Role Overview
We are looking for a SOC Technical Lead to lead security operations, threat detection, incident response, and technical improvements across enterprise environments.
Key Responsibilities
- Lead SOC operations, major incident response, threat hunting, and investigations
- Design and optimize SIEM, SOAR, EDR/XDR, NDR, and security-monitoring solutions
- Develop detection rules, correlation searches, dashboards, use cases, and response playbooks
- Guide L1/L2/L3 analysts and provide technical escalation support
- Coordinate containment, eradication, recovery, and post-incident reviews
- Analyze threat intelligence, vulnerabilities, attack patterns, and security trends
- Automate SOC processes using Python, PowerShell, or similar tools
- Collaborate with infrastructure, cloud, network, application, and compliance teams
- Track SOC KPIs, improve processes, and maintain runbooks and documentation
Required Skills
- Strong expertise in SIEM, SOAR, EDR/XDR, threat hunting, digital forensics, and incident response
- Knowledge of Windows, Linux, cloud security, networking, IAM, firewalls, and MITRE ATT&CK
- Experience with tools such as Splunk, Microsoft Sentinel, QRadar, ArcSight, CrowdStrike, or Microsoft Defender
- Strong leadership, analytical, communication, and stakeholder-management skills
Experience
- 10+ years of experience in SOC, cybersecurity operations, incident response, or threat detection
Preferred
- CISSP, CISM, GCIH, GCIA, GCFA, CEH, Security+, or CySA+ certification
- Experience leading 24/7 SOC operations and supporting ISO 27001, SOC 2, PCI DSS, or SOX compliance
- Knowledge of security automation, threat intelligence platforms, cloud-native security, and security architecture
Join us and be part of the exciting journey