Security Operations Manager
الوصف الوظيفي
Position Overview
We are seeking a highly skilled and experienced Security Operations Manager to lead our Security Operations Center (SOC) and safeguard our organization against evolving cybersecurity threats. In this critical leadership role, you will oversee a team of security professionals, drive operational excellence, and ensure the implementation of robust security measures to protect our digital assets, infrastructure, and sensitive data. The ideal candidate will possess a deep understanding of cybersecurity operations, incident response, and threat mitigation, combined with exceptional leadership and strategic planning capabilities.
Key Responsibilities
The Security Operations Manager will play a pivotal role in strengthening our organization’s security posture by executing the following responsibilities:
- Leadership and Team Management: Provide strategic direction and day-to-day leadership to the SOC team, including Tier 1, Tier 2, and Tier 3 security analysts. Foster a culture of continuous learning, professional development, and accountability within the team.
- Security Operations Oversight: Monitor, detect, investigate, and respond to cybersecurity threats in real-time, ensuring minimal disruption to business operations. Lead incident response efforts, including containment, eradication, recovery, and post-incident reviews to prevent recurrence.
- Process Development and Optimization: Develop, refine, and maintain incident response playbooks, standard operating procedures (SOPs), and escalation protocols. Continuously improve security processes to enhance efficiency, accuracy, and effectiveness.
- Technology and Platform Management: Oversee the operation, configuration, and optimization of critical security technologies, including:
- Security Information and Event Management (SIEM) platforms (e.g., Splunk, Microsoft Sentinel, Elastic Security, QRadar)
- Endpoint Detection and Response (EDR/XDR) solutions
- Security Orchestration, Automation, and Response (SOAR) tools
- Intrusion Detection/Prevention Systems (IDS/IPS)
- Email security solutions
- Threat intelligence platforms
- Vulnerability management tools
- Threat Detection and Response: Review, tune, and optimize security detection rules and use cases to reduce false positives and enhance threat detection capabilities. Conduct proactive threat hunting activities to identify and mitigate potential risks before they escalate.
- Vulnerability Management: Collaborate with infrastructure and application teams to prioritize and remediate vulnerabilities, ensuring alignment with organizational risk tolerance and compliance requirements.
- Reporting and Compliance: Develop and maintain comprehensive security metrics, dashboards, and executive reports to track SOC performance, incident trends, and overall security posture. Ensure adherence to security policies, industry standards, and regulatory requirements.
- Stakeholder Collaboration: Work closely with IT, infrastructure, and business stakeholders to align security initiatives with organizational goals. Coordinate with third-party Managed Security Service Providers (MSSPs) and security vendors as needed.
- Training and Readiness: Lead cyber incident tabletop exercises to enhance organizational readiness and improve response capabilities. Stay abreast of emerging cyber threats, attack techniques, and industry best practices to proactively mitigate risks.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field.
- Minimum of 7 years of experience in cybersecurity, with at least 3 years in a leadership or senior SOC role.
- In-depth knowledge of:
- Security Operations Center (SOC) processes and frameworks
- Incident response methodologies and best practices
- Threat intelligence and threat hunting techniques
- Security monitoring and alert triage
- Cyber Kill Chain and MITRE ATT&CK Framework
- NIST Cybersecurity Framework and other industry standards
- Proven experience leading security incident investigations and managing response efforts.
- Hands-on experience with SIEM platforms such as Splunk, Elastic Security, Microsoft Sentinel, or QRadar.
- Strong understanding of Windows, Linux, Active Directory, cloud security (AWS, Azure, OCI, or GCP), and networking fundamentals.
- Experience with endpoint detection and response (EDR/XDR) solutions.
- Proficiency in scripting languages such as PowerShell, Python, or Bash for automation and tooling is a plus.
Preferred Certifications
While not mandatory, the following certifications are highly valued and will be considered a strong asset:
- Certified Information Systems Security Professional (CISSP)
- GIAC Certified Intrusion Analyst (GCIA)
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Forensic Analyst (GCFA)
- Certified Ethical Hacker (CEH)
- CompTIA Security+
- Splunk Enterprise Security Certified Admin (or equivalent SIEM certification)
- Microsoft SC-200 (if using Microsoft Sentinel)
Technical and Soft Skills
The successful candidate will demonstrate a blend of technical expertise and leadership acumen, including:
- Technical Skills: SIEM management, incident response, digital forensics (basic to intermediate), threat hunting, malware analysis, log analysis, SOAR automation, endpoint security, network security, firewall technologies, IDS/IPS, email security, cloud security, vulnerability management, and security reporting.
- Leadership and Soft Skills: Exceptional team leadership and mentorship abilities, strong stakeholder management, crisis decision-making under pressure, analytical and problem-solving skills, and excellent documentation and communication abilities.
Key Performance Indicators (KPIs)
The Security Operations Manager will be evaluated based on the following metrics to ensure operational excellence:
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Incident resolution SLA compliance
- Reduction in false-positive alerts
- Threat detection and response effectiveness
- Vulnerability remediation timelines
- Compliance with security policies and regulatory requirements
يمكن أن يرتكب الذكاء الاصطناعي أخطاءً.