
SOC Manager
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Romania.
• Lead and manage daily operations within the SOC, encompassing continuous security monitoring, alert triage, investigation, escalation, and incident response.
• Ensure the smooth functioning of 24/7 monitoring services, providing adequate coverage across shifts and on-call arrangements.
• Guarantee that incidents and security alerts are addressed in accordance with SLAs, escalation protocols, and incident response procedures.
• Supervise critical security incidents and serve as an escalation point for complex or high-severity situations.
• Maintain operational documentation, including procedures, runbooks, escalation processes, and RACI models.
• Oversee service capacity, workload distribution, shift coverage, and identify operational bottlenecks.
• Coordinate efforts among SOC Analysts, Security Engineers, infrastructure teams, application teams, and client stakeholders.
• Take ownership of the operational performance of SOC services provided to clients.
• Monitor and report on KPIs, SLAs, response times, incident volumes, detection effectiveness, and overall service quality.
• Lead operational and service review meetings with clients.
• Provide reports on security incidents, trends, emerging threats, risks, and measures for improvement.
• Manage operational escalations and communication during significant security incidents.
• Coordinate risk mitigation strategies and support service planning and managed service governance.
• Oversee monitoring and detection across various environments, including endpoint, identity, cloud, network, application, and infrastructure.
• Assist in incident investigation, containment, remediation, and post-incident activities.
• Enhance detection quality, prioritize alerts, reduce false positives, and improve security use cases.
• Support initiatives in threat hunting, threat intelligence, and security investigation activities.
• Coordinate the use of SIEM, EDR/XDR, and SOAR technologies.
• Facilitate the onboarding of new log sources, applications, infrastructure, and customers into the SOC.
• Drive the automation of repetitive SOC tasks using SOAR playbooks and security tools.
• Lead, mentor, and develop SOC Analysts and Security Engineers.
• Assist with recruitment, onboarding, training, and career development within the SOC.
• Promote collaboration across SOC Operations, Security Engineering, Cloud & Infrastructure, and delivery teams.
• Enhance SOC processes, operating models, tools, automation, and service quality.
• Support the development and standardization of Accesa’s Managed Security Services portfolio.
• Contribute to service definitions, operating models, SLAs, KPIs, staffing structures, and delivery processes.
• Aid in the transition and onboarding of new SOC customers.
• Participate in discovery and transition activities for new security services.
• Contribute to proposals, RFPs, solution design, and customer workshops related to Security Operations.
• Significant professional experience in Cyber Security / Security Operations.
• Prior experience in a SOC environment, ideally progressing through roles such as SOC Analyst, Senior Analyst, Incident Response, Security Engineering, or SOC Lead.
• Experience in coordinating or managing operational security teams.
• Solid understanding of security monitoring and alert triage processes.
• Strong grasp of incident response and escalation protocols.
• Familiarity with SIEM and detection engineering concepts.
• Knowledge of EDR/XDR technologies.
• Understanding of SOAR and security automation practices.
• Familiarity with threat intelligence and threat hunting methodologies.
• Good understanding of cloud security principles.
• Knowledge of identity and endpoint security measures.
• Understanding of network and infrastructure security protocols.
• Experience with operational SLAs, KPIs, service reporting, and managed services.
• Familiarity with MITRE ATT&CK, NIST Cybersecurity Framework, incident response frameworks, and ISO 27001 standards.
• Strong analytical, organizational, and decision-making abilities.
• Capability to manage operational priorities in high-pressure security scenarios.
• Excellent communication skills with stakeholders and clients.
• Proficient in English; German is considered a significant advantage.
• Experience in building or scaling a SOC or Managed Security Service is preferred.
• Experience operating 24/7 security services is advantageous.
• Familiarity with Microsoft Sentinel and Defender XDR is a plus.
• Experience with Palo Alto XSOAR/XSIAM is beneficial.
• Knowledge in detection engineering and security automation is desirable.
• Scripting skills in Python or PowerShell are preferred.
• Experience with Microsoft Azure, AWS, or GCP is a plus.
• Experience assisting RFPs, service transitions, and managed service onboarding is appreciated.
• Relevant certifications such as CISSP, CISM, GIAC, Microsoft Security certifications, or equivalent are advantageous.
• Medical benefits.
• Gym support.
• Personalized fitness options.
• Team events.
• Healthy Habits Club.
• Flexible work-life dynamic.
• Mental wellbeing support.
• Social wellbeing initiatives in a hybrid environment.
Neogen Corporation
Clear Star
Get handpicked remote jobs straight to your inbox weekly.