Our client is seeking a Head of Security Operations
Responsibilities
What you’ll do
Detection strategy & engineering
- Define and maintain the detection strategy, mapped to MITRE ATT&CK and iterated against real incidents and threat intel, not left as a static framework exercise
- Set the standards and review bar for Microsoft Sentinel content (detection rules, analytics, workbooks, Logic Apps playbooks) whether authored by the MSSP or in-house, and own detection-as-code practices – version control, peer review, testing – for that content
- Own the detections the MSSP can’t reasonably build: bespoke, payments/fraud-specific, or identity-driven logic
- Onboard new log sources and systems into the detection pipeline as the platform evolves, and integrate Defender XDR , Wiz, Cloudflare, Zscaler , and other tooling as it’s added, including email/data security telemetry (Defender for O365, DLP) once in scope
- Consume threat intelligence (feeds, ISACs, sector-specific sources) and translate it into detection and hunting priorities rather than treating it as a subscription nobody reads
- Build and maintain SOAR automation for alert enrichment, triage, and response actions, so the function scales with the estate rather than with headcount
MSSP & outsourced SOC
- Own the MSSP/outsourced SOC relationship end to end: SLAs, triage quality, playbook tuning, and contract renewal or rescoping as the function’s needs change
- Actively shape the boundary between MSSP and in-house scope as the team and platform mature, rather than treating today’s split as permanent
Incident response & management
- Lead incident response: own L3 investigation and forensic analysis across cloud and endpoint, working from MSSP escalations and your own detections
- Own incident management end to end alongside the CISO – major incident declaration, exec/board notification, and coordination with legal/comms on regulatory notification clocks (GDPR 72-hour, DORA incident classification and reporting) – not just the technical investigation
- Develop and maintain incident response playbooks and runbooks, and test them regularly through tabletop exercises rather than leaving them filed and unverified
- Drive post-incident reviews and RCAs, and feed lessons back into detection and playbook updates
Vulnerability management & identity governance
- Own vulnerability management as a program: scanning coverage across cloud, endpoint, and applications, risk-based prioritization, remediation SLAs, and exception handling with named owners
- Own identity governance within security operations: privileged access monitoring, access anomaly detection, joiner/mover/leaver assurance from a security lens, and identity-related detection coverage across Entra ID/Okta and cloud IAM
Metrics, team, and reporting
- Own MTTD, MTTR, and other operational metrics: baseline them, track them, and drive them down
- Manage the security operations team, including direct line management of the Security Analyst, and build the hiring/leveling plan as team and MSSP scope evolve
- Manage SOC systems, tooling, and processes end to end, including budget and licensing conversations with the CISO
- Support the CISO on incident communication, board/customer reporting, and post-incident reviews
What we’re looking for
Essential:
- Deep Microsoft Sentinel experience: KQL proficient, able to author and critically review detection rules, workbooks, and playbooks, even where day-to-day content maintenance sits with a third party
- Experience onboarding new data sources into a SIEM and scaling detection coverage as an environment grows
- Hands-on incident response and digital forensics experience across cloud and endpoint, including running an incident through containment, eradication, and RCA, not just triage
- Experience sharing ownership of the incident management process: major incident declaration, exec communication, and regulatory notification timelines (GDPR, DORA, or equivalent), typically alongside a CISO or equivalent
- Applied MITRE ATT&CK knowledge used in detection engineering, not just framework familiarity
- Experience running or managing vulnerability management as a program: tooling, prioritization, remediation tracking, and reporting
- Working knowledge of identity governance and access risk (privileged access, JML, IAM/entitlement review) as it applies to security operations
- Experience managing an MSSP/outsourced SOC relationship, including SLAs, contract or scope negotiation, and holding a third party accountable for quality
- Experience running tabletop exercises or equivalent IR plan testing
- Cloud security telemetry: AWS CloudTrail, Azure Monitor, GCP audit logs
- Strong written communication for incident reports and RCAs aimed at non-technical readers
Nice to have:
- Prior people management or mentoring experience in a SOC or detection engineering team
- Experience with Defender XDR (Defender for Endpoint, Identity, Cloud Apps)
- Wiz or equivalent CSPM integration into detection pipelines
- Fintech, payments, or regulated environment background
- Formal threat intelligence platform experience (beyond consuming feeds)
- Python or PowerShell for automation
- Certifications (valued, not required): SC-200, AZ-500, GCIA, GCIH, GCFE, GCFA, or equivalent applied experience
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#AlbionarcJobs#FintechJobs
#AsiaJobs#MiddleEastCareers
#TechTalent#FintechRecruitment
#FinanceOpportunities#
