As a seasoned Security Operations Centre (SOC) Manager at Tech Mahindra, you will oversee the day-to-day operations of the SOC within an organization. This role involves managing a team of security analysts and engineers to ensure the continuous monitoring, detection, analysis, and response to security threats and incidents.
The SOC Manager ensures that the organization's security posture is strong and that incidents are addressed efficiently and effectively. This role requires strong leadership, communication, and technical expertise in cybersecurity operations.
Key Responsibilities:
• Lead, mentor, and manage the SOC team (Tier 1, Tier 2, and Tier 3 analysts) to ensure the effective operation of the SOC.
• Establish clear objectives, KPIs, and performance metrics for the SOC team.
• Oversee staffing levels, training, and skill development to ensure that the team has the necessary capabilities to address emerging threats.
The SOC Manager plays a critical role in ensuring the continuity of the SOC's operations and is responsible for developing and refining incident detection and response procedures, workflows, and escalation protocols.
The successful candidate will have a proven track record of leading high-performing teams and responding to complex security incidents.
This role offers a unique opportunity to join a dynamic team and contribute to the development of cutting-edge cybersecurity solutions.
The ideal candidate will have a Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field, or equivalent experience.
Experience:
• Minimum of 7-10 years of experience in security operations, with at least 5 years in a leadership or managerial role in a SOC.
• Hands-on experience in incident detection, response, and management using SIEM platforms, firewalls, IDS/IPS, endpoint detection tools.
• Experience with network and system security, threat intelligence, and vulnerability management.
Technical Skills:
• Expertise with SIEM platforms and incident response tools.
• Strong hand on experience in managing SIEM platforms, Use Case creations, Connector and Parser development, L3 SOC Analyst investigations.
• Knowledge of network security protocols, firewall configurations, and intrusion detection/prevention systems (IDS/IPS).