Security Operations Centre Manager
Triskele Labs · Melbourne, Victoria, Australia
Apply & track with Apply EdgeTriskele Labs is one of Australia's leading sovereign cyber security firms, delivering Managed Detection & Response (MDR), Digital Forensics & Incident Response (DFIR), Offensive Security, and Governance, Risk & Compliance (GRC) services to regulated enterprises, government, and the higher education sector. Built over more than a decade, founder-led and independently owned, we partner with clients operating under some of Australia's most demanding regulatory regimes.Our Security Operations Centre runs 24x7x365 and remains completely onshore, and we are the largest CREST Registered Penetration Testing company in Melbourne. Sovereign Australian ownership, deep technical capability, and front-line threat intelligence from one of the most active DFIR practices in the country sit at the centre of how we differentiate.We are hiring a SOC Manager to lead the operational performance of our Australian Security Operations Centres. You will manage our L1 to L3 analyst structure, you will own rostering and capacity across a 24x7x365 operation, own the SOC's workflow and triage automation roadmap through your SOC Automation Analyst, and be accountable for how well our MDR service actually runs in front of the client.The role sits alongside our Platform Engineering Manager, and the two roles carry the MDR service between them. Platform Engineering owns what the service can detect, hunt and validate: detection engineering, cyber threat intelligence, threat hunting and breach attack simulation. The SOC owns how well that capability is operated: triage quality, service levels, escalation handling, client communication, the development of the analysts doing the work, and the workflow and triage automation that makes the operation scale.That boundary is deliberate and it is the most important thing to understand about this role. You are not building the detection capability. You are leading the function that consumes it well, and will need to be the peer who tells Platform Engineering the truth about what is and is not working in the queue. The partnership is at a minimum a weekly operating rhythm and joint prioritisation, not an escalation path used after something has gone wrong.Automation runs the other way. Workflow and triage automation belongs to the SOC, and the SOC Automation Analyst reports to you. You decide what gets automated next, you hold the quality bar on playbook design, and you partner with the SOAR Engineer and the DevOps team, who provide the platform capability, integrations and infrastructure underneath.This is a hands-on operational leadership role, not a reporting layer. You will need enough technical depth to challenge an analyst's conclusion, review playbook logic rather than just its outcomes, and judge the operational impact of a detection or automation change before it reaches the live queue.You must be able to weigh the risk and the benefit of those decisions, to keep our service at the forefront of our clients' cyber security concerns while supporting our team to do their work effectively and safely.Key ResponsibilitiesLeadershipLead, coach and manage the SOC analyst team from L1 through to L3, and the SOC Automation Analyst, across state-based Security Operations Centres, owning performance reviews, career development and succession planningOwn rostering, scheduling and capacity across a 24x7x365 operation, including roster fairness, fatigue monitoring, mental health awareness and analyst wellbeingRefine and drive the analyst development pathway from L1 through to L3 and onward into Platform Engineering, DFIR or engineering specialisations, identifying training needs and knowledge gaps and acting on them. Operational managementEnsure day-to-day SOC operations meet SLA, KPI and incident response commitments, and act as the key operational escalation point for the teamOversee escalations across the L1 to L3 tiers and coordinate high-severity incident response, shift standups and handoffsOwn workflow and triage automation and the SOC automation roadmap, agreed with the Head of Managed Services and delivered through the SOC Automation Analyst who reports to you: deciding what gets automated next, reviewing playbook design and logic, and holding delivery and qualityMaintain SOC processes, SOPs, runbooks and knowledge management aligned to ISO 20000, ISO 27001 and SOC 2, and support audit preparation and evidence rigourDrive incident simulation planning, and support post-incident reviews so that what is learned reaches the runbooksClient serviceAct as a senior escalation contact for key MDR clients, and attend client meetings during onboarding, escalation and service reviewOwn the operational readiness of new client onboarding into the SOC: tooling, alerting, runbooks and analyst enablement in place before the client goes liveEnsure the quality, consistency and timeliness of incident documentation, case categorisation, remediation guidance, threat briefs and monthly service reportingCapability and toolingDrive the evolution of the SOC's tooling and automation, SIEM, SOAR and EDR, from the operational side, and evaluate emerging technology for what it would genuinely do for triage quality, response time and analyst effortDefine the SOC's operational requirements for tooling and workflow, and work with Engineering, DevOps and Platform Engineering to see them deliveredPlatform Engineering partnershipHold the peer relationship with the Platform Engineering Manager: weekly operational alignment, joint prioritisation