SOC Lead (Security Operations Center)
We are seeking an experienced SOC Lead to take charge of our Global Cybersecurity Operations team. As the SOC Lead, you will oversee the security operations ecosystem around the clock, driving the strategic and technical advancements of our cybersecurity operating model. Your key responsibilities will include maintaining continuous monitoring coverage, serving as the primary technical escalation point, and designing a robust defense infrastructure.
Our goal is to expand a modern, intelligence-driven SOC that operates across multiple cloud environments and extensively utilizes AI and automation. This role calls for a hands-on technical leader capable of maneuvering between in-depth cloud investigations, code-based automation management projects, and guiding a high-performing engineering team.
Responsibilities:
- Operational Oversight & Escalation: Establish and optimize operational frameworks to ensure round-the-clock monitoring support. Be available as the key escalation point to lead responses during critical security incidents.
- Advanced Investigations: Direct thorough investigations across all threat vectors, focusing particularly on complex multi-cloud environments using tools like CNAPP, EDR/XDR, and digital forensics tools.
- AI & Automation Strategy: Develop and implement the strategy for our AI-driven SOC. Lead the creation of autonomous agents and refine SOAR playbooks for rapid response.
- Technical Project Leadership: Head SOC initiatives aimed at enhancing EDR platforms, boosting Email Security Gateways, and spearheading proactive threat-hunting efforts.
- Incident Command & Response: Take on the role of technical Incident Commander during major security events, managing incident response activities and crucial decisions.
- Mentorship & Talent Development: Mentor and elevate the technical skills of SOC analysts, promote continuous learning, conduct technical exercises, and foster a culture of excellence.
Requirements:
- 8+ years of hands-on experience in Information Security, with at least 3+ years in a senior SOC or Incident Response position.
- Demonstrated experience in building operational frameworks for 24/7 monitoring and on-call structures.
- Proficient in modern security architectures, including EDR/XDR, Email Security Gateways, and Digital Forensics tools.
- Expertise in Cloud Security Forensics across AWS, Azure, and GCP, with proficiency in CNAPP platforms.
- Strong programming and scripting skills (e.g., Python, Bash) for custom API integrations and automation.
- Familiarity with AI-augmented engineering and workflows, utilizing methodologies like LLM for automated defensive operations.
- Strong leadership skills, experience in mentoring teams, and handling stressful incident scenarios.
- Willingness to be on-call outside regular hours for high-impact incidents.
In the recruitment process, we may employ AI tools to help evaluate your application against the job requirements. These tools aid in reviewing applications but do not replace human judgment, as final recruitment decisions are made by humans. If you require more information on data processing, kindly reach out to us.
