SOC Team Leader

We are looking for a SOC Team Leader who will be responsible for the operational leadership of our Security Operations Center, coordinating responses to security incidents, team development and mentorship, improving operational processes, and ensuring high-quality services for our clients.

Job description:

Operational Leadership: Coordinates the work of SOC analysts and the Incident Response team, assigns tasks and shifts, monitors team workload and SLA fulfillment. Serves as the primary escalation point for complex incidents and tracks key operational metrics;

Client Relations: Communicates directly with clients, organizes meetings as needed, and actively monitors their satisfaction with service quality;

Incident Response: Actively participates in leading high-priority incidents and coordinates collaboration between analysts and the IR team during active situations. Reviews and approves incident reports before sending them to clients;

Quality and Continuous Improvement: Checks the quality of documentation in tickets and closed offenses, identifies recurring false positives, and escalates tuning suggestions. Monitors team compliance with internal procedures and playbooks, tracks new detection rules, and proposes improvements. Writes and improves playbooks and participates in efforts to enhance overall SOC performance, as well as in standardization and compliance groups;

Team Development and Leadership: Mentors team members, monitors their development, organizes training, participates in the onboarding of new employees, and takes part in semi-annual and annual employee evaluations.

Required qualifications:

Knowledge of SIEM platforms, writing and optimizing correlation rules, tuning, false positive analysis, understanding architecture and data flow;
Knowledge of Incident Response processes and methodologies;
Good knowledge of the MITRE ATT&CK framework and practical application in detection, triage, and hunt activities;
Experience in analyzing logs from heterogeneous sources – endpoint (EDR), network, firewall, AD/IdP, cloud;
Knowledge of malware analysis fundamentals and the ability to interpret IOCs in an operational context;
Understanding of vulnerability management processes and correlation with detection;
Knowledge of relevant standards and frameworks – NIST, ISO 27001, CIS Controls;
Experience in leading and mentoring teams in a high-intensity operational environment.

Desired competencies:

Knowledge of SOAR platforms, creating and improving playbooks, automating triage and response actions, integration with external tools;
Experience with threat intelligence platforms and applying TI feeds in daily SOC operations.

Apply for this position

Drag & Drop Files, Choose Files to Upload
Data processing

We offer you:

Projects with advanced technologies
Work in a team of experienced IT professionals
Professional development (training)
Private health insurance
Hybrid work model
Group sports activities

Apply for this position

Drag & Drop Files, Choose Files to Upload
Data processing

Guardians of your business

As a strategic partner of the Telekom Srbija Group, PULSEC combines regional and global expertise with state-of-the-art technology to provide organizations with reliable protection against modern cyber threats.

Similar open positions: