Overview
Remote
$100,000 - $140,000
Full Time
Skills
SOC
MDR
TCP/IP
IDS/IPS
Firewalls
VPNs
SIEM
EDR
Job Details
Manager to help build, lead, and mature an EMEA-based SOC team for a global MDR provider with 24x7 operations. This role combines hands-on technical expertise, leadership, and strategy to drive the success of our Managed Detection & Response (MDR) and SOC-as-a-Service offerings.
Key Responsibilities
SOC Leadership & Operations
SOC Leadership & Operations
- Design, recruit, and develop a high-performing EMEA SOC team.
- Partner with the global SOC Operations Leader to train, mentor, and manage analysts.
- Define, track, and report on KPIs to ensure consistent SOC performance.
- Enforce SOC operational standards, processes, and escalation practices.
- Lead triage, investigation, and escalation of validated security incidents.
- Notify clients of incidents and guide mitigation efforts.
- Conduct proactive threat hunting to detect and contain emerging threats.
- Fine-tune XDR/SIEM rules to reduce false positives and detect missed threats.
- Perform forensic analysis and vulnerability assessments when needed.
- Collect and analyze global threat intelligence to strengthen defenses.
- Proactively monitor security sources for potential client impacts.
- Share threat reports, advisories, and corrective action guidance.
- Actively participate in security forums to stay ahead of evolving attack patterns.
- Interpret and analyze logs from diverse sources (firewalls, IDS, Windows DC, access systems, EPP/EDR, email security, etc.).
- Maintain hands-on expertise across IDS/IPS, firewalls, VPNs, SIEM, XDR, and EDR tools.
- Apply knowledge of ITIL processes including Incident, Problem, and Change Management.
- 8+ years as a Tier 3 SOC Analyst (MDR experience strongly preferred).
- Proven track record leading or managing SOC teams in global environments.
- Deep knowledge of TCP/IP traffic analysis, log analysis, and incident response workflows.
- Hands-on experience with IDS/IPS, Firewalls, VPNs, SIEM, EDR, and XDR solutions.
- Familiarity with major firewall platforms (SonicWall, Checkpoint, Cisco, Fortinet, Palo Alto).
- Experience with threat hunting, vulnerability assessments, and cloud security.
- Strong communication skills for internal collaboration and client-facing updates.
- Security certifications such as CISM, CND Analyst, or equivalent.
- Forensic analysis experience is a plus.
- Cloud security architecture expertise is a plus.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.