← Todas as vagas

SOC Manager

Sobre a vaga

• Lead and coordinate day-to-day SOC operations, including continuous security monitoring, alert triage, investigation, escalation, and incident response
• Ensure effective operation of 24/7 monitoring services and coverage across shifts and on-call arrangements
• Ensure incidents and security alerts are handled according to SLAs, escalation paths, and incident response procedures
• Oversee critical security incidents and act as an escalation point for complex or high-severity situations
• Maintain operational procedures, runbooks, escalation processes, and RACI models
• Monitor service capacity, workload distribution, shift coverage, and operational bottlenecks
• Coordinate activities among SOC Analysts, Security Engineers, infrastructure teams, application teams, and client stakeholders
• Own operational performance of SOC services delivered to clients
• Monitor and report KPIs, SLAs, response times, incident volumes, detection effectiveness, and service quality
• Lead operational and service review meetings with clients
• Report on security incidents, trends, emerging threats, risks, and improvement measures
• Manage operational escalations and communication during major security incidents
• Coordinate risk mitigation actions and support service planning and managed service governance
• Oversee monitoring and detection across endpoint, identity, cloud, network, application, and infrastructure environments
• Support incident investigation, containment, remediation, and post-incident activities
• Improve detection quality, alert prioritization, false-positive reduction, and security use cases
• Support threat hunting, threat intelligence, and security investigation activities
• Coordinate SIEM, EDR/XDR, and SOAR technologies
• Support onboarding of new log sources, applications, infrastructure, and customers into the SOC
• Drive automation of repetitive SOC activities using SOAR playbooks and security tooling
• Lead, mentor, and develop SOC Analysts and Security Engineers
• Support recruitment, onboarding, training, and career development within the SOC
• Foster collaboration across SOC Operations, Security Engineering, Cloud & Infrastructure, and delivery teams
• Improve SOC processes, operating models, tooling, automation, and service quality
• Support development and standardization of Accesa’s Managed Security Services portfolio
• Contribute to service definitions, operating models, SLAs, KPIs, staffing models, and delivery processes
• Support transition and onboarding of new SOC customers
• Participate in discovery and transition activities for new security services
• Contribute to proposals, RFPs, solution design, and customer workshops related to Security Operations

• Strong professional experience in Cyber Security / Security Operations
• Previous experience in a SOC environment, ideally progressing through SOC Analyst, Senior Analyst, Incident Response, Security Engineering, or SOC Lead roles
• Experience coordinating or managing operational security teams
• Good understanding of security monitoring and alert triage
• Good understanding of incident response and escalation
• Good understanding of SIEM and detection engineering
• Good understanding of EDR/XDR technologies
• Good understanding of SOAR and security automation
• Good understanding of threat intelligence and threat hunting
• Good understanding of cloud security
• Good understanding of identity and endpoint security
• Good understanding of network and infrastructure security
• Experience working with operational SLAs, KPIs, service reporting, and managed services
• Understanding of MITRE ATT&CK, NIST Cybersecurity Framework, incident response frameworks, and ISO 27001
• Strong analytical, organizational, and decision-making skills
• Ability to manage operational priorities in high-pressure security situations
• Strong stakeholder and client communication skills
• Fluent English
• German is considered a strong advantage
• Experience building or scaling a SOC or Managed Security Service is nice to have
• Experience operating 24/7 security services is nice to have
• Experience with Microsoft Sentinel and Defender XDR is nice to have
• Experience with Palo Alto XSOAR/XSIAM is nice to have
• Experience with detection engineering and security automation is nice to have
• Scripting knowledge in Python or PowerShell is nice to have
• Experience with Microsoft Azure, AWS, or GCP is nice to have
• Experience supporting RFPs, service transitions, and managed service onboarding is nice to have
• Relevant certifications such as CISSP, CISM, GIAC, Microsoft Security certifications, or equivalent are nice to have

• Medical benefits
• Gym support
• Personalised fitness options
• Team events
• Healthy Habits Club
• Flexible work-life dynamic
• Mental wellbeing support
• Social wellbeing initiatives in a hybrid environment