of detection improvements, and integration of client feedback into their roadmapOwn the SOC side of the feedback loop, ensuring false-positive patterns, noisy alerts and missed-detection observations reach Detection Engineering in a structured, actionable formEnsure Platform Engineering output, validated detections, enriched indicators, hunt findings and BAS gap data, is operationalised in the SOC with analysts trained and runbooks updated before the change reaches the queueGovernance and reportingEnsure SOC practice remains compliant with ISO 27001, ISO 20000 and SOC 2, and contribute to internal and external governance and assurance reportingProvide regular reporting to the Head of Managed Services on performance, escalations, threats, staffing and initiativesOrganisational contributionContribute to Triskele Labs' thought leadership through blog content, Brown Bag talks and internal showcasesRepresent the SOC at industry events and client forums where usefulLead by example to uphold the culture, values and technical standards expected of a high-performing SOCApplication ProcessA cover letter addressed to Brad Morgan, Head of Managed Services, is mandatory for this role. Applications without one will not be considered. Tell us about a SOC you have run and one operational problem you fixed that the metrics can prove.RequirementsAustralian citizenship or permanent residency. This is a sovereign MDR requirement and sponsorship is not availableBased in Melbourne and able to work on-site, with some work from home available by agreementMinimum five years in a SOC environment, including at least two years in a leadership roleProven experience managing 24x7 SOC operations, shift teams and security case processes in an MSSP or enterprise environment, including ownership of rostering and capacity planningStrong technical understanding of SIEM, SOAR, EDR and incident response, enough to challenge an analyst's conclusion, review playbook logic, and hold a quality bar, not only to report on oneSound judgement on risk and benefit: able to weigh the operational upside of a detection, automation or process change against its impact on service quality, client risk, and the analysts who have to work with itExcellent written and verbal communication across technical and executive audiences, including direct client escalation handlingAvailable for after-hours escalation as required, and able to travel occasionally to other state-based SOC locations or clientsHighly RegardedDemonstrated ownership of a workflow and triage automation capability: deciding what to automate, reviewing playbook design, and directing the person building itDemonstrated ability to operate as a peer to an engineering or platform function without absorbing or duplicating its remitStrong working knowledge of security frameworks including MITRE ATT&CK, NIST and ISOExperience with our stack or equivalent: Microsoft Sentinel, Splunk, Rapid7 InsightIDR, Elastic, Microsoft Defender, CrowdStrike, and Shuffle or an equivalent SOAR platformHands-on SOAR playbook build experience, or the ability to review playbook logic in detail rather than only its outcomesExperience managing geographically distributed or state-based operational teamsExposure to ISO certification audits or SOC-CMM assessmentExperience building or operating an analyst development pathway and moving people through itCertifications such as GCIA, GCIH or equivalent SOC leadership credentials, and experience with reporting tools such as Power BIA bachelor's degree in cyber security or information technology, or demonstrated equivalent experienceBenefitsTeam culture is everything to Triskele Labs and it is the reason we exist. We are a forward-thinking company and always looking for ways to boost our team culture to ensure we are a destination employer. We continually undertake surveys to seek feedback from our team on ways we can improve our work environment and team member experience at Triskele Labs.We provide our team a great range of additional benefits such as:Collaborate closely with C-Suite executives and gain insights from top industry leadersHelp influence and lead the SOC Team's growth as we continue to expand throughout the Australian marketEnjoy a brand-new office located in the heart of Melbourne CBDFrequent events organised by our People & Culture TeamBenefits Specific to this roleOperational leadership of an onshore, sovereign 24x7 SOC serving financial services, government, health and higher educationA genuine peer partnership with a dedicated Platform Engineering function, rather than carrying detection engineering and operations in one overloaded roleA dedicated SOC Automation Analyst reporting to you, and a SOAR Engineer and DevOps team to partner with. The workflow and triage automation agenda is yours to set, with people to deliver itDirect reporting line to the Head of Managed Services, and close collaboration with our C-Suite. This is a role with genuine access to the people setting the direction of the businessReal influence over the growth of the SOC team as we continue to expand across the Australian marketReal capability to draw on: DFIR, CTI, threat hunting, detection engineering and offensive security practices in the same businessFunded certification and development, for you and for your teamA team that backs each other, with leaders who work the floor rather than manage from a distanceYou must include a cover letter addressed to Brad Morgan, Head of Managed Services to be considered for this role.Working Arrangements:The role is full time, Monday to Friday in our Melbourne office.