SOC Team Lead
Location:
UAE / Middle East (On-site)
Employment Type:
Full-Time
Department:
Managed Security Services - SOC
Experience:
5-8 Years (SOC / Incident Response)
Reports To:
Director of Managed Services
The SOC Team Lead is a senior hands‑on role responsible for the day‑to‑day leadership of the ITHR Security Operations team. You will oversee a team of SOC analysts (L1/L2/L3), own the quality of detection and response across monitored customer environments, and serve as the primary escalation point for significant incidents. This role combines technical depth with people leadership and operational excellence.
You will contribute directly to threat detection and investigation activities while driving continuous improvements in analyst capability, detection engineering, playbook maturity, SIEM coverage, and customer communications. You will work closely with DFIR specialists, delivery teams, account managers, and customer stakeholders while helping shape the evolution of the SOC practice as ITHR expands its managed security services capabilities.
- Lead, mentor, and develop a team of L1, L2, and L3 SOC analysts, owning shift coverage, performance management, and professional growth.
- Serve as the primary escalation point for high‑severity and complex incidents across monitored customer environments.
- Conduct and oversee threat detection, alert triage, investigation, and incident response activities while remaining actively involved in analysis and investigation work.
- Lead threat hunting initiatives by proactively identifying indicators of compromise, attacker persistence mechanisms, lateral movement, and emerging threats.
- Own and continuously improve SIEM correlation rules, detection logic, use cases, and alert tuning to reduce false positives and improve detection effectiveness.
- Develop, maintain, and enforce incident response playbooks, operational runbooks, and escalation procedures to ensure consistent execution across the SOC.
- Produce and review customer‑facing incident reports, security advisories, executive summaries, and monthly service reports to ensure clarity, accuracy, and business relevance.
- Manage SLA adherence across detection, triage, escalation, containment, and response activities, identifying bottlenecks and implementing service improvements.
- Collaborate with DFIR teams on post‑incident reviews, lessons learned exercises, and continuous enhancement initiatives.
- Coordinate with customers and internal delivery teams during active incidents, providing updates, guiding containment actions, and managing stakeholder expectations.
- Support customer onboarding activities including log source integration, use case development, baseline establishment, and initial detection tuning.
- Stay current with the threat landscape, attacker methodologies, regional threat actors, and emerging attack trends, translating these insights into actionable improvements.
- Support internal audits, compliance initiatives, customer assessments, and managed security governance activities as a technical authority.
- 5-8 years of experience in security operations, with at least 2 years in a senior analyst or team lead capacity.
- Proven hands‑on experience with SIEM platforms including rule development, log integration, alert tuning, investigation workflows, and detection engineering.
- Experience with Microsoft Sentinel, Splunk, IBM QRadar, or similar enterprise SIEM technologies.
- Strong practical understanding of incident response methodologies including triage, containment, eradication, recovery, and post‑incident activities.
- Deep understanding of attacker tactics, techniques, and procedures (TTPs) and strong familiarity with the MITRE ATT&CK framework.
- Hands‑on experience with endpoint detection and response technologies such as Crowd Strike, Sentinel One, Microsoft Defender, or equivalent solutions.
- Experience with network security monitoring, IDS/IPS technologies, firewall investigations, and anomaly detection techniques.
- Strong reporting and communication capabilities, including production of executive‑ready incident reports and customer communications.
- Demonstrated…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).