Roles & Responsibilities:
- Lead and manage the Security Operations Center (SOC) function, ensuring 24x7 monitoring, detection, investigation, and response to cybersecurity incidents.
- Own the operational security posture by managing threat detection, incident response, vulnerability management, and security monitoring processes.
- Develop and maintain SOC processes, playbooks, escalation procedures, and incident response workflows aligned with industry standards.
- Lead a team of security analysts, engineers, and incident responders; provide mentoring, coaching, and performance management.
- Monitor and analyze security alerts from SIEM, EDR, IDS/IPS, firewalls, cloud security platforms, and other security tools.
- Drive incident investigations, root cause analysis, containment, remediation, and post-incident reviews.
- Manage threat intelligence operations, including identifying emerging threats, indicators of compromise (IOCs), and attack patterns.
- Improve SOC maturity through automation, SOAR implementation, process optimization, and operational metrics.
- Define and track SOC KPIs/KRIs, including incident response time, detection effectiveness, false positives, and threat trends.
- Collaborate with infrastructure, cloud, application, and compliance teams to strengthen security controls.
- Support security audits, regulatory compliance requirements, and risk assessments.
- Ensure alignment with cybersecurity frameworks such as ISO 27001, NIST CSF, MITRE ATT&CK, and industry best practices.
- Coordinate with external vendors, managed security service providers (MSSPs), and incident response partners when required.
- Prepare executive-level security reports, dashboards, and risk updates for senior management.
Preferred Candidate Profile:
- Experience: 815 years of experience in cybersecurity, with significant experience leading SOC operations, incident response, or security monitoring teams.
- Proven experience managing a SOC team in an enterprise environment, preferably in UAE/GCC markets.
- Strong hands-on experience with SIEM platforms (Splunk, Sentinel, QRadar), EDR/XDR solutions, threat intelligence, vulnerability management, and cloud security monitoring.
- Strong understanding of security incident lifecycle, threat hunting, malware analysis, network security, IAM, and security architecture.
- Experience developing SOC processes, operational procedures, and automation workflows.
- Ability to lead investigations involving APTs, phishing, ransomware, and insider threats.
- Strong stakeholder management skills with the ability to communicate security risks to technical and business leadership.
- Experience working with compliance and regulatory requirements such as ISO 27001, NIST, PCI-DSS, GDPR, or UAE regulatory frameworks.
Preferred Certifications:
- CISSP, CISM, GIAC certifications (GCIH, GCIA, GCFA), OSCP/OSCE, CCSP, or ISO 27001 Lead Auditor.
Didn’t find the job appropriate? Report this Job