SOC Manager
EverstarRemoteFull Time3d ago
SOCremotecurated-jd
Job description
SOC Manager at Everstar
About the role
This position is for a SOC Manager who will oversee the security operations center for a client in the defense technology sector. You will lead a team focused on protecting critical infrastructure and electronic devices.
Key facts
What you'll do
- Guide the day-to-day activities of the SOC team, including scheduling, hiring, performance reviews, and retention efforts.
- Design, implement, and monitor operational processes and service level agreements.
- Manage the technology stack, including SIEM, UBA, EDR, MDM, DLP, vulnerability management platforms, and threat intelligence tools.
- Prepare weekly and monthly performance reports with key metrics for the CISO.
- Oversee the SOC budget, including OPEX/CAPEX and investment justifications.
- Collaborate with business units during incident investigations.
- Develop and implement team training and development programs.
- Create a 1-3 year strategic roadmap for SOC evolution.
Requirements
- 5+ years in information security, with at least 3 years in a leadership role.
- Comprehensive understanding of SOC functions: detection, incident response, threat hunting, and technical investigation.
- Experience managing and developing SIEM, EDR, UBA, vulnerability management, MDM, and DLP platforms.
- Ability to define KPIs, maturity metrics, and performance dashboards.
- Budget management experience, including TCO, ROI, CAPEX, and OPEX planning.
- Project management skills for SOC initiatives.
- Experience conducting tabletop exercises and incident simulations.
- Familiarity with regulatory frameworks such as ISO 27001, NIST, and Ukrainian State Service for Special Communications and Information Protection (ДССЗЗІ).
- Knowledge of threat intelligence programs, including sources and dissemination.
- Vendor management experience, including Service Level Agreements (SLAs).
- Understanding of cloud security architectures in Azure, AWS, or GCP.
- Awareness of OT/ICS security principles in industrial environments.
- Risk management experience using frameworks like FAIR, CVSS, and risk registers.
- Proven ability to lead and motivate technical teams under pressure.
- Strategic thinking with an understanding of SOC's role within the broader business.
- Strong communication skills for presenting to senior leadership.
- Experience in conflict resolution and making difficult decisions.
- Skill in recruiting and retaining specialized cybersecurity talent in a competitive market.
- Resilience during crisis situations.
- Ability to balance security requirements with operational needs.
- Mentorship capabilities to foster team member growth.
- Understanding of the full SOC lifecycle, from concept to mature operations.
- Knowledge of cybersecurity economics, investment justification, and quantitative risk assessment.
- Familiarity with threats relevant to the defense industry, including APTs, attribution, and campaigns.
- Understanding of legal aspects, including chain of custody and regulatory reporting.
- Knowledge of HR practices in cybersecurity, including compensation, career paths, and burnout prevention.
Nice to have
- CISSP or CISM certification.
Skills & tools
- SIEM
- EDR
- UBA
- Vulnerability Management
- MDM
- DLP
- Threat Intelligence Platforms
- Azure
- AWS
- GCP
- ISO 27001
- NIST
- FAIR
- CVSS
Practical notes
- Official employment.
- 24 calendar days of annual leave.
- Health insurance provided after successful probation.
- Opportunities to propose and implement new ideas.
- Continuous professional development and expertise expansion.
- Military reservist deferment available with valid military registration documents.
- Collaborative and professional team environment focused on innovation.