Job Description
Manager SOC Security Specialist
Department: Cyber Services and Capabilities
Employment Type: Full Time
Location: NLD Rijswijk
As a SOC Specialist Manager within NCC Groups MXDR SOC, your role is pivotal in improving the efficacy of the current operating SOC. This role focusses around improving the existing processes and detections within the SOC, across all our tech stacks that support the SOC services.
Key Responsibilities
Key accountabilities for this role are as follows:
- Co-ordinate the reviews of recommended alert filtering opportunities that have been flagged by analysts and implement filters in detection logic at the appropriate point, liaising with our detection engineering team for efficient filtering to drive down FP rates.
- Co-ordinate the baselining of clients that are being onboarded. Reviewing new clients’ estates, and again applying recommended filters where possible to present an acceptable level of alerting to the relevant SOC Manager prior to go-live date. This is across our MXDR Splunk, Sentinel, EDR, MNIA, MIS, OXM, IDS/IPS and DDoS services.
- Co-ordinate the overarching playbook templates, playbook creation and playbook maintenance for all services supported by the SOC.
- Collaborate with the SOC management team on process alignment, onboarding clients and the standardization of operating playbooks.
- Support the Head of SOC UK in client engagements across our Leeds & Manchester offices, as well as occasional on-site visits to clients when necessary.
- Conduct monthly/half year/yearly performance evaluation and mentorship for a small team of direct reports.
- Regularly update Head of SOC with improvement metrics, as well as advising on the MXDR strategy moving forwards with regards to specific improvements that can be identified in your role.
Skills, Knowledge & Expertise
- Experience within a SOC team lead role. (Flexible based on experience and technical level)
- Strong people management and leadership skills.
- Strong desire to improve and perfect processes, following an overall strategy of excellence.
Desirable Requirements
- Experience within any SOC operations role.
- Splunk Certified Power/Advanced Power User
- Microsoft SC200 Certified
- Experience working with CI/CD pipelines.
- CompTIA Certifications (Security+/ Network+/ Linux+)
- Crest, GIAC or CISSP Certification
- Degree in related field.
- Other relevant certifications.
Job Benefits
-
Flexible Working Balance your work and personal life with our flexible working options.
-
Generous Holiday Allowance Enjoy 25 days of holiday, plus bank holidays, with the option to buy up to 5 additional days of annual leave.
- Medicash & Critical Illness Scheme
-
Financial & Investment Benefits Enjoy peace of mind with our Pension, Life Assurance, and Share Save Scheme.
-
Community & Volunteering Programmes Make a difference in your community with our volunteering opportunities.
-
Green Car Scheme: Drive green and save money with our eco-friendly car scheme.
-
Cycle Scheme: Stay fit and healthy with our cycle-to-work scheme.
-
Special Time Off Take time off for those big moments in life, like getting married/entering into a civil partnership, becoming a grandparent, and welcoming home a new pet.
-
Family Planning Benefit from our generous maternity and paternity leave, as well as time off and support for those undergoing fertility treatments.