SOC Operations & Incident Management- Take ownership of day-to-day Security Operations Center (SOC) activities and support the smooth execution of security monitoring and incident response processes.
- Act as a senior escalation resource for complex and high-impact security incidents, providing hands-on investigation, analysis, and resolution support.
- Coordinate incident workflows and ensure SOC activities follow established playbooks, procedures, and security standards.
- Support and guide SOC analysts during assigned shifts, helping maintain operational quality and effective decision-making.
- Ensure compliance with internal policies, customer requirements, and relevant security procedures.
Cybersecurity Service Delivery- Support the delivery of cybersecurity services in accordance with agreed SLAs, KPIs, and customer expectations.
- Identify operational gaps and recommend improvements to SOC processes, workflows, tools, and overall service quality.
- Work closely with technical and internal delivery teams to support customer onboarding, service transitions, and ongoing operations.
- Contribute to improving the efficiency and maturity of security monitoring and incident response capabilities.
Client Communication & Escalation Support- Serve as a key point of escalation for customers regarding security incidents and operational issues.
- Communicate clearly and effectively with customers and internal stakeholders to ensure issues are addressed in a timely manner.
- Understand customer environments and business requirements to provide appropriate cybersecurity support and recommendations.
- Proactively identify potential service risks and opportunities to improve customer experience and service value.
Reporting & Operational Improvement- Prepare and communicate operational updates, security risks, and incident-related information to relevant stakeholders and management.
- Review incident patterns, operational metrics, and customer feedback to identify areas for improvement.
- Provide practical recommendations to enhance SOC operations, security tools, and service capabilities.
Technical & Professional Requirements- Minimum 5 years of experience in cybersecurity, SOC operations, or cybersecurity service delivery.
- Demonstrated experience handling and investigating escalated security incidents in a SOC environment.
- Strong knowledge of SIEM, threat intelligence, IDS/IPS, firewalls, and malware detection technologies.
- Good understanding of cybersecurity frameworks and standards, particularly MITRE ATT&CK and NIST.
- Hands-on experience working as a Security Consultant or security professional with multiple SOC/security solution vendors.
- Strong analytical and problem-solving skills, with the ability to make sound decisions in high-pressure situations.
- A good understanding of service delivery and operational problem-solving is essential.
- Previous team leadership experience is not mandatory, although the ability to guide and support team members is important.
- Professional certifications such as CISA or CISM are an advantage.
- Bachelor's degree in Cyber Security, Information Security, or a related field. A Master's degree is a plus.
Communication Requirements- Very strong English communication skills, with the ability to work effectively with customers, technical teams, and multiple stakeholders.
Working ScheduleDuring ProbationNormal working hours:
- 8:00 AM – 5:00 PM, or
- 9:00 AM – 6:00 PM
After ProbationThe role requires working in a rotating shift schedule, including night shifts:
- Shift 1: 6:00 PM – 2:00 AM (VNT), including a 1-hour break
- Shift 2: 10:00 PM – 7:00 AM (VNT), including a 1-hour break
Employees will rotate between shifts according to the operational schedule assigned by the SOC Lead