Monroe Consulting Group Indonesia, an executive recruitment firm, is looking to fill the position of IT SOC & Managed Risk Manager for a prominent system integrator in Indonesia. The ideal candidates should possess extensive experience to lead the Security Operations Center and Managed Risk services in a managed security (MSSP) environment, ensuring 24/7 monitoring and incident response, while also overseeing vulnerability, risk, and compliance management for multiple enterprise clients.
Key Responsibilities:
- Lead daily SOC operations across multiple clients.
- Manage SOC teams (analysts, threat hunters, incident responders) to meet SLAs and service quality.
- Oversee incident handling, escalation, and post-incident reviews.
- Improve detection rules, playbooks, and security automation.
- Oversee vulnerability scanning, assessment, and remediation tracking.
- Deliver managed risk services such as risk scoring, reporting, patch advisory, and attack surface monitoring.
- Ensure risk deliverables meet client expectations and contractual SLAs.
- Combine incident data with vulnerability insights to give clients a clear risk picture.
- Serve as the main point of contact for SOC and risk services.
- Provide regular reports on security incidents, vulnerabilities, and risk posture.
- Lead client review meetings and quarterly business reviews (QBRs).
- Support sales and pre-sales activities to grow service offerings.
- Integrate threat intelligence into detection and risk workflows.
- Prioritize response by linking active threats to vulnerable assets.
- Track emerging threats, CVEs, and cybersecurity trends.
- Maintain SOC and risk documentation (SOPs, SLAs, runbooks).
- Ensure alignment with standards such as ISO, NIST, and CIS.
- Support internal and client audits.
- Drive continuous service and process improvements.
- Train and mentor SOC analysts and risk consultants.
- Manage certifications and skill development plans.
- Build a collaborative, proactive security culture.
Requirements
- Bachelor's or Master's degree in IT, Computer Science, or Information Security (preferred).
- 5-10 years of cybersecurity experience, including:
- 3+ years in SOC leadership
- 2+ years in risk or vulnerability management
- Experience managing multi-tenant environments (MSSP or large enterprise).
- Strong knowledge of SIEM, SOAR, EDR, vulnerability tools, and risk frameworks.
- Strong leadership, communication, and stakeholder management skills.
- Able to manage multiple clients and priorities effectively.
Preferred Certifications
- Security+: CEH, GCIH
- CISSP, CISM, or CRISC
- GIAC certifications (GCIA, GCFA, GRID)