Posted on: 17/08/2026
Role : Security Operations Lead
Job Description :
We are looking for an experienced Security Operations Lead to provide functional leadership, technical direction, and operational oversight for our Security Operations Center (SOC). The role will focus on strengthening threat detection, incident response, investigation quality, and continuous improvement across cybersecurity operations.
Key Responsibilities :
- Provide functional leadership and operational coordination for 24x7 SOC shift activities.
- Lead and guide SOC analysts during security investigations and ensure investigation quality standards are maintained.
- Monitor, triage, investigate, and coordinate the response to security incidents from initial alert through documented closure.
- Perform hands-on investigation of security events using SentinelOne EDR, Mimecast, SIEM, and other security platforms.
- Investigate phishing, malware, endpoint compromise, suspicious authentication activity, and other security incidents.
- Develop, maintain, and improve SOC SOPs, runbooks, and playbooks covering alert triage, escalation, containment, and closure.
- Develop SIEM detection use cases, write queries, tune alert rules, and reduce false positives.
- Manage the SIEM use-case lifecycle from threat scenario identification through detection logic design, testing, implementation, and continuous tuning.
- Enrich alerts using threat intelligence and map observed indicators and attacker activity to the MITRE ATT&CK framework.
- Conduct alert quality reviews and ensure investigation findings are adequately documented before ticket closure.
- Support post-incident analysis, Root Cause Analysis (RCA), incident reporting, and continuous improvement initiatives.
- Build and maintain dashboards and reports for incident tracking, SLA visibility, and SOC performance.
- Use ServiceNow for incident management, ticket tracking, SLA monitoring, and reporting.
- Guide and coach L1/L2 SOC analysts on investigation techniques, documentation standards, and security tool usage.
- Support vulnerability management activities using Tenable or equivalent tools.
- Coordinate with Incident Response, Threat Management, IT, external MDR partners, and other stakeholders during security incidents.
- Participate in shift handovers, coverage planning, task allocation, and operational governance.
Required Technical Skills :
- Strong hands-on experience in 24x7 SOC operations, incident detection, triage, investigation, and response.
- Hands-on experience with SentinelOne EDR, Mimecast, and SIEM platforms (Microsoft Sentinel, Rapid7, IBM QRadar).
- Strong understanding of the MITRE ATT&CK framework, SOC SOPs, and ServiceNow.
- Knowledge of Windows/Linux, scripting (PowerShell/Bash/Python), Tenable, SOAR, and cloud security (Entra ID, AWS).
Experience Requirements :
- 7 to 10 years of experience in Information Security / Cybersecurity.
- Minimum 2+ years of experience as a Technical Lead, SOC Lead, Shift Lead, or Senior Analyst in a 24x7 SOC environment.
Education & Certifications :
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience preferred.
- Preferred Certifications : CompTIA Security+, CySA+, GSEC, SC-200, CISSP, SentinelOne, or Mimecast certifications.
Shift Requirement :
- This role requires participation in 24x7 rotational shift operations and support for APAC time zones.
Immediate joiners or candidates with a short notice period are preferred.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1663742