SOC Lead
by Adecco in Cybersecurity
The SOC Lead (Senior Security Consultant L2–L3) is a cybersecurity operations leadership role within a Managed Security Services Provider (MSSP) environment focused on advanced Security Operations Center (SOC) functions, XDR, MDR, SIEM, EDR, and multi-platform threat detection ecosystems. The role requires 7–9 years of cybersecurity experience with at least 6+ years in SOC operations, performing L2–L3 escalation handling, deep-dive threat investigations, and end-to-end incident response including triage, containment, eradication, recovery, and root cause analysis (RCA). The position involves working with modern security platforms such as Taegis, CrowdStrike Falcon, CrowdStrike NG SIEM (LogScale), Rapid7 IDR, Microsoft Defender XDR, Palo Alto Cortex XDR, QRadar, Splunk, and other SIEM/XDR tools to perform advanced correlation across endpoint, network, identity, cloud, and email security domains. The role includes SOC process development responsibilities such as creating and refining SOPs, runbooks, playbooks, escalation workflows, and detection standardization frameworks aligned with MSSP SLAs and KPIs. It also requires leadership in SOC operations management including shift oversight, queue management, quality assurance, analyst mentoring, and training L1/L2 staff on threat hunting and detection engineering. The SOC Lead is responsible for proactive threat hunting using XDR, SIEM, EDR, and threat intelligence sources, as well as developing and tuning detection rules and correlation logic to improve accuracy and reduce false positives. Additionally, the role includes customer-facing responsibilities such as incident reporting, service review meetings, dashboard presentation, onboarding support, and monthly/quarterly security reporting. The candidate also supports MSSP presales activities including solution design, customer workshops, BoQ preparation, SOW drafting, and SOC service architecture. The role requires strong expertise in cybersecurity frameworks such as MITRE ATT&CK, NIST CSF, ISO 27035, and Cyber Kill Chain, with the ability to handle complex security incidents such as ransomware, insider threats, account compromise, lateral movement, and phishing-based attacks while ensuring high-quality SOC service delivery in a fast-paced MSSP environment.