Job Details
Skills And Tools:
Job Description
Team Leadership & Management:
- Lead, mentor, and develop a high-performing team of SOC analysts.
- Conduct performance reviews, provide feedback, and identify any requirements.
- Foster a positive and collaborative team environment.
Security Operations Management:
- Oversee the daily operations of the SOC, ensuring 24/7 coverage and effective incident response.
- Develop and implement security monitoring strategies and procedures.
- Configure and maintain SIEM systems and other security monitoring and automations tools.
- Analyze security trends, identify emerging threats, and adjust security controls accordingly.
Incident Response & Management:
- Develop and maintain incident response plans and playbooks.
- Lead the incident response process for critical security events.
- Conduct post-incident reviews and implement corrective actions.
- Ensure timely and effective communication during security incidents.
Threat Intelligence & Analysis:
- Collect, analyze, and disseminate threat intelligence to relevant stakeholders.
- Conduct threat hunting activities to proactively identify and mitigate threats.
- Stay informed about emerging threats, vulnerabilities, and security best practices.
Security Program Development:
- Contribute to the development and implementation of the overall security strategy.
- Collaborate with other security teams and departments to improve security posture.
- Ensure compliance with relevant security standards and regulations (e.g., ISO 27001, NIST Cybersecurity Framework, GDPR).
Job Requirements
• Education:
Bachelor’s degree in Computer Science, Information Technology, or a related field.
CISSP, CCNA/CCNP/CCIE security, CISM, or other relevant advanced security certifications highly preferred.
• Experience:
10+ years of experience in cybersecurity roles, with at least 3 years of experience in a SOC management or leadership position.
Proficiency in using SIEM systems (e.g., Netwitness, Splunk, QRadar, ArcSight) for advanced log analysis and threat hunting.
Experience with security orchestration and automation platforms (SOAR).
Familiarity with scripting languages (Python, Bash, PowerShell) for automation and analysis.
Hands-on experience with network security tools (firewalls, IDS/IPS, VPNs, proxies, endpoint security).