certification.
Preferred Qualifications
- Experience operating or transforming a global SOC in an enterprise environment.
- Experience working as an Incident Commander, leading IR execution for the company.
- Experience working with Microsoft Sentinel, Microsoft Defender XDR, KQLs, UEBA, or comparable security operations platforms.
- Experience with cloud security monitoring across Azure, AWS, GCP, or hybrid cloud environments.
- Experience with threat hunting, purple-team collaboration, adversary emulation, or detection engineering.
- Experience managing managed detection and response providers or outsourced SOC services.
- Experience in semiconductor, technology, manufacturing, or intellectual property-intensive environments.
- Familiarity with GenAI-assisted SOC workflows, including alert enrichment, analyst productivity, incident summarization, and security automation.
- Additional certifications such as CEH, or similar.