We are seeking an experienced Security Operations Lead to build, manage, and continuously improve our internal Security Operations Centre (SOC). Based in Geneva or London, this role combines hands-on cyber defense with team leadership across three global offices (Singapore, London, and Houston). The ideal candidate is a technically proficient cybersecurity professional who can operate as both a senior incident handler (L2/L3) and a people leader shaping our detection and response capabilities.
KEY RESPONSIBILITIES
SOC Leadership & Governance
- Lead a team of 4 SOC analysts/engineers distributed across Singapore, London, and Houston, ensuring 24/7 coverage alignment and consistent service quality.
- Define and enforce SOC operating procedures, escalation paths, shift handover protocols, and performance metrics (MTTD, MTTR, false-positive rate).
- Report on SOC performance, threat landscape trends, and risk posture to the CISO and senior stakeholders.
- Manage the external SOC relationship — act as the primary interface with the outsourced SOC provider, govern service performance, drive continuous improvement, and ensure alignment with internal security objectives.
Detection Engineering & Threat Management
- Own the detection engineering lifecycle: develop, tune, and maintain analytics rules, correlation logic, and custom detections in Microsoft Sentinel (KQL) and across the broader security stack.
- Continuously improve detection coverage mapped to MITRE ATT&CK, reducing blind spots and noise.
- Evaluate and integrate threat intelligence feeds to enrich alerts and drive proactive hunting.
Incident Response & Hands-on Operations
- Act as a senior incident responder (L2/L3), leading triage, investigation, containment, eradication, and recovery for complex security incidents.
- Coordinate cross-functional incident response with IT, Legal, Compliance, and business units.
- Conduct post-incident reviews and root-cause analysis; translate findings into detection improvements and process updates.
Playbook & Process Development
- Author, maintain, and test SOC playbooks and runbooks covering the full incident lifecycle (phishing, malware, insider threat, cloud compromise, ransomware, BEC, data exfiltration, etc.).
- Improve existing playbooks and create new ones based on emerging threats, red team findings, and lessons learned.
- Drive tabletop exercises and purple-team simulations to validate playbook effectiveness.
Red Team Collaboration & Purple Teaming
- Partner with the internal Red Team to translate adversary emulation results into actionable detection rules and response procedures.
- Participate in purple-team exercises, validating detection coverage and tuning alerts based on simulated attack paths.
Training & Capability Development
- Mentor and develop SOC team members through structured training plans, knowledge-sharing sessions, and hands-on coaching.
- Foster a culture of continuous improvement and professional growth across the distributed team.
Experience & Education
- 4+ years of progressive experience in cybersecurity operations, incident response, or security engineering.
- Demonstrated experience leading or managing a SOC team, including remote/distributed personnel.
- Strong understanding of SOC operating models (tiered, hybrid, follow-the-sun).
- Proven track record of building or significantly improving detection and response capabilities.
Technical Expertise
- SIEM & Analytics: Microsoft Sentinel (KQL), log source onboarding, analytics rule development, workbook/dashboard creation.
- Endpoint Security: Microsoft Defender for Endpoint (MDE), CrowdStrike Falcon (EDR/XDR).
- Cloud Security: AWS (GuardDuty, CloudTrail, Security Hub) and Microsoft Azure (Defender for Cloud, Entra ID Protection); Wiz for cloud security posture management (CSPM).
- Data Security & DLP: Microsoft Purview (DLP, Information Protection, Insider Risk), Varonis (data access governance, threat detection).
- Network & Web Security: Zscaler (ZIA/ZPA), Palo Alto Networks (NGFW, Panorama, Cortex).
- Incident Response: Digital forensics fundamentals, malware analysis, memory/disk acquisition, chain-of-custody practices.
- Frameworks: MITRE ATT&CK, NIST CSF, NIST 800-61 (Incident Handling).
Soft Skills & Leadership
- Excellent communication and stakeholder management skills; ability to translate technical findings for executive audiences.
- Strong organisational and project-management abilities to coordinate across time zones.
- Analytical mindset with attention to detail and a bias for action.
- Preferred qualifications
- Industry certifications: CISSP, CISM, GCIH, GCIA, GCED, SC-200, AZ-500, or equivalent.
- Experience in the commodity trading, energy, or financial services sector.
- Familiarity with automation and orchestration (SOAR) platforms, scripting (Python, PowerShell, KQL).
- Experience with threat hunting methodologies and tools.
- French language skills (advantageous for Geneva-based candidates).
Travel
- Periodic travel between Geneva and London offices; occasional travel to Singapore and Houston for team engagement and alignment