- Company Name
- Sectech Solutions
- Job Title
- Head of Cyber Defence
- Job Description
-
Job Title: Head of Cyber Defence
Role Summary:
Lead and mature global cyber defence and Security Operations Centre (SOC) capabilities. Direct day‑to‑day SOC operations, incident response, threat detection, and security monitoring across on‑premise, cloud, and hybrid environments. Collaborate with security engineering, risk, compliance, and technology teams to improve detection, response, and operational resilience.
Expectations:
- Deliver 24/7 SOC leadership and continuous improvement in SOC maturity.
- Serve as the primary escalation point for all SOC analysts (L1‑L3).
- Implement and maintain runbooks, playbooks, and operational procedures.
- Drive automation, tooling upgrades, and detection use‑case enhancements.
- Manage major incident response lifecycle, conduct post‑incident reviews, and support crisis response.
- Provide clear reporting on security events, trends, and operational performance to senior stakeholders.
- Mentor and develop SOC staff, fostering a culture of collaboration and continuous improvement.
Key Responsibilities:
- Oversee SOC analysts and security monitoring operations.
- Lead incident detection, investigation, and response activities.
- Coordinate escalation and response across internal teams and external partners.
- Develop SOC runbooks, playbooks, and operational procedures.
- Enhance SIEM detection use cases, analytics, and alerting.
- Integrate threat intelligence to identify emerging threats.
- Drive automation and tooling improvements within the SOC.
- Conduct post‑incident reviews and lessons‑learned exercises.
- Support cyber crisis response for major incidents.
- Identify and close gaps in monitoring, logging, and response capabilities.
- Collaborate with security engineering to improve EDR, SIEM, and security tooling.
- Provide stakeholder engagement with technology, infrastructure, risk, and compliance teams.
- Support regulatory, audit, and client assurance activities.
Required Skills:
- Extensive experience in security operations, cyber defence, or incident response.
- Proven SOC team management background.
- Deep knowledge of SIEM platforms, EDR, threat detection, response, and log analysis.
- Strong understanding of threat actors, attack techniques, and detection strategies.
- Hands‑on incident incident coordination experience.
- Familiarity with cloud security environments and modern infrastructure.
- Ability to improve detection use cases and SOC processes.
- Excellent communication skills; able to engage technical and senior business stakeholders.
- Calm, structured, and decisive under high‑pressure incidents.
Required Education & Certifications:
- Bachelor’s degree in Information Security, Computer Science, or related field, or equivalent experience.
- Industry certifications: CISSP, CISM, GIAC, GCIA / GCIH or equivalent operational security certifications.
---