Operational Leadership: Coordinates the work of SOC analysts and the Incident Response team, assigns tasks and shifts, monitors team workload and SLA fulfillment. Serves as the primary escalation point for complex incidents and tracks key operational metrics;
Client Relations: Communicates directly with clients, organizes meetings as needed, and actively monitors their satisfaction with service quality;
Incident Response: Actively participates in leading high-priority incidents and coordinates collaboration between analysts and the IR team during active situations. Reviews and approves incident reports before sending them to clients;
Quality and Continuous Improvement: Checks the quality of documentation in tickets and closed offenses, identifies recurring false positives, and escalates tuning suggestions. Monitors team compliance with internal procedures and playbooks, tracks new detection rules, and proposes improvements. Writes and improves playbooks and participates in efforts to enhance overall SOC performance, as well as in standardization and compliance groups;
Team Development and Leadership: Mentors team members, monitors their development, organizes training, participates in the onboarding of new employees, and takes part in semi-annual and annual employee evaluations.

