تفاصيل الوظيفة
ROLE OBJECTIVE
Team Lead – SOC is responsible for supervising 24x7 security operations, managing a team of analysts, and ensuring that all security events, incidents, and vulnerabilities are handled effectively and efficiently. The role serves as the operational backbone of the SOC, ensuring that processes, playbooks, tools, and people work cohesively to deliver proactive, intelligence-driven threat detection and response. The incumbent acts as the bridge between management and technical teams, ensuring quality service delivery to clients and alignment with Otech’s cybersecurity framework and SLAs.
RESPONSIBILITIES
Strategic and Operational Leadership
• Lead daily SOC operations, ensuring effective monitoring, analysis, detection, and escalation of potential cyber threats across internal and client environments.
• Coordinate across SOC shifts, guaranteeing seamless 24x7 coverage and real-time response to high-severity incidents.
• Implement SOC playbooks, use cases, and correlation rules for multiple client environments aligned with MITRE ATT&CK and NIST frameworks.
• Conduct operational reviews and service reporting (MTTD, MTTR, false positive rates, SLA adherence, etc.) and recommend improvements.
• Drive automation initiatives through SOAR, reducing manual workloads and enhancing efficiency.
• Act as a technical escalation point for Tier 1 and Tier 2 analysts and provide direct support during major incident response.
• Maintain readiness for incident containment, threat hunting, and digital forensics support.
• Ensure regular review and optimization of SIEM content, rules, dashboards, and data feeds.
Governance, Compliance, and Quality Assurance
• Enforce adherence to SOC policies, processes, and service standards across all shifts and clients.
• Ensure compliance with ISO 27001, ISO 22301, and OIA-aligned frameworks.
• Prepare periodic audit and compliance evidence for SOC processes, service delivery, and incident management.
• Conduct quality assurance on incident tickets, ensuring accurate classification, documentation, and closure.
• Ensure all incidents undergo Root Cause Analysis (RCA) and lessons-learned documentation.
• Coordinate customer-facing service reviews and contribute to performance improvement plans.
Customer and Stakeholder Engagement
• Act as primary point of contact for client escalations, queries, and reporting requirements.
• Present SOC performance metrics, service dashboards, and recommendations during governance meetings.
• Support client onboarding and ensure appropriate log sources, use cases, and escalation workflows are in place.
• Collaborate with customer account teams to identify and mitigate risks proactively.
People Management and Capability Building
• Supervise and mentor SOC analysts across shifts, ensuring optimal workload distribution and skill enhancement.
• Conduct technical and behavioral training sessions, tabletop exercises, and after-action reviews.
• Define shift rosters, leave schedules, and coverage matrices ensuring uninterrupted operations.
• Conduct performance evaluations, identify skill gaps, and establish career development paths.
• Foster a culture of accountability, continuous learning, and operational discipline.
ROLE SPECIFICATIONS
Qualification
• Bachelor’s degree in Information Technology, Computer Science, or Cybersecurity.
Certification
• CEH, CompTIA CySA+, GCIA, GCIH, Splunk Certified Administrator preferred.
Experience
• 6–8 years in cybersecurity operations with at least 2 years in a supervisory role leading SOC analysts
Skills
• SOC management, threat response, governance, customer reporting, team leadership, and service management.
المتطلبات
- الخبرة
- 6+ years
- المؤهل العلمي
- Bachelor's Degree
الإبلاغ عن مشكلة في هذه الوظيفة
إن كان الإعلان منتهيًا أو رابط التقديم لا يعمل أو البيانات غير صحيحة، أخبرنا وسنراجعه. بلاغك لا يحذف الإعلان تلقائيًا؛ نراجعه بأنفسنا أولًا.