SOC Manager/SOC Architect

Location: PK

Category: Security

Last Date: 08-24-2026

Apply Now

Own the day-to-day operation of the Security Operations Center, ensuring customer security incidents are identified, investigated, communicated, and resolved in accordance with SLAs while continuously improving detection capabilities and operational efficiency.

Knowledge and Skills:

  • Expert knowledge of SIEM platforms (Microsoft Sentinel, QRadar, Splunk, Elastic, etc.)
  • Experience with Microsoft Defender XDR, CrowdStrike, SentinelOne, or similar EDR platforms.
  • Strong understanding of:
    • Windows Active Directory
    • Microsoft 365
    • Azure
    • Linux
    • Firewalls
    • VPNs
    • Networking
    • DNS
    • Email security
  • Familiarity with MITRE ATT&CK
  • Experience with SOAR automation
  • Incident response and forensic fundamentals
  • Ability to write detection logic using KQL, AQL, SPL, Sigma, or YARA

Job Description:

  • Lead daily SOC operations and oversee Tier 1 and Tier 2 analysts.
  • Serve as the final technical escalation point for high-severity security incidents.
  • Review and approve incident investigations before customer communication.
  • Manage customer onboarding into the SOC platform.
  • Conduct monthly and quarterly security review meetings with customers.
  • Develop and maintain detection rules, use cases, and playbooks.
  • Continuously tune SIEM, EDR, and XDR detections to reduce false positives.
  • Lead threat hunting and post-incident root cause analysis.
  • Ensure compliance with customer SLAs and internal response metrics.
  • Create and maintain SOC documentation, SOPs, and runbooks.
  • Coordinate with customer IT teams during security incidents.
  • Track SOC KPIs and prepare executive reports.
  • Mentor analysts and oversee technical training.
Operational Responsibilities
  • Ensure 24×7 SOC coverage.
  • Review all Critical and High severity incidents.
  • Maintain detection quality.
  • Improve automation.
  • Manage analyst schedules.
  • Review customer reports before delivery.
  • Handle customer escalations.
  • Define SOC processes and standards.

Tasks:

  • SLA compliance ≥ 99%
  • Mean Time to Detect (MTTD)
  • Mean Time to Respond (MTTR)
  • False positive rate
  • Detection coverage improvements
  • Customer satisfaction
  • Analyst utilization
  • Automation rate
  • Incident closure time

Education:

Bachelors

Qualification:

Required Experience

  • 7+ years in cybersecurity
  • 3+ years in a Security Operations Center
  • 2+ years leading analysts or incident response teams
  • Experience supporting multiple customers in an MSSP environment preferred

Certifications (Preferred)

  • CISSP
  • GCIA
  • GCIH
  • GCFA
  • Microsoft SC-200
  • CompTIA CySA+
  • Splunk, QRadar, or Microsoft Sentinel certifications