Security Operations Centre (SOC) Manager
Triskele Labs · Melbourne, Victoria, Australia
Apply & track with Apply EdgeTwelve years ago Triskele Labs was one person and an idea about how cyber security should actually be delivered. Today we run a 24x7x365 Security Operations Centre (SOC) that never leaves Australian soil, an MDR practice protecting regulated enterprise, government and higher education, and one of the busiest DFIR benches in the country. Still founder-led. Still independently owned. Still Australian.We are looking for the leader who takes the SOC further.The RoleYou own how well our MDR service runs in front of the client.That means the L1 to L3 analyst team across our state-based SOCs. It means rostering, capacity and fatigue across a round-the-clock operation. It means triage quality, service levels, escalation handling and the development of every analyst doing the work. And it means the SOC's workflow and triage automation roadmap, delivered through your SOC Automation Analyst.This is a hands-on operational leadership role, not a reporting layer. You will need the depth to challenge an analyst's conclusion, read playbook logic rather than just its outcomes, and judge what a detection or automation change will do to the live queue before it gets there.The DetailThe role sits alongside our Platform Engineering Manager. Between you, you carry the MDR service.Platform Engineering owns what the service can detect, hunt and validate: detection engineering, threat intelligence, threat hunting, breach attack simulation. The SOC owns how well that capability is operated.You are not building the detection capability. You are leading the function that consumes it well, and you are the peer who tells Platform Engineering the truth about what is and isn't working in the queue. Weekly rhythm and joint prioritisation, not an escalation path used after something has already gone wrong.Automation runs the other way. Workflow and triage automation belongs to you. You decide what gets automated next and you hold the quality bar on playbook design, with the SOAR Engineer and DevOps providing the platform underneath.Clear lines, real ownership, a genuine peer to argue with. That boundary is deliberate, and it's the most important thing to understand about the job.The PositionLeading, coaching and developing the analyst team: performance, career pathways, successionRoster fairness, fatigue monitoring and analyst wellbeing across a 24x7 operationSLA, KPI and incident response commitments, and acting as the senior operational escalation pointThe SOC automation roadmap, agreed with the Head of Managed ServicesOperational readiness for new client onboarding: tooling, alerting, runbooks and analysts ready before go-liveSenior escalation contact for key MDR clients, and the quality of what we put in front of themSOC processes, SOPs and runbooks aligned to ISO 20000, ISO 27001 and SOC 2Driving the operational evolution of our SIEM, SOAR and EDR toolingThe analyst development pathway from L1 through to L3 and onward into Platform Engineering, DFIR or engineering specialisationsYour FitYou have run a SOC, not just worked in one. You can hold a technical argument with an L3 and win it on the merits. You have opinions about what should and shouldn't be automated, and scars from getting it wrong. You take rostering and analyst burnout as seriously as MTTR. And you can sit in front of a client during a bad week and be the reason they stay calm.What we provideA SOC with real scale and real clients, sovereign and onshore. Front-line threat intelligence from an active DFIR practice. A founder-owned business where the decision-maker is in the building. And the mandate to build the operation you think a SOC should be. ApplicationA cover letter addressed to Brad Morgan, Head of Managed Services, is mandatory. Applications without one will not be considered.Tell us about a SOC you have run, and one operational problem you fixed that the metrics can prove.