Manager SOC
Job Summary
The SOC Manager leads the Security Operations Centers people processes and technology to detect investigate and respond to cybersecurity threats across the organization on a 24x7x365 basis. This role owns the SIEM/SOAR platform strategy drives proactive threat hunting and intelligence integration and ensures the SOC operates with strong governance automation and continuous improvement. The SOC Manager acts as a key crisis leader during security incidents and serves as a trusted communicator to technical teams and executive stakeholders alike.
Key Responsibilities
Security Operations Leadership
Own and manage 24x7x365 SOC operations ensuring continuous monitoring detection and response coverage across all shifts including nights weekends and holidays.
Design and maintain shift schedules staffing models and follow-the-sun or on-call rotations to guarantee round-the-clock coverage without gaps.
Lead the SOCs daily operations including shift coverage escalation paths and performance metrics (MTTD MTTR alert volume/quality).
Define and continuously improve SOC processes playbooks and standard operating procedures.
Set strategic direction for the SOC in alignment with overall security and business objectives.
Incident Response & Crisis Management
Serve as incident commander for high-severity security incidents coordinating containment eradication and recovery.
Maintain and regularly test the incident response plan including tabletop exercises and post-incident reviews.
Coordinate cross-functional crisis response with IT legal communications and executive leadership as needed.
Threat Detection & Hunting
Direct proactive threat hunting programs to uncover hidden or emerging threats not caught by existing detections.
Continuously refine detection logic and use cases based on the evolving threat landscape and lessons learned from incidents.
SIEM/SOAR Management
Own the SIEM and SOAR platforms end to endarchitecture content development tuning and health monitoring.
Partner with engineering to ensure adequate log source coverage data quality and retention.
Threat Intelligence
Integrate internal and external threat intelligence into detection engineering risk assessments and briefings.
Track relevant threat actors TTPs and campaigns to inform SOC prioritization.
Cybersecurity Risk Management
Assess and communicate operational security risks partnering with stakeholders on remediation prioritization.
Support exception processes with clear well-documented rationale.
Security Automation
Drive automation initiatives (SOAR playbooks scripting orchestration) to reduce manual effort and improve response times.
Identify opportunities to eliminate repetitive analyst tasks through tooling and process redesign.
People & Stakeholder Management
Hire coach and develop SOC analysts and engineers; manage performance staffing and shift schedules.
Build strong partnerships with IT engineering legalandcompliancestakeholders.
Security Governance and Compliance
Ensure SOC operations align with internal policy regulatory requirements and audit/compliance obligations.
Maintain accurate documentation metrics and evidence to support audits and governance reviews.
Communication
Deliver clear concise incident reports summaries and operational updates to technical and non-technical audiences.
Represent the SOC in cross-functional meetings and executive briefings.
Core Competencies
Security Operations Leadership
Directs the day-to-day operation of a 24x7x365 Security Operations Center (SOC) setting priorities shift structures and performance standards to ensure continuous high-quality monitoring and defense coverage around the clock.
Incident Response & Crisis Management
Leads end-to-end incident response for security events coordinating containment eradication and recovery efforts and acting as incident commander during high-severity or crisis-level events.
Threat Detection & Hunting
Oversees proactive threat hunting activities and continuously improves detection logic to identify adversary behavior novel attack techniques and gaps in existing coverage.
SIEM/SOAR Management
Owns the SOCs SIEM and SOAR platforms end to enduse-case development correlation rule tuning playbook design and platform healthto maximize detection fidelity and response speed.
Threat Intelligence
Integrates threat intelligence feeds and analysis into SOC operations to inform detection priorities risk assessments and proactive defense measures against relevant threat actors.
Cybersecurity Risk Management
Evaluates and communicates operational security risk working with stakeholders to prioritize remediation and ensure risk decisions are made with accurate timely information.
Security Automation
Champions automation of repetitive SOC tasks and response workflows to reduce mean time to detect/respond and free analyst capacity for higher-value investigative work.
People & Stakeholder Management
Manages mentors and develops SOC analysts and engineers while building strong working relationships across IT engineering legal and executive stakeholders.
Problem Solving and Decision Making
Makes sound timely decisions under pressure and ambiguity applying structured problem-solving to complex evolving security situations.
Security Governance and Compliance
Ensures SOC processes align with security policies regulatory requirements and audit/compliance obligations maintaining thorough documentation and control evidence.
Good Written and Verbal Communication
Communicates technical findings and risk clearly to both technical and non-technical audiences including executive reporting and cross-functional coordination.
Bachelors degree in Cybersecurity Computer Science Information Technology or equivalent experience.
5 years of experience in security operations with at least 23 years in a leadership or management capacity.
Hands-on experience administering SIEM/SOAR platforms.
Demonstrated experience leading incident response for medium-to-high severity security events.
Strong understanding of threat intelligence threat hunting methodologies and the MITRE ATT&CK framework.
Excellent written and verbal communication skills including experience presenting to executive audiences.
Prior experience managing or operating within a 24x7x365 SOC environment including shift-based staffing models and on-call/escalation rotations.
Willingness to be available for off-hours escalation and to periodically work outside standard business hours in support of round-the-clock operations.
Preferred
Industry certifications such as CISSP CISM GCIH GCIA or equivalent.
Experience with security automation/scripting (Python PowerShell) and SOAR playbook development.
Experience operating within a regulated or compliance-driven environment (e.g. SOX PCI-DSS ISO 27001).
Background in vulnerability management risk management or governance functions.
Benefits:
- Hybrid working arrangements (2/3 days in the office)
- Annual performance-related bonus
- 6x Flexi Anyday: knock 2.5 hours off your day on any workday
Engaging fun & inclusive culture: check out the MRI Software APAC Insta feed and stories!
About Us
From the day we opened our doors MRI Software has built flexible game-changing real estate software that powers thriving communities and helps make the world a better place to live work and play. Fulfilling that mission is only possible because of one thing: exceptional people. People like you!
Our people-first approach to PropTech is defining a new industry standard for client experiences that quite frankly cant be duplicated. Experiences that deliver real value every day. And we know those experiences begin with our people.
We believe MRI is more than just a workplace; its a connected community of people who truly feel they belong. Whether were investing in employee resource groups or providing tailored resources for each person to reach their full potential were passionate about creating a work environment that makes you excited to show up every single day.
At MRI one of our core values is to strive to amaze. From the intelligent solutions we create to the culture we cultivate thats our goal every day. Because thats what industry leaders do. Whether youre joining as a new Pride member or rejoining us after a short time away your talent is vital to us our partners and our clients.
Amazing growth requires amazing employees. Are you up to the challenge
We know confidence gap and imposter syndrome can get in the way of meeting remarkable candidates so please dont hesitate to apply. Wed love to hear from you!
MRI is proud to be an inclusive employer. We welcome and celebrate diversity across all backgrounds including ethnicity religion sexual orientation gender identity disability age military veteran status and more.
We believe that Belonging is a direct result of Diversity Equity and Inclusion. Those values are woven into the fabric of who we are and are foundational to our continued success. Come and see for yourself!
Required Experience:
Manager
About Company
MRI Software offers innovative, open and connected technology for real estate owners, operators & occupiers. Transforming the way communities live, work & play.