Manager - SOC
Job description
About the role
Freshworks is looking for a leader to oversee our 24x7 Security Operations Center. You will guide a team of analysts and engineers while refining our threat detection, incident response, and automation strategies to protect our global infrastructure. In this capacity, you will own the design and execution of the security operations strategy that supports the business objectives of the organization. You will be responsible for establishing the operational cadence and ensuring that the SOC functions at a level that meets industry best practices and internal service expectations. The role requires a balance of tactical oversight and strategic thinking to ensure that security operations are efficient, effective, and aligned with the broader risk posture of the company. You will play a critical part in fostering a culture of security awareness and continuous improvement within the SOC team. Your work will directly influence the reliability and trustworthiness of the platforms that our customers and partners rely on every day.
Key facts
What you'll do
- Oversee the execution of complex investigations and manage the end-to-end lifecycle of security incidents within the 24x7 environment.
- Act as the primary escalation point and Incident Commander for high and critical severity security threats, ensuring calm and decisive leadership during crises.
- Drive the optimization of detection use cases, SIEM workflows, and SOAR automation to improve operational efficiency and reduce manual overhead.
- Perform comprehensive monitoring of security across cloud, endpoint, identity, network, and application layers to maintain situational awareness.
- Lead proactive threat hunting initiatives to discover hidden threats, attacker behaviors, and security vulnerabilities before they are exploited.
- Establish and maintain a robust metrics framework by defining, tracking, and reporting on MTTD, MTTR, false positive rates, and automation coverage to measure program effectiveness.
- Partner closely with IT, Engineering, and Product Security teams to identify risks, prioritize remediation, and improve overall cyber resilience across the technology stack.
- Invest in the growth of the team by mentoring staff through technical coaching, skills development, and career pathing to build a high-performing security organization.
- Synthesize complex technical data into clear narratives and prepare security dashboards and operational reports tailored for senior leadership and stakeholders.
- Oversee the management of vendor relationships and MSSP partnerships to ensure service levels are met and that external capabilities complement internal operations.
Requirements
- Possess 8 to 12+ years of total experience in cybersecurity with a strong track record of professional practice in the field.
- Bring 3 to 5+ years of direct experience managing a Security Operations Center, demonstrating success in leading teams and processes.
- Show advanced proficiency with SIEM platforms such as Palo Alto Cortex XSIAM, XDR, Splunk, Microsoft Sentinel, or QRadar in live operational settings.
- Have hands-on experience with SOAR platforms and the implementation of security automation to streamline response activities.
- Demonstrate deep expertise in incident response, digital forensics, and detection engineering to guide investigations and analysis.
- Prove the ability to effectively manage P1 cybersecurity incidents, including coordination with stakeholders and resolution tracking.
- Illustrate familiarity with cloud security within AWS, Azure, or GCP environments to understand and secure modern infrastructure components.
- Apply knowledge of security frameworks including NIST CSF, ISO 27001, CIS Controls, and MITRE ATT&CK to guide the maturity of the SOC.
- Exhibit strong communication skills to manage stakeholders, handle escalations, and deliver executive reporting that informs strategic decisions.
Nice to have
- Hold certifications such as CISSP, GIAC (GCIH, GCIA), GCFA, or CISM to validate your expertise and commitment to the profession.
- Have practical experience with Palo Alto Cortex XSOAR, CrowdStrike, or Microsoft Defender within previous roles.
- Possess a background in implementing AI-driven SOC operations and understanding how emerging technologies can enhance security operations.
Practical notes
Freshworks is an equal opportunity employer committed to a diverse and inclusive workplace.