Security Operations Centre Manager
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Key Skills for This Role
Full Job Posting
Leadership
Lead, coach and manage the SOC analyst team from L1 through to L3, and the SOC Automation Analyst, across state-based Security Operations Centres, owning performance reviews, career development and succession planning.
Own rostering, scheduling and capacity across a 24x7x365 operation, including roster fairness, fatigue monitoring, mental health awareness and analyst wellbeing.
Refine and drive the analyst development pathway from L1 through to L3 and onward into Platform Engineering, DFIR or engineering specialisations, identifying training needs and knowledge gaps and acting on them.
Operational management
Ensure day-to-day SOC operations meet SLA, KPI and incident response commitments, and act as the key operational escalation point for the team.
Oversee escalations across the L1 to L3 tiers and coordinate high-severity incident response, shift standups and handoffs.
Own workflow and triage automation and the SOC automation roadmap, agreed with the Head of Managed Services and delivered through the SOC Automation Analyst who reports to you: deciding what gets automated next, reviewing playbook design and logic, and holding delivery and quality.
Maintain SOC processes, SOPs, runbooks and knowledge management aligned to ISO 20000, ISO 27001 and SOC 2, and support audit preparation and evidence rigour.
Drive incident simulation planning, and support post-incident reviews so that what is learned reaches the runbooks.
Client service
Act as a senior escalation contact for key MDR clients, and attend client meetings during onboarding, escalation and service review.
Own the operational readiness of new client onboarding into the SOC: tooling, alerting, runbooks and analyst enablement in place before the client goes live.
Ensure the quality, consistency and timeliness of incident documentation, case categorisation, remediation guidance, threat briefs and monthly service reporting.
Capability and tooling
Drive the evolution of the SOC’s tooling and automation, SIEM, SOAR and EDR, from the operational side, and evaluate emerging technology for what it would genuinely do for triage quality, response time and analyst effort.
Define the SOC’s operational requirements for tooling and workflow, and work with Engineering, DevOps and Platform Engineering to see them delivered.
Platform Engineering partnership
Hold the peer relationship with the Platform Engineering Manager: weekly operational alignment, joint prioritisation of detection improvements, and integration of client feedback into their roadmap.
Own the SOC side of the feedback loop, ensuring false-positive patterns, noisy alerts and missed-detection observations reach Detection Engineering in a structured, actionable form.
Ensure Platform Engineering output, validated detections, enriched indicators, hunt findings and BAS gap data, is operationalised in the SOC with analysts trained and runbooks updated before the change reaches the queue.
Governance and reporting
Ensure SOC practice remains compliant with ISO 27001, ISO 20000 and SOC 2, and contribute to internal and external governance and assurance reporting.
Provide regular reporting to the Head of Managed Services on performance, escalations, threats, staffing and initiatives.
Organisational contribution
Contribute to Triskele Labs’ thought leadership through blog content, Brown Bag talks and internal showcases.
Represent the SOC at industry events and client forums where useful.
Lead by example to uphold the culture, values and technical standards expected of a high-performing SOC.
Application Process
A cover letter addressed to Brad Morgan, Head of Managed Services, is mandatory for this role. Applications without one will not be considered. Tell us about a SOC you have run and one operational problem you fixed that the metrics can prove.
Requirements
- Australian citizenship or permanent residency. This is a sovereign MDR requirement and sponsorship is not available.
- Based in Melbourne and able to work on-site, with some work from home available by agreement.
- Minimum five years in a SOC environment, including at least two years in a leadership role.
- Proven experience managing 24x7 SOC operations, shift teams and security case processes in an MSSP or enterprise environment, including ownership of rostering and capacity planning.
- Strong technical understanding of SIEM, SOAR, EDR and incident response, enough to challenge an analyst’s conclusion, review playbook logic, and hold a quality bar, not only to report on one.
- Sound judgement on risk and benefit: able to weigh the operational upside of a detection, automation or process change against its impact on service quality, client risk, and the analysts who have to work with it.
- Excellent written and verbal communication across technical and executive audiences, including direct client escalation handling.
- Available for after-hours escalation as required, and able to travel occasionally to other state-based SOC locations or clients.
Highly Regarded
Demonstrated ownership of a workflow and triage automation capability: deciding what to automate, reviewing playbook design, and directing the person building it.
Demonstrated ability to operate as a peer to an engineering or platform function without absorbing or duplicating its remit.
Strong working knowledge of security frameworks including MITRE ATT&CK, NIST and ISO.
Experience with our stack or equivalent: Microsoft Sentinel, Splunk, Rapid7 InsightIDR, Elastic, Microsoft Defender, CrowdStrike, and Shuffle or an equivalent SOAR platform.
Hands-on SOAR playbook build experience, or the ability to review playbook logic in detail rather than only its outcomes.
Experience managing geographically distributed or state-based operational teams.
Exposure to ISO certification audits or SOC-CMM assessment.
Experience building or operating an analyst development pathway and moving people through it.
Certifications such as GCIA, GCIH or equivalent SOC leadership credentials, and experience with reporting tools such as Power BI.
A bachelor’s degree in cyber security or information technology, or demonstrated equivalent experience.
Benefits
- Team culture is everything to Triskele Labs and it is the reason we exist. We are a forward-thinking company and always looking for ways to boost our team culture to ensure we are a destination employer. We continually undertake surveys to seek feedback from our team on ways we can improve our work environment and team member experience at Triskele Labs.
- We provide our team a great range of additional benefits such as:
- Collaborate closely with C-Suite executives and gain insights from top industry leaders.
- Help influence and lead the SOC Team’s growth as we continue to expand throughout the Australian market.
- Enjoy a brand-new office located in the heart of Melbourne CBD.
- Frequent events organised by our People & Culture Team.
- Benefits Specific to this role
- Operational leadership of an onshore, sovereign 24x7 SOC serving financial services, government, health and higher education.
- A genuine peer partnership with a dedicated Platform Engineering function, rather than carrying detection engineering and operations in one overloaded role.
- A dedicated SOC Automation Analyst reporting to you, and a SOAR Engineer and DevOps team to partner with. The workflow and triage automation agenda is yours to set, with people to deliver it.
- Direct reporting line to the Head of Managed Services, and close collaboration with our C-Suite. This is a role with genuine access to the people setting the direction of the business.
- Real influence over the growth of the SOC team as we continue to expand across the Australian market.
- Real capability to draw on: DFIR, CTI, threat hunting, detection engineering and offensive security practices in the same business.
- Funded certification and development, for you and for your team.
- A team that backs each other, with leaders who work the floor rather than manage from a distance.
Working Arrangements
The role is full time, Monday to Friday in our Melbourne office.
About Triskele Labs
Australian-owned cybersecurity firm serving organizations with managed detection, incident response, offensive security, and governance services.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Triskele Labs
Commercial Operations Manager
Melbourne, AUS
Offensive Security Consultant
Melbourne, AUS
Digital Forensics Analyst
Melbourne, AUS
Level 1 Security Analyst
Melbourne, AUS
Offensive Security Consultant
Perth, AUS