Security Lead; MSSP
Listed on 2026-06-24
-
IT/Tech
Cybersecurity, Security Manager, Information Security, Network Security
We are seeking an experienced Security Lead to oversee the delivery, governance, and continuous improvement of Managed Security Services (MSSP) operations. The role will be responsible for leading security operations, incident response activities, threat management, security monitoring, and customer security engagements while ensuring compliance with industry standards and service-level commitments.
The Security Lead will act as the primary technical authority for cybersecurity operations, managing security analysts, coordinating incident response efforts, driving security best practices, and working closely with customers to enhance their security posture. The role requires strong expertise across Security Operations Center (SOC) functions, threat detection, security governance, risk management, and cybersecurity frameworks.
Key Accountabilities & Responsibilities Security Operations Leadership- Lead and oversee day-to-day MSSP and Security Operations Center (SOC) activities.
- Manage and mentor security analysts, incident responders, and cybersecurity engineers.
- Act as the primary escalation point for critical security incidents and cyber threats.
- Ensure security monitoring services are delivered in accordance with agreed SLAs and KPIs.
- Drive operational excellence through continuous process improvements and automation initiatives.
- Lead the investigation, containment, eradication, and recovery of cybersecurity incidents.
- Coordinate major incident response activities with customers, stakeholders, and third-party vendors.
- Conduct root cause analysis and prepare incident reports with corrective actions.
- Oversee threat hunting activities and proactive threat detection initiatives.
- Ensure timely response to security alerts and escalation of critical events.
- Manage SIEM, SOAR, EDR, NDR, IDS/IPS, email security, and vulnerability management platforms.
- Oversee security use case development, tuning, and optimization.
- Ensure effective log collection, correlation, monitoring, and threat detection across customer environments.
- Support deployment and enhancement of security technologies and controls.
- Review security architectures and recommend improvements to strengthen defenses.
- Ensure alignment with ISO 27001, NIST Cybersecurity Framework, CIS Controls, and industry best practices.
- Lead security audits, compliance assessments, and risk management activities.
- Develop and maintain security policies, procedures, standards, and operational playbooks.
- Support customers in addressing compliance and regulatory requirements.
- Conduct security risk assessments and recommend mitigation strategies.
- Serve as the primary security advisor for assigned customers.
- Present security posture reports, incident summaries, and improvement recommendations to management and customers.
- Conduct security review meetings and executive-level briefings.
- Collaborate with infrastructure, cloud, network, and application teams to address security risks.
- Define and monitor security KPIs and operational metrics.
- Produce executive dashboards, monthly service reports, and incident trend analysis.
- Track SLA compliance, incident response times, threat trends, and security maturity improvements.
- Minimum 7 years of experience in cybersecurity, security operations, or managed security services.
- Minimum 2 years of experience in a Security Lead, SOC Lead, Incident Response Lead, or equivalent leadership role.
- Experience working within a Managed Security Service Provider (MSSP) environment is highly preferred.
- Proven experience managing enterprise security operations and customer-facing security services.
- Bachelor's Degree in Cybersecurity, Computer Science, Information Security, Information Technology, or a related field
- CISSP (Certified Information Systems Security Professional) – Mandatory.
- CISM (Certified Information Security Manager) – Preferred.
- ISO 27001 Lead Auditor or Lead Implementer – Mandatory.
- Additional certifications such as CEH, GCIA, GCIH, SC-200, AZ-500, or equivalent are advantageous.
- Strong knowledge of SOC operations, SIEM, SOAR, EDR, XDR, IDS/IPS, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).