← Browse all jobs

M

SOC Manager

Mobilink Microfinance Bank Ltd · Sindh, Pakistan

FULL TIME

Job Description

The Manager SOC will oversee and mature the bank’s Security Operations Center (SOC) operations with a focus on threat detection, incident response, and continuous monitoring. The incumbent will lead the integration, optimization, and operation of key security tools including SIEM, SOAR, DAM, XDR, FIM, IDS/IPS, and Active Directory Monitoring. The role ensures timely detection and response to cyber threats while maintaining compliance with State Bank of Pakistan (SBP) regulations and international best practices.

Responsibilities

  • 1. SOC Leadership & Operations
    • Lead end‑to‑end SOC operations and manage a team of L1–L3 analysts.
    • Ensure 24/7 security event monitoring through IBM QRadar SIEM and log aggregation from critical systems.
    • Coordinate use cases, correlation rules, and dashboards aligned with MITRE ATT&CK.
    • Manager SOC may be required to participate in rotational shifts or cover critical shifts to maintain 24x7 security operations coverage.
  • 2. Security Tools Management
    • Administer and fine‑tune SIEM for optimized event correlation and alerting.
    • Oversee SOAR playbook development and integration with SIEM and incident handling processes.
    • Ensure data activity monitoring via Database activity monitoring across databases and sensitive environments.
    • Manage XDR for endpoint, server, and network telemetry visibility and threat detection.
    • Ensure the effectiveness of File Integrity Monitoring (FIM) for policy and compliance alerts.
    • Operate and monitor Intrusion Detection and Prevention Systems (IDS/IPS) and respond to detected threats.
    • Administer Active Directory Monitoring for identity and privilege‑related event tracking and audit trail reporting.
  • 3. Incident Response & Threat Handling
    • Coordinate triage, investigation, containment, and remediation of security incidents.
    • Maintain and test incident response runbooks, including roles for key bank departments (Legal, HR, Compliance).
    • Collaborate with threat intelligence platforms for proactive risk awareness and TTP mapping.
  • 4. Compliance & Reporting
    • Ensure compliance with SBP’s regulations and cyber incident reporting guidelines.
    • Align SOC controls with ISO 27001 Annex A controls and PCI DSS requirements (e.g., logging, monitoring, IR).
    • Maintain reporting dashboards, incident records, and threat metrics for senior management and regulators.
  • 5. Threat Intelligence & Threat Hunting
    • Integrate internal and external threat intel sources into SIEM and SOAR (e.g., Resecurity, IBM XForce).
    • Lead proactive threat hunting exercises and simulate APT scenarios using MITRE ATT&CK mapping.
    • Generate actionable threat briefings, IoCs, and TTP insights relevant to the financial sector in Pakistan.
  • 6. Process Improvement & Automation
    • Continually improve SOC workflows and automate repetitive tasks using IBM SOAR.
    • Review and refine alert thresholds, correlation rules, and suppression logic to reduce false positives.
    • Conduct lessons learned exercises post‑incident and apply insights to SOC maturity roadmap.
  • 7. Team Development & Stakeholder Engagement
    • Train and mentor SOC analysts on tools, response tactics, and regulatory understanding.
    • Facilitate Red and Purple Teaming coordination with IS or third‑party partners.
    • Engage with IT, Risk, and Audit teams for continuous improvement and stakeholder alignment.

Qualifications

  • Education: Bachelor’s or Master’s in Information Security, Computer Science or related.
  • Certifications:
    • Certified Ethical Hacker (CEH) (Required)
    • CISM/CISA/CISSP (Preferred)
    • IBM QRadar / IBM SOAR Certified Specialist (Preferred)
    • GIAC Certified Incident Handler (GCIH), CompTIA CySA+, or equivalent (Preferred)
    • CSA (EC-Council), or Certified Threat Intelligence Analyst (CTIA) (Preferred)
    • ISO 27001 Lead Implementer/Auditor and PCI DSS awareness is a plus
  • 5–7 years of overall experience in cybersecurity.
  • Minimum 3+ years in SOC operations or incident response leadership.
  • Strong hands‑on experience with:
    • SIEM, SOAR, Database Activity Monitoring
    • XDR and FIM
    • IDS/IPS platforms
    • Active Directory Auditing or similar identity audit solutions
    • Integration and management of threat intelligence feeds

Job Location

Head Office

#J-18808-Ljbffr

Details

CompanyMobilink Microfinance Bank Ltd
LocationSindh, Pakistan
TypeFULL TIME
Nichegeneral

Similar Jobs

L

Responsable Technique Informatique (h/f)

LHH

L

Gestionnaire de paie h/f

LHH

L

Responsable Delivery Informatique (h/f)

LHH

L

Commercial itinérant Nord-ouest+IDF H/F

LHH

L

Comptable Général (h/f)

LHH