Key Accountabilities & Responsibilities
SOC Operations & Incident Response
Lead and manage 24×7 SOC operations, ensuring effective monitoring and rapid response to security events.
Oversee the full incident response lifecycle: detection, containment, eradication, recovery, and post‑incident analysis.
Serve as the primary escalation point for high‑severity (P1/P2) cybersecurity incidents.
Ensure all incidents are handled in line with defined SLAs, playbooks, and escalation procedures.
Threat Detection, Monitoring & Response
Maintain optimal configuration, tuning, and performance of security technologies such as SIEM, SOAR, EDR/XDR, NDR, and UEBA.
Lead the development and refinement of detection use cases, correlation logic, and alerting rules.
Drive proactive threat‑hunting and continuous monitoring activities aligned with evolving threat landscapes.
Ensure SOC operations follow MITRE ATT&CK methodologies, leverage threat intelligence, and align with industry best practices.
Governance, Risk & Compliance
Ensure SOC operations adhere to regulatory and internal requirements, including:
National cyber risk regulations
Internal information security policies and standards
International frameworks (e.g., NIST, ISO 27001)
Support audits, regulatory reviews, and compliance assessments.
Maintain accurate and up‑to‑date SOC documentation, including SOPs, runbooks, incident reports, and dashboards.
People Management & Capability Development
Lead, mentor, and develop SOC analysts and incident responders across all levels (L1-L3).
Define shift schedules, competency matrices, training plans, and performance goals.
Drive continuous capability improvement through training, simulations, tabletop exercises, and lessons learned.
Foster a strong security culture and operational discipline within the SOC.
Vendor & Third‑Party Management
Manage relationships with SOC vendors, MSSPs, and technology partners.
Track vendor performance against SLAs and KPIs.
Coordinate vendor involvement during incidents, investigations, and forensic activities.
Support vendor assessments, renewals, and service improvement initiatives.
Reporting & Stakeholder Engagement
Deliver regular SOC performance and risk reports to senior leadership, covering:
Incident metrics and trends
SLA adherence
Threat landscape updates
Brief senior stakeholders during major incidents or crisis situations.
Collaborate closely with IT, Cloud, GRC, and business teams.
Key Performance Indicators (KPIs)
Mean Time to Detect (MTTD)
Mean Time to Respond (MTTR)
Incident SLA compliance
Reduction in recurring or high‑severity incidents
Audit and regulatory compliance outcomes
Qualifications & Experience
Education
Bachelor's degree in Cybersecurity, Information Security, Computer Science, IT, or a related field.
Experience
At least 10 years of cybersecurity experience, including 5+ years in SOC or Incident Response leadership roles.
Strong background operating SOC functions within banking or other regulated sectors.
Preferred Certifications
CISSP / CISM
GIAC certifications (e.g., GCIH, GCED, GCIA)
Cloud security certifications (AWS or Azure)
Technical & Professional Skills
Strong knowledge of SIEM, SOAR, EDR/XDR, and threat intelligence platforms.
Deep understanding of cyber threats, malware, ransomware, and advanced persistent threats.
Hands‑on experience with incident handling, digital forensics, and log analysis.
Strong analytical, decision‑making, and crisis‑management capabilities.
Behavioural Competencies
Leadership and accountability
Ability to perform under pressure
Clear communication with senior stakeholders
Risk‑based decision‑making
Strong collaboration and stakeholder engagement
GCS is acting as an Employment Agency in relation to this vacancy.
SOC Manager
Other similar jobs
Popular job searches
Your next job
starts here.
JOB SPECIALISMS
LATEST JOBS
TOP SEARCHES
LOCATIONS
- IT Support & Infrastructure
- Project Management
- Software Development
- Manufacturing & Production
- BI & Data Analytics
- Engineering Technology
- Engineering
- .NET/C#
- Controls & Automation
- Cyber
- Network security consultant
- Python developer
LATEST JOBS
- Controls Engineer
- Python Developer
- Network Engineer
- Cloud Security Engineer - Cont...
- Marketing Representative
- Head of Sales
- C# Developer Role - Hybrid - B...
- Information Security Programme...
- Business Development
- Customer Engagement Manager
- Account Manager
- Senior / Lead Consultant
TOP SEARCHES
LOCATIONS
- Engineer
- Data Scientist
- Senior Data Scientist
- Head of Data Science
- Trainee Data Scientist
- Data Science Graduate
- Senior Financial Accountant
- Management Accountant
- Cost Accountant
- Civil Engineer
- Senior Civil Engineer
- Civil Design Engineer