Remote job
AI SOC Manager
Job details
About this role
Role overview Lead the day-to-day operation of a 24/7 security operations centre serving multiple clients. The role combines team leadership and incident response with setting safe, measurable ways to use AI agents in triage and investigation, while improving detection and response over time.
Responsibilities - Run SOC processes and procedures to deliver consistent detection and response across client environments. - Hire, lead and develop SOC leads and analysts; plan shifts and team capacity. - Set the scope, safeguards, human review points and quality measures for AI agent use in SOC workflows. - Own service-level performance, operational metrics and client reporting. - Maintain the incident response programme, including evidence handling, and lead the response to major incidents. - Set detection engineering and automation priorities with engineering teams; report threats, risks and performance to senior leaders and clients. - Drive operational improvement, audits and certification readiness.
Requirements - 8–12 years of security operations experience, including at least 4 years managing a SOC or security operations team. - Deep experience with SIEM, EDR/XDR and SOAR platforms in an enterprise or multi-client setting. - Strong incident response leadership, including experience managing major incidents. - Experience defining SOC metrics and service levels, and reporting to clients or executives. - Understanding of how AI and automation can support security operations, including their risks. - Strong leadership, communication and time-management skills.