Manager Security Operations Center
UltimoThe SOC Manager leads Ultimo’s 24x7 Cloud Security Operations Center, including its security engineers and analysts. The role manages incidents, compliance, and security improvements while shaping an AI-augmented SOC operating model.
Skills & Expertise
Key Responsibilities
Lead day-to-day Cloud Security Operations Center operations and manage major security incidents.
Improve security posture through vulnerability management and collaboration with engineering, platform, and product teams.
Develop the AI-augmented SOC operating model and lead, mentor, and develop the SOC team.
Full Description
Job Description
The SOC Manager is a strategic leadership role responsible for managing and overseeing all Security Operations Center activities on a 24x7 basis which is part of the Product & Customer Organization (PCO). In this position, you will lead a team of security engineers and analysts, manage major security incidents, ensure regulatory compliance, and drive continuous security posture improvements. You will be reporting to the Director of Cloud Services and Security who is responsible for PCO organization that manages cloud security strategy, infrastructure architecture oversight, operations alignment, and enterprise cloud and security initiatives.
Essential duties and accountabilities
• Lead and manage the day-to-day operations of the Cloud Security Operations Center (CSOC)
• Drive continuous improvement of the organization's security posture through collaboration with engineering, platform, and product teams.
• Oversee vulnerability management activities and ensure timely remediation of identified security risks and weaknesses.
• Support internal and external security audits, compliance assessments, customer security reviews, and evidence collection activities.
• Develop, maintain, and continuously improve SOC processes, procedures, runbooks, knowledge base articles (KBAs), and operational documentation.
• Plan, coordinate, and facilitate cybersecurity tabletop exercises, incident simulations, and operational readiness activities.
• Define, monitor, and report on SOC Key Performance Indicators (KPIs), Service Level Agreements (SLAs), and operational metrics to drive continuous improvement.
• Lead the SOC's workforce and reporting transformation for AI adoption redesigning analyst roles and upskilling paths toward AI-oversight and threat-hunting specialization, tracking automation effectiveness metrics, and acting as executive liaison for AI-related security incidents and governance decisions.
• Evaluate and recommend security technologies, automation opportunities, and operational improvements to enhance SOC maturity and effectiveness.
• Lead, mentor, and develop Security Engineers and Analysts, including hiring, onboarding, performance management, succession planning, and promotion assessments.
• Any other duties as designated by the line manager.
Overall required competence
• Strong leadership and people management skills
• Own the AI augmented SOC operating model
• Excellent stakeholder communication and executive reporting capabilities.
• Solid understanding of cloud security technologies and security architecture.
• Strong understanding of Security Operations Center functions and best practices.
• ITSM knowledge will be an added advantage.
• An ability to build strong relationships with internal teams, and senior leadership is essential
Qualifications
Essential: A degree in Information Security, Computer Science, or Information Technology with 5+ years of Security Operations Center, Incident Response, or Cyber Security Operations experience including 2+ years in a team leadership or management role.
Desirable:
• Experience managing global or distributed SOC teams
• Experience supporting enterprise compliance programs and security audits.
• One combination of: CISSP/CISM/CEH /CCSK / Security+ or other similar qualifications.
• Any cloud security specific certification or other qualifications is an added advantage.
• Previous experience on any of cloud providers (Amazon Web Services, Microsoft Azure, Google Cloud)
• Knowledge of automation, orchestration, and AI-driven security operations capabilities.
Additional Information
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.