SOC Manager
About the Role
The SOC Manager is responsible for leading and managing the Security Operations Center within a Managed Security Service Provider (MSSP) environment. This role ensures the delivery of high quality, 24/7 security monitoring, detection, and incident response services to multiple customers while meeting contractual SLAs, maintaining service excellence, and continuously improving SOC operational maturity.
Key Responsibilities
1. SOC Operations Management
- Manage day‑to‑day SOC operations across multiple customer environments in a 24/7/365 MSSP model.
- Ensure consistent delivery of SOC services aligned with customer contracts, SLAs, and KPIs.
- Develop, maintain, and enforce SOC processes, SOPs, escalation paths, and playbooks.
- Oversee shift scheduling, workload distribution, and operational coverage.
2. Customer & Service Delivery Management
- Act as the primary escalation point for customer security incidents and service issues.
- Support customer onboarding activities, including use-case development, log source integration, and runbook definition.
- Participate in customer meetings, service reviews, and incident briefings.
- Ensure clear, timely, and professional communication with customers during incidents.
3. Incident Response & Threat Management
- Lead and coordinate response to high‑severity security incidents across customer environments.
- Ensure effective triage, investigation, containment, eradication, and recovery activities.
- Oversee threat intelligence integration and proactive threat hunting initiatives.
- Conduct incident post‑incident reviews and continuous improvement activities.
4. SOC Tools & Technology
- Manage and optimize multi‑tenant SOC platforms including SIEM, SOAR, EDR/XDR, NDR, and threat intelligence tools.
- Ensure alert tuning, use-case optimization, and reduction of false positives.
- Evaluate and recommend new tools or enhancements to improve service efficiency and detection capabilities.
5. Team Leadership & Development
- Lead, mentor, and develop SOC analysts and incident responders.
- Conduct performance reviews, skills assessments, and training plans.
- Foster a strong security culture, operational discipline, and customer‑focused mindset.
6. Reporting, Governance & Compliance
- Produce operational and executive‑level SOC reports for internal management and customers.
- Track service metrics such as MTTA, MTTR, alert volumes, and incident trends.
- Support compliance requirements and audits relevant to MSSP services (e.g., ISO 27001, NIST, SOC 2).
- Contribute to SOC maturity
roadmap and service innovation initiatives.
- Education: A bachelor’s degree in computer science, or Information Technology is the standard benchmark.
- Professional Certifications (Preferred)
- CompTIA CySA+ (Cybersecurity Analyst) or EC-Council ECIH (Certified Incident Handler).
- OSCP (Offensive Security Certified Professional).
- CISSP, CISM, or CISA
- GIAC certifications (GCIH, GCED, GCIA)
- CEH, Security+
- SIEM
platform certifications (Splunk, Elastic, QRadar, etc.)
- Work Experience
- Minimum 4–5 years of experience in cybersecurity or information security operations.
- High priority for candidates working experience 2-3 years in a SOC leadership or management role, preferably within an MSSP environment.
- Experience managing multi‑customer SOC
operations and SLA‑based service delivery is high priority
Personal Attributes
1. Soft Skills
- Communication skill, remaining calm and articulate during a high-pressure breach where a client’s business may be offline.
- The ability to review Tier 1 and Tier 2 escalations and provide "teaching moments" to reduce future false positives.
- The ability to ask the right question, rather than just following a checklist.
- Understanding that in a managed service, an alert must be acknowledged within a specific timeframe.
- A detective’s curiosity mindset, the refusal to close a ticket until they truly understand how an event happened.
- Strong people management and team leadership skills.
- Proven incident leadership and crisis management skills.
- Analytical, detail‑oriented, and able to work under pressure.
2. Technical Skills
- Mastery of query languages (e.g., KQL for Sentinel, SPL for Splunk, ESQL for Elastic) to build custom hunts and correlation rules.
- Strong expertise in SOC operations, incident response, and threat detection.
- Hands‑on knowledge of SIEM, SOAR, EDR/XDR, IDS/IPS, firewalls, and threat intelligence platforms.
- Solid understanding of:
- Network and endpoint security
- Cloud security environments (AWS, Azure, GCP)
- Malware analysis and attacker techniques
- MITRE ATT&CK framework
- Ability to analyze complex security events across diverse customer environments.
- Strong understanding of SLA‑driven service delivery and customer expectations.
- Experience managing multi‑tenant security platforms.
- Ability to balance operational efficiency with high service quality.
- Monday to Half-Saturday: 8:00 a.m. – 12:00 p.m. & 1:00 p.m. – 5:00 p.m.
- Lunch Break: 12:00 p.m. – 1:00 p.m.
Why Join First Cambodia
At First Cambodia, we believe that our people are our greatest asset. You’ll join a team of professionals who are shaping Cambodia’s digital future through innovation and world-class technology solutions.
Benefits & Perks:
- Attractive & Competitive Salary — aligned with your experience and performance.
- Profit-Sharing Bonus — rewarding dedication and contribution to company success.
- Seniority Pay — 15 days per year, in line with Cambodian labor law.
- Annual Salary Review — recognizing performance and commitment.
- Insurance Coverage (NSSF) — ensuring health, social, and retirement protection.
- Generous Leave Policy — 18 days of annual leave plus public holidays.
- Paid Maternity Leave — 90 days with 100% pay.
- Financial Assistance — for marriage, childbirth, and bereavement.
- Healthy Work–Life Balance — supportive environment that values family, flexibility, and wellbeing.
- Continuous Learning Opportunities — through training, workshops, and certification programs.
- Annual Company Retreat & Team-Building Trips — to celebrate success and strengthen teamwork.
- Positive & Supportive Culture — collaborative, inclusive, and purpose-driven.
How to Apply
Interested candidates are invited to submit the following documents:
- Updated resume (CV) with a brief cover letter and university transcript/GPA
Links to your professional profiles (e.g., LinkedIn and/or Facebook)
📧 Email: [email protected]
💬 Telegram: https://t.me/sreypich_sam
📞 Contact: (+855) 23 961 222 / 011 545 084
✅ Join us and be part of Cambodia’s leading IT transformation journey!
NOTE: Only shortlisted candidates will be contacted.