SOC Manager – Security Operations Lead
Salmon Group Ltd · Serbie
Job description
About the role
You will own Security Operations at group level across a regulated bank, a consumer finance business, and a shared technology platform, reporting directly to the Group CISO. This role is central to protecting millions of users and partners in Southeast Asia.
Key responsibilities
- Define and drive monitoring, detection, and response strategy for cloud, identity, endpoints, SaaS, and containerised environments.
- Lead technical response during major cyber incidents and coordinate cross‑functional teams.
- Select, manage, and hold MSSP/MDR providers accountable, deciding when to build in‑house versus outsource.
- Own SIEM design, data source integration, retention policy, forensic readiness, and telemetry cost management.
- Define critical threat scenarios, maintain detection coverage, and conduct threat hunting using MITRE ATT&CK.
- Develop and maintain incident‑response playbooks, escalation procedures, and tabletop exercises.
- Manage vulnerability and exposure programs, set remediation priorities, and govern risk acceptance.
- Oversee DLP operations and access‑governance controls, including SSO, privileged access monitoring, and access reviews.
- Set priorities for the Security Operations team, define performance metrics, and ensure readiness for BSP and PCI DSS audits.
Required profile
- Proven experience managing MSSP/MDR providers, including selection, negotiation, and escalation.
- Hands‑on expertise with Microsoft Sentinel and KQL.
- Experience with Microsoft Defender XDR and Defender for Endpoint.
- Strong knowledge of Microsoft 365 security, audit telemetry, identity and access telemetry, and cloud security monitoring.
- Familiarity with containerised platforms and complex SIEM data flows.
- Track record of independently assessing security functions, prioritising risk versus cost, and leading through high‑severity incidents.
Required skills
- Microsoft Sentinel
- KQL (Kusto Query Language)
- Microsoft Defender XDR / Defender for Endpoint
- Microsoft 365 security and audit telemetry
- Identity and access telemetry
- Cloud security monitoring
- Container platforms
- SIEM design and data‑flow management
- MSSP/MDR management
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the Philippines.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 week ago
Expires 1 month from now
10 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Salmon Group Ltd
Serbie