Lead SOC operations, drive incident response and threat hunting, streamline security processes, and keep the team ready for emerging risks.
Job Summary
What’s in It for You?
HMO on Day 1 – Start with peace of mind
Exciting perks and rewards – Performance truly pays off
Travel opportunities – Explore new horizons
Get recognized – Your work makes a difference
Work-life balance – Because your time matters
Continuous learning – Grow faster than ever
Responsibilities
Salary : 50,000 - 55,000
Lead and oversee daily SOC operations, threat monitoring, alert analysis, and incident response activities across enterprise environments.
Manage, mentor, and direct Tier 1 & Tier 2 SOC Analysts, ensuring SLA compliance for incident containment and resolution.
Serve as the primary escalation point for complex, high-severity security incidents, leading containment, eradication, and post-incident root cause analysis.
Develop, refine, and enforce SOC standard operating procedures (SOPs), incident playbooks, and Security Configuration Assessment, (SCA) policies.
Optimize and manage SIEM solutions (e.g., Wazuh), EDR, firewalls, and integration workflows (e.g., n8n, VirusTotal, ServiceDesk Plus, MSP).
Perform advanced threat hunting, log correlation, and IOC analysis across network, endpoint, and cloud assets.
Collaborate with the IT Manager, CISO, and Infrastructure teams to coordinate emergency patching and vulnerability remediation.
Produce detailed technical incident reports, executive metrics dashboards, and operational risk summaries for executive management.
Drive continuous improvement in threat intelligence integration, security automation, and threat detection efficiency.
Requirements
Extensive hands-on experience in Incident Response leadership, SIEM management, and threat triage.
In-depth knowledge of SIEM architecture, log parsing, custom rule detection, and security automation.
Deep expertise in incident response methodologies aligned with NIST SP 800-61, SANS, and ISO 27001 standards.
Strong experience with vulnerability management, EDR deployment, firewalls, and threat intelligence feeds.
Proven leadership and mentoring skills with the ability to manage shift schedules and analyst workflows.
Excellent written and verbal communication skills for technical documentation and leadership updates. Preferred Qualifications:
Professional cybersecurity certifications: CISSP, CISM, GCIH, CySA+, or CASP+.
Hands-on experience with open-source SIEM/XDR platforms like Wazuh, along with automation tools (e.g., n8n).
Experience in Managed Security Services Provider (MSSP) environments.