KPMG Ukraine

Manager - Consulting Implementation

KPMG Ukraine  •  Mumbai, IN (Onsite)  •  1 month ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

The SOC Manager is responsible for leading and managing the organization's Security Operations Center (SOC), ensuring effective monitoring, detection, investigation, response, and remediation of cybersecurity threats. The role oversees Incident Response, Threat Hunting, Threat Intelligence, Threat Detection Engineering, and SOC operations while driving continuous improvement of security monitoring capabilities and cyber defense strategies.

1. Security Operations Management

  • Lead and manage 24x7 SOC operations and security monitoring activities.
  • Develop and implement SOC processes, procedures, and operational metrics.
  • Ensure timely triage, analysis, escalation, and resolution of security incidents.
  • Drive operational excellence through process optimization and automation.
  • Manage SOC analysts, incident responders, and threat hunters.

2. Incident Response

  • Lead cyber incident response activities for security breaches, malware, ransomware, phishing, insider threats, and advanced persistent threats (APTs).
  • Coordinate containment, eradication, recovery, and post-incident reviews.
  • Develop and maintain Incident Response Plans, Playbooks, and Runbooks.
  • Conduct root cause analysis and lessons learned exercises.
  • Collaborate with legal, compliance, IT, and executive leadership during major incidents.

3. Threat Hunting

  • Build and mature proactive threat hunting capabilities.
  • Develop threat-hunting hypotheses based on intelligence and adversary tactics.
  • Perform endpoint, network, cloud, and log-based threat hunting activities.
  • Identify stealthy threats, attacker behaviors, and indicators of compromise (IOCs).
  • Recommend detection improvements from hunting findings.

4. Threat Intelligence

  • Establish and manage Cyber Threat Intelligence (CTI) programs.
  • Analyze emerging threats, adversary tactics, techniques, and procedures (TTPs).
  • Integrate threat intelligence feeds into SOC operations and SIEM platforms.
  • Produce actionable intelligence reports for technical and leadership teams.
  • Track global threat actors, vulnerabilities, and industry-specific cyber risks.

5. Threat Detection Engineering

  • Design, implement, and continuously improve threat detection use cases.
  • Develop SIEM detection rules, correlation searches, and analytics.
  • Tune alerts to reduce false positives and improve detection effectiveness.
  • Map detections to MITRE ATT&CK framework.
  • Work with threat hunters and incident responders to enhance visibility and detection coverage.

6. Security Monitoring & SIEM Management

  • Manage SIEM, EDR, NDR, SOAR, and Threat Intelligence platforms.
  • Ensure log onboarding, normalization, and retention requirements are met.
  • Monitor cloud, endpoint, network, and application security events.
  • Drive automation and orchestration initiatives to improve SOC efficiency.

7. Risk, Compliance & Reporting

  • Support compliance frameworks such as ISO 27001, NIST CSF, PCI DSS, CIS Controls, SOC2, and GDPR.
  • Report cybersecurity posture, KPIs, KRIs, and incident trends to senior management.
  • Participate in audits, assessments, and regulatory reviews.

8. Team Leadership

  • Mentor and develop SOC analysts and cybersecurity professionals.
  • Conduct performance reviews and training programs.
  • Build career development and succession plans within the SOC team.
  • Foster a culture of continuous learning and operational excellence.
  • 8+ years of Cybersecurity experience.
  • 3–5+ years of SOC leadership or managerial experience.
  • Experience managing enterprise SOC environments and incident response engagements.
  • Experience with cloud security monitoring and multi-cloud environments preferred.
  • SIEM: Microsoft Sentinel, Splunk, QRadar, ArcSight, LogRhythm
  • EDR/XDR: Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black
  • SOAR: Palo Alto XSOAR, Splunk SOAR, Microsoft Sentinel Automation
  • Threat Intelligence Platforms (TIP)
  • Network Security, IDS/IPS, Firewall

KPMG Ukraine

About KPMG Ukraine

KPMG – це міжнародна мережа фірм, що надають аудиторські, податкові та консультаційні послуги. В офісах KPMG у 143 країнах світу працюють понад 273,000 співробітників (FY23). Кожна фірма KPMG є незалежною юридичною особою і представляє себе як таку.

KPMG працює в Україні з 1992 року. KPMG в Україні надає аудиторські, податкові, бухгалтерські та консультаційні послуги для місцевих і міжнародних компаній. Нашою метою завжди було використання глобального інтелектуального потенціалу фірми в поєднанні з практичним досвідом наших українських професіоналів, щоб допомогти провідним компаніям досягти своїх цілей.

Офіси компанії знаходяться у Києві та Львові.

______________

KPMG is a global network of professional services firms providing audit, tax and advisory services. We operate in 143 countries and territories, and in FY23, collectively employed more than 273,000 people working in member firms around the world.

KPMG in Ukraine provides audit, tax, accounting and advisory services to local and international businesses. KPMG has been working in Ukraine since 1992, and our goal has always been to use the firm's global intellectual potential, combined with the practical experience of our Ukrainian professionals, to help leading companies to achieve their goals.

In Ukraine KPMG has its offices in Kyiv and Lviv.

Industry
Consulting & Advisory
Company Size
201-500 employees
Headquarters
Kyiv, UA
Year Founded
1992
Website
kpmg.com
Social Media