أبلاي إيدج ابدأ البحث عن عمل

Security Operations Manager

Arpya · Tirana, Albania

قدّم وتابع مع أبلاي إيدج
ABOUT ARPYAArpya is the cybersecurity and AI division of Global Technologies Italia, an engineering group of approximately 120 professionals that has served major Italian enterprises for more than twenty years, with a project roster that includes Enel, Ford, Vodafone, AXA and Reply.THE ROLEWe are looking for a SOC Lead to take professional ownership of Arpya’s managed detection and response service.The position is accountable for how the service runs and for the quality of everything it produces: the coverage it provides, the incidents it handles, the decisions it makes under pressure, the reports that reach the client, and the development of the analysts who do the work.It is a leadership role with substantial hands-on technical contribution. You are expected to work inside the platforms rather than above them, and to remain credible in front of both an analyst and a client’s IT director. The indicative balance between leadership and hands-on work is set out and agreed at offer stage rather than left to assumption.THE SERVICE YOU WILL LEADArpya’s defensive practice delivers managed detection and response to clients in regulated sectors, spanning:Continuous monitoring of endpoint, identity, email, cloud and network telemetry, with triage, escalation and incident tracking against agreed SLAsDetection engineering and use case development across SIEM and EDREDR and XDR platform management, including policy tuning, sensor health and exclusionsIncident response, from initial triage and severity classification through containment recommendations to post-incident reviewVulnerability management, including asset-based scanning, risk-based prioritisation and remediation trackingThreat intelligence applied to detection and hunting, including threat actor tracking and attack surface monitoringReadiness assurance, including tabletop exercises, ransomware readiness and backup validationYou will not personally deliver all of this. You will be accountable for the standard to which it is delivered, and hands-on in the areas where senior judgement or senior technical skill is the constraint.KEY RESPONSIBILITIESService operations and qualityOwn the daily operation of the service: coverage, prioritisation, escalation paths and the operating rhythm of the analyst teamHold the written standard for triage, classification, evidence and closure, and review incident records before they reach the clientManage the shift and escalation model, including on-call arrangements and handover disciplineOwn the service metrics reported to clients and to the business, including time to acknowledge, time to contain and false positive rate, and act on what they showIncident managementAct as incident commander for significant incidents: direct the investigation, decide on containment, and control communication with the clientCoordinate response with client technical teams and, where relevant, with third-party providers and prime contractorsRun post-incident reviews and convert findings into changes to detection, procedure or client recommendationEnsure incident documentation meets the evidentiary standard expected by clients operating under NIS2, DORA or ISO 27001Detection, tuning and automationDirect the detection roadmap: coverage priorities mapped to MITRE ATT&CK, gap closure, and retirement of content that no longer contributesAuthor and review detection content and tuning changes yourself where the work requires senior judgementDrive automation of repetitive analyst work, enrichment and triage support, and hold alert quality as a measured outcome rather than an impressionOwn the technical relationship with the platforms the service runs on, including onboarding of new client telemetryTeam leadership and developmentLead the analyst team: workload allocation, technical mentoring, structured coaching and quality feedback against defined criteriaDevelop each analyst against a documented progression framework, and make an honest case at review timeBuild and maintain the operating procedures, playbooks and runbooks the team works from, and test them through exercisesContribute to hiring and onboarding of new analysts as the practice growsClient relationship and reportingLead periodic service reviews with client technical stakeholders, presenting posture, incidents and recommendationsTranslate technical findings into language a non-technical stakeholder can act onAdvise the commercial team on scope, feasibility and delivery risk where operational judgement is requiredESSENTIAL REQUIREMENTSAt least six years in security operations, incident response or a CSIRT function, including at least two years leading, coordinating or mentoring analystsDemonstrated ownership of incidents end to end: triage, investigation, containment decisions, client communication and post-incident reviewPractical command of at least one enterprise SIEM and one EDR platform, including triage at volume, tuning, and validation of detection content. Direct experience with Microsoft Sentinel and Defender, CrowdStrike etc...Hands-on detection engineering ability: you have authored production detection content and can explain its logic, data sources, tuning history and failure modesWorking knowledge of MITRE ATT&CK applied to coverage assessment, detection design and investigationPractical automation ability, whether through a SOAR platform or through scripting against platform APIs, with sufficient command of Python or PowerShell to build and maintain toolingThe ability to write clearly for a client audience: incident notifications, service reports and recommendations that a non-technical stakeholder can act onSound judgement on when to escalate, when to contain and when to hold, with the confidence to make the call and record the reasoningProfessional working proficiency in EnglishPREFERRED QUALIFICATIONSItalian language ability at professional working levelExperience delivering security operations as a service provider to external clients, rather than to a single internal estateExperience of vulnerability management or exposure management programmesThreat hunting, purple team or adversary simulation experienceCloud and identity detection experience across Microsoft 365, Entra ID or equivalent platformsFamiliarity with NIS2, DORA or ISO 27001 as they affect monitoring, incident reporting and evidence retentionA university degree and specific certifications are welcome but are not requirements. Demonstrated judgement and technical ability are assessed directly during selection.WHAT WE OFFERGenuine ownership of a service in its formative period: the standards, the procedures and the technical direction are set by the person in this roleThe service operates continuously against agreed client SLAs. This position is a business-hours role carrying senior escalation duty; it does not involve rotating night shifts, and any out-of-hours arrangement is set out explicitly at offer stageSponsored professional certifications aligned to a defined progression pathDirect client responsibility and decision authority significantly earlier than is typical in a larger organisationProfessional equipment of your choice