SOC Manager
Listed on 2026-09-08
-
IT/Tech
Security Management & Operations, Cybersecurity
About the role
The SOC Manager is responsible for leading the day-to-day operations of the RADICL vSOC. This role directly manages a team of security analysts across all tiers, ensuring 24×7 coverage through disciplined shift scheduling, rigorous escalation management, and continuous process improvement. The SOC Manager serves as the critical bridge between front-line analyst operations and the broader security programs — including incident response, threat intelligence, threat hunting, and detection engineering — ensuring seamless integration of analyst triage and investigation workflows into each discipline.
If the above excites you, RADICL Defense is seeking high performing, motivated individuals to join our mission.
As an early member, you will work closely alongside an experienced founding team and realize the life-changing experience of building a company. You will work with the latest technologies in software, cybersecurity, and cloud and will have a significant impact on the formation of our platform and offering.
You enjoy fast-paced environments, bring a positive attitude, and excel at getting things done. You enjoy being part of a high performing team and are also able to self-direct and self-start. You consider yourself to be top tier talent and are eager to help others raise their game. You enjoy working with customers, are an excellent communicator, and able to engage and interact with people of various backgrounds and skill levels.
You want your work to have meaning, to be important. You want to be part of creating something great.
Team Leadership & People Management
- Directly manage a team of Tier 1, Tier 2, and Tier 3 security analysts, providing day-to-day leadership, coaching, mentorship, and performance management.
- Conduct regular 1:1s, team meetings, and performance reviews; set clear goals and development plans aligned with individual and organizational objectives.
- Foster a high-performance, collaborative SOC culture with a focus on analyst growth, retention, and well-being across a 24×7 operational environment.
- Manage shift handoffs, holiday coverage, and surge staffing plans to address operational gaps without analyst burnout.
- Participate in hiring, onboarding, and skills development initiatives for the analyst team.
- Own and continuously refine the SOC escalation framework, ensuring clearly defined escalation paths, SLAs, and communication protocols.
- Serve as an escalation point for complex, high-severity, or ambiguous security events, providing real-time guidance and decision-making support to analysts.
- Coordinate escalations to client security teams, executive stakeholders, and third-party responders as required, maintaining clear and timely communication throughout.
- Conduct post-escalation reviews to identify process gaps and drive continuous improvement.
- Ensure analyst triage and investigation workflows are tightly integrated with the MDR incident response lifecycle, from initial detection through containment, eradication, and recovery.
- Collaborate with the Incident Response team to define and document IR playbooks, ensuring analysts are trained and prepared to execute them effectively.
- Oversee analyst participation in incident response activities, coordinating handoffs and maintaining situational awareness during active incidents.
- Conduct or facilitate post-incident reviews (PIRs) with the analyst team to extract lessons learned and drive process improvements.
- Partner with the RAID team to operationalize intelligence within the SOC, ensuring analysts are consuming and applying relevant TI in their daily triage and investigation activities.
- Facilitate regular TI briefings and knowledge-sharing sessions to keep the analyst team current on adversary TTPs, active threat campaigns, and client-relevant intelligence.
- Provide operational feedback to the RAID team on intelligence relevance, gaps, and analyst consumption patterns to continuously refine RAID outputs.
- Coordinate analyst involvement in threat…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).