Search Jobs

Search by job, company or skills

SOC Manager

SOC Manager

KPMG Philippines
7-9 Years
  • Posted 22 hours ago
  • Be among the first 10 applicants

Job Description

About the role

The Security Operations Manager is responsible for leading the day-to-day operations of the SOC Analyst staff. The role coordinates and works with the SOC Analysts to make sure that the analysts, processes, and technology are meeting the SOC security monitoring, analysis, and escalation objectives, organization service level agreements, objectives, and metrics. They are also responsible for communicating with the executive level management team (when deemed necessary) and serving as the principle liaison coordinating incident response functions.

Key Responsibilities

  • Lead the 24x7 delivery team, foster innovation, and drive accountability within SOC engineering.
  • Oversee the daily activities of the SOC to ensure the integrity and protection of networks, systems, and applications by technical enforcement of organizational security policies.
  • Ensure escalation of cases to the appropriate teams.
  • Conduct follow-up meetings of escalated or noteworthy cases and modifies SOPs and playbooks based on policies, standards and best practices learned from previous cases.
  • Provide technical oversight for security tool deployment and implementation .
  • Continuously monitor levels of service as well as interpret and prioritize threats through use of intrusion detection systems, firewalls and other boundary protection devices, and any security incident management products deployed.
  • Recognize potential, successful, and unsuccessful intrusion attempts and compromises thorough review and analyses of relevant event detail and summary information.
  • Monitor and proactively mitigate information security risks.
  • Coordinate shift schedule and deployment of staffing within the established structure. Manage regular, holiday, illness, vacation and emergency scheduling.
  • Keep current with the latest vendor updates, expansion opportunities, and technology directions, utilized in the Clients environment.
  • Ensure daily operational processes effectively support SOC operations objectives.
  • Ensure the Director of Cybersecurity Services is aware of any issues or incidents.
  • Own the successful completion of all daily operational processes and procedures.
  • Ensure analysts follow existing procedures and all procedures are documented in accordance with local guidelines.
  • Establish operational foundations, defining metrics and KPIs to drive governance, quality, and efficiency.Influence and improve existing processes through innovation and operational change.
  • Manage staffing, including recruitment, supervision, scheduling, development, evaluation, and disciplinary actions.

About you

  • Minimum 7 years Security leadership, with experience building long-term career development plans for team members at all levels.
  • Exceptional operational rigor with extensive real-world experience in ITIL methodologies and frameworks for IT operations.
  • Experience in designing, implementing and measuring relevant security and technology management critical success factors, key performance indicators, and metrics .
  • Ability to create shift schedules to ensure 24x7 coverage by support personnel .
  • In-depth knowledge of modern security concepts and how to apply the Advanced scripting knowledge with languages like PowerShell, bash/ksh/sh, Cisco IOS.sh, JunOS sh/csh, Perl, Tcl, Lua.
  • Familiarity with Azure Sentinel.
  • Familiarity with common network vulnerability/penetration testing tools including, but not limited to, Metasploit, vulnerability scanners, Kali Linux, and Nmap.
  • 4-6 year's experience with SIEM tools (Sentinel, Splunk, Logrhythm, etc.).
  • Familiarity with common IDS/IPS and Firewalls (Snort, Cisco, Fortigate, Sourcefire).
  • Knowledge of Windows, Unix-based systems, architectures, and network security devices .
  • Intermediate level of knowledge of LAN and WAN technologies
  • Knowledge of networking protocols and security implications.
  • 4-6 year's experience with Incident Response activities .
  • Experience with packet analysis and packet capture tools.
  • Expert knowledge of security best practices and concepts.

Qualifications:

  • Masters or Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field; or an equivalent experience in lieu of degree.
  • Demonstrated understanding of Information Security and Networking required.
  • Demonstrated technical knowledge of current network security, network hardware, protocols, and standards required.
  • Proven ability to diagnose and troubleshoot technical issues required.
  • Proven ability to make decisions and perform complex problem-solving activities under pressure.
  • Previous management and project leadership experience required.
  • Demonstrated strong oral and written communication and client facing skills.
  • Flexibility to adapt to different types of engagement, working hours, work environments, and locations.
  • Proven ability to work creatively, analytically in a problem-solving environment.

Desired Certifications

Security+, C|EH, Network+, Certified Information Systems Manager (CISM), Certified Information Systems Security Professional (CISSP), GIAC Certified Intrusion Analyst, GIAC Certified Incident Handler, or GIAC Reverse Engineering Malware.

Benefits

  • HMO with 2 Free Dependents
  • Communication Allowance
  • Rice Allowance
  • Clothing Allowance
  • Christmas/Holiday Gift (Christmas Cash Gift)
  • Group Personal Accident Insurance
  • Life Insurance with coverage
  • Flexi-ben reimbursement (Medical/Dental/Optical)
  • Bereavement Assistance
  • Retirement Plan
  • Leave Privileges
  • Firm-wide holiday shutdown on last 2 weeks of the year
  • Company work suspensions during extreme weather conditions

More Info

Job Type:
Industry:
Function:
Employment Type:

Key Skills

LAN and WAN technologies

Packet analysis and packet capture tools

Azure Sentinel

ITIL methodologies and frameworks

Sourcefire)

Networking protocols and security implications

Firewalls (Snort

About Company

Similar Jobs

7-9 yrs
Philippines, Quezon City
Skills:
Security+, Email Security, Incident Response, Siem, Cism, SOAR, CySA+, SOC automation, SOAR workflows, SSE, strategic cybersecurity initiatives, detection engineering, security playbooks, GCIA, EDR, threat detection, Security Monitoring, defensive cybersecurity programs, Cissp, MDR, gcih
5-7 yrs
Philippines, Manila
Skills:
PowerShell, Incident Response, Digital Forensics, Siem, Rest Apis, Malware Analysis, Windbg, Python, Assembly Language, Threat Hunting, Windows Internals, IDA Pro, x64dbg, Binary Ninja, Reverse Engineering, YARA, EDR, Ghidra, Linux Systems, dynamic analysis, SOAR
7-9 yrs
Philippines
Skills:
Incident Response, Security tool deployment and implementation, LAN and WAN technologies, Packet analysis and packet capture tools, Azure Sentinel, ITIL methodologies and frameworks, Networking protocols and security implications, Security best practices and concepts