Job Description:
• Take ownership of positive security outcomes for a designated set of customers.
• Curate a world class security operations team with a relentless focus on innovation and automation.
• Build and maintain a operating strategy for internal service groups and external clients.
• Regularly report on SOC metrics, improvements, and issues to executive management.
• Provide overall guidance, instruction, mentorship, and leadership to all squad members.
• Serve as a leadership escalation point for customer related issues.
• Ensure the squad has the tools, processes, and support needed to maximize value to customers.
• Work with other internal teams to drive improvements in SOC service quality, consistency, and efficiency.
• Advocate of standardization, where appropriate.
• Ensure SOC analyst onboarding and training is reviewed and adjusted as necessary.
• Maintain current knowledge and understanding of the threat landscape.
Requirements:
• 8 or more years of combined, and progressing, experience in Information Technology or security disciplines (e.g. IT, Cyber Security, Law Enforcement, Military, etc).
• Practical experience in a leadership role within the last three years.
• Bachelor’s Degree or higher in related security domains is preferred.
• Strong verbal and written communication skills with the ability to adapt information delivery based on the target audience.
• Strong analytical skills, excellent customer service skills, and the ability to deal with high-pressure situations.
• Ability to lead SOC tours and support customer or prospect presentations.
• Confident leader in building a new department or changes within an established organization.
• Knowledge of information security principles, concepts, practices, and related components.
• Advanced understanding of networking concepts and ability to analyze network artifacts.
• Demonstrated experience in using Endpoint Detection and Response software (SentinelOne, Crowdstrike, Defender ETC.)
• Advanced knowledge of at least one leading SIEM platform (Sentinel, Splunk, Elastic, IBM Qradar, Chronicle etc.)
• Possess at least one industry certification (Sec+, CEH, SANS Certification (e.g. GCIH, GCIA, GSEC, GMON), OSCP etc.) or working towards a related certification.
• Prior knowledge of SOAR platform such as Siemplify, Forti soar etc.
• Demonstrated expert knowledge of the MITRE ATT&CK framework.
Benefits:
• Equal Opportunity Employer (EOE).
• Direct applicants only (no outside recruiters).