Job Summary
Responsible for leading the investigation, containment, eradication, and recovery of security incidents across enterprise environments. This role acts as the final escalation point within the SOC, handling high‑severity and complex incidents, performing forensic analysis, coordinating response actions, and driving post‑incident improvements to detections and controls.
Key Responsibilities
1. Ensure Timely Resolution Of Escalations By Leading Security Event Investigations Through Soar And Siem Tools, Adhering To Agreed Sla Norms To Deliver Optimal Outcomes. 2. Oversee The Generation Of Tower-Level Ee And En Revenue By Implementing Strategic Initiatives And Optimizing Resource Allocation Within The Support Operations. 3. Validate And Oversee Operational Hygiene By Reviewing Reports And Ensuring That Services Are Delivered In Accordance With The Statement Of Work (Sow). 4. Promote Positive Custom
Skill Requirements
- Strong experience with SIEM/SOAR platforms (Splunk, Microsoft Sentinel, XSIAM)
- Hands‑on EDR/XDR experience (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto)
- Proficiency in:
- KQL / SPL / advanced hunting queries
- Log and telemetry correlation
- Deep understanding of:
- Windows, Linux, macOS internals
- Identity systems (AD, Entra ID)
- Network fundamentals and attack techniques
- Familiarity with:
- MITRE ATT&CK
- NIST 800‑61 (Incident Response)
Experience & Qualifications
- 5–10 years in SOC, Incident Response, or Cyber Defense roles
- Experience operating in 24×7 SOC environments
- Certifications (preferred):
- GCIH, GCIA, GCED
- SC‑200, AZ‑500, CISSP
Other Requirements
1. Optional But Valuable Certifications: Certified Information Systems Security Professional (Cissp), Certified Information Security Manager (Cism), And Security Operations Center (Soc) Management Certification