Role Summary
The AVP – SOC is responsible for the day-to-day operational effectiveness, technical execution, and continuous optimization of the bank's security monitoring capabilities. Reporting directly to the Head of SOC, this role provides hands-on technical leadership to ensure rapid threat detection, effective triage, and seamless telemetry engineering. The AVP – SOC acts as the primary operational interface between the bank's security platform engineering, threat hunting functions, and the outsourced Managed Security Service Provider (MSSP). The role demands a balance of deep technical capability in detection engineering, robust vendor management skills, and agile project delivery.
Key Responsibilities
1. Tactical SOC Operations & Technical Leadership
- Operational Command: Manage day-to-day SOC detection and analysis workflows, serving as the first line of escalation for complex technical investigations and high-priority alerts.
- Shift & Tier Oversight: Oversee the operational cadence of monitoring layers, ensuring high-quality analyst triage, continuous operational coverage, and adherence to strict quality gates.
- Incident Bridge Support: Act as the primary technical lead during incident escalation, driving initial triage, technical bridge orchestration, and containment coordination before elevating severe crises to the Head of SOC.
2. Detection Engineering & Architecture Optimization
- Pipeline Management: Own the optimization and maintenance of SIEM, UEBA, EDR, and NDR telemetry pipelines, ensuring high-fidelity log ingestion and parsing.
- Use Case Development: Architect, tune, and maintain detection content explicitly mapped to the MITRE ATT&CK framework to aggressively reduce false positives and analyst alert fatigue.
- SOAR Orchestration: Partner with Cyber Engineering to design, test, and implement automated playbooks within the SOAR platform for automated alert enrichment, containment, and ticketing.
3. MSSP Governance & Vendor Performance
- SLA Enforcement: Provide direct operational governance over the outsourced MSSP/MDR provider, monitoring daily SLA compliance, tracking operational metrics, and conducting routine performance reviews.
- Capability Integration: Drive tight operational alignment between internal monitoring capabilities and the outsourced MSSP teams, ensuring seamless handoffs during alert triage and threat-hunting cadences.
- Logging Validation: Collaborate with infrastructure teams to audit and ensure that critical business assets are consistently logging to the SOC platform in accordance with security policies.
4. Proactive Threat Hunting & Intel Integration
- Hunting Execution: Plan and execute hypothesis-driven threat hunting exercises across the bank's networks, endpoints, and cloud environments to uncover hidden persistent threats.
- Intel Operationalization: Translate tactical cyber threat intelligence (from FS-ISAC and commercial feeds) into immediately deployable SIEM correlation rules, firewall blocks, and EDR containment criteria.
5. Regulatory Compliance & Audit Readiness
- Evidence Preparation: Collate and maintain defensible operational logs, incident investigation timelines, and runbook documentation to support central bank (BNM RMiT) audits and compliance checks.
- Remediation Delivery: Execute technical remediation plans and process improvements stemming from post-incident Root Cause Analysis (RCA) and audit findings under the guidance of the Head of SOC.
6. Team Coaching & Project Delivery
- Analyst Development: Mentor, coach, and upskill internal security analysts and engineers, formulating individual skills matrices and technical training paths (e.g., GIAC, SANS).
- Project Management: Lead cybersecurity implementation and modernization projects end-to-end, managing milestones, technical dependencies, and deliverables aligned with broader Cyber Defense objectives.
Key Performance Indicators (KPIs)
- Operational Efficiency: Continuous reduction of median and P90 Mean Time to Acknowledge (MTTA) and Mean Time to Triage/Contain across the operational tiers.
- Detection Efficacy: Measurable expansion of MITRE ATT&CK coverage and a proven decrease in false-positive ratios across active SIEM use cases.
- MSSP Adherence: Maintenance of vendor SLA compliance scores above target thresholds, with zero undocumented escalation delays.
- Automation Index: Percentage increase in the volume of security alerts successfully auto-enriched or auto-remediated via SOAR playbooks.
- Remediation Velocity: On-time delivery of SOC-related project milestones and swift closure of assigned post-incident RCA action items.
Job Requirements
Required Qualifications
- Education: Bachelor's degree in Computer Science, Information Security, Computer Engineering, or a related technical field.
- Experience: 7–10+ years of dedicated professional experience in cybersecurity, with at least 3–5 years directly leading or supervising technical SOC operations or advanced incident response teams.
- Technical Proficiency: Hands-on experience configuring, managing, and engineering enterprise-grade security tools (e.g., Splunk, QRadar, CrowdStrike, SentinelOne, Palo Alto Cortex XSOAR, MISP).
- Framework Mastery: Deep operational familiarity with the MITRE ATT&CK framework, NIST SP 800-61, and modern cyber kill chain strategies.
- Investigative Skills: Proven capability in digital forensics, log analysis across heterogeneous operating systems, network traffic analysis, and structured root cause determination.
Preferred Certifications
- Technical Operations: GIAC Certified Intrusion Analyst (GCIA), GIAC Certified Incident Handler (GCIH), GIAC Continuous Monitoring Certification (GMON).
- Forensics & Intelligence: GIAC Certified Forensic Analyst (GCFA), GIAC Cyber Threat Intelligence (GCTI).
- Security Governance: CISSP or CISM.
Core Competencies
- Technical Depth: Ability to dive deep into endpoint/network telemetry, cloud infrastructure data, and identity logs to piece together complex attack chains.
- Operational Discipline: Strong execution focus with a strict command over metrics, playbooks, operational gates, and data-driven decision-making.
- Calm Under Pressure: Ability to maintain logical rigor, clarity, and rapid execution speed during active, fast-moving security incidents.
- Collaborative Influence: Excellent interpersonal and technical communication skills to seamlessly manage relations with internal IT teams and external MSSP vendors.