Direct the functions, processes, and operations of the SOC and ensure policies and procedures are followed
Lead the 24×7 operations of the SOC to ensure optimal identification/resolution of security incidents and enhance client security
Manage the SOC team and handle shift scheduling
Ensure SLA compliance, process adherence, and continuous process improvement to meet operational objectives
Manage the collection, documentation, and investigation of security incidents received via the SOC
Provide clients/CISOs/Senior Management with a realistic overview of risks and threats in the enterprise environment
Develop and maintain an incident response management program covering detection, analysis, containment, eradication, recovery, and forensic evidence handling
Work directly with customers to ensure resolution management and customer satisfaction
Create reports, dashboards, metrics for SOC operations and present to management and customers
Lead and conduct technical tabletop exercises with the SOC team on a regular basis
Manage SOC process improvement programs
Conduct scheduled and ad hoc training exercises to ensure staff are up to date on current threats and incident response techniques
Provide direction, leadership, and management of SOC team personnel
Establish performance goals and priorities
Administer performance reviews for SOC team personnel
Qualifications
5+ years of experience handling a SOC team
10+ years of experience in Security Operations management and incident response within a SOC
Strong understanding and hands-on experience with SIEM tools such as:
IBM QRadar
Azure Sentinel
Splunk
Palo Alto
Sumo Logic
LogRhythm
Sourcefire
Cisco AMP
Expertise in security operational services:
Unified Threat Management
Anti-virus
SIEM
DDoS/DoS
Threat & Vulnerability Management
Cyber Investigations
Cybersecurity Forensic Investigations
Advanced knowledge of security best practices related to:
Information systems applications
Data security
Infrastructure security
Strong time management and leadership abilities
Excellent written and verbal communication skills
Strong knowledge of networking and security fundamentals
Proven ability to prioritize and deliver results with a focus on quality