Stop applying to jobs that are already dead.
Every listing verified, aged honestly, expired when filled.

All listings

JustMarkets via Greenhouse

Head of Security Operations Center (Head of SOC)

head Europe
still open verified 1d ago posted 67d ago checked 2h ago
Apply at job-boards.eu.greenhouse.io

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 67d ago

The date the source published, not the day we noticed it (2026-07-09). Last seen at its source 2h ago.

Is it remote?

Remote, Europe

That is the location the employer filed this posting under. Quoted as written — we do not re-word the source's own location.

Who may apply?

Europe

The description states no restriction of its own. This is the source's own tag.

Pay not stated

Similar roles pay £74k–98.8k/yr

Middle 50% of 12 listings that do state pay — Operations · all levels · Europe · GBP/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.

Skills named in the ad

AWSAzureCross-functional CollaborationGCPIncident ManagementKnowledge BaseMentoringOnboardingSIEMSSOSplunkStakeholder ManagementTeam ManagementThreat Modeling

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

We are looking for a Head of Security Operations Center (Head of SOC) to lead, mature, and operate our resilient security operations capability. In this role, you will own the defense of our environment, ensuring fast and precise threat detection, investigation, containment, and exposure reduction. You will lead our security operations function, making the organization faster in responding to threats while continuously improving controls across the attack surface.
 
Responsibilities
  • Own Cyber Defense execution across SOC, detection engineering, incident response, and exposure remediation
  • Lead alert triage quality, escalation standards, incident command, and response coordination
  • Prioritize critical vulnerabilities and exposures using asset criticality, exploitability, and business impact
  • Manage Cyber Defense dashboards, runbooks, remediation follow-up, and operational metrics
  • Coordinate with IT, Platform, Product, GRC, Legal, and business owners during incidents and remediation
  • Build and develop the Cyber Defense team, including hiring, onboarding, mentoring, and retaining security talent
  • Drive continuous improvement of detection coverage, response playbooks, and security controls based on lessons learned and threat intelligence
  • Report on Cyber Defense performance, incidents, and risk posture to security leadership and stakeholders
Requirements
  • 10+ years of experience in Information Security
  • 3+ years in a security management or team lead role with direct people management experience
  • Hands-on experience managing SOC operations, leading incident command, and driving MTTD/MTTR improvement
  • Ability to design, validate, and maintain detection logic across SIEM, EDR, and cloud platforms, with a deep understanding of runbook development and false-positive reduction
  • Knowledge of top attack scenarios (ATO, credential theft, privilege escalation, data exfiltration) and ability to map detections to threat models like MITRE ATT&CK
  • Experience prioritizing vulnerabilities using CVSS and asset criticality to reduce exposure aging
  • Hands-on experience with at least one enterprise SIEM (Splunk, Microsoft Sentinel, Chronicle, Elastic) and SOAR tooling
  • Understanding of cloud-native security controls and monitoring in AWS, GCP, or Azure
  • Understanding of IAM, PAM, SSO, and identity-related attack vectors relevant to detection and response
  • Ability to define, track, and communicate security KPIs and operational dashboards to technical and executive audiences
  • English - Upper-Intermediate or higher
  • Ukrainian - Fluent 

Will be a plus

  • Experience in fintech, e-commerce, or other high-risk industries with complex threat landscapes
  • Hands-on background as a SOC analyst, incident responder, or detection engineer prior to moving into management
  • Experience building a SOC or Cyber Defense function from scratch or significantly maturing an existing one
  • Familiarity with threat intelligence platforms and threat-informed defense methodologies
  • Relevant certifications: CISSP, CISM, GIAC (GSOM, GCED, GCIH) or equivalent

We offer

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays as per the company’s approved Public holiday list
  • Medical budget
  • Opportunity to work remotely
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear and related expenses)

Role mission

Lead and mature the company's Cyber Defense function to ensure the environment is protected through effective detection, investigation, containment and exposure reduction. The role exists to build and operate a resilient security operations capability — making the organization faster and more precise in responding to threats, while continuously improving controls and reducing exposure across the attack surface.

Requirements hard skills

1. Security Operations & Incident Response: hands-on experience managing SOC operations, leading incident command, and driving MTTD/MTTC/MTTR improvement.
2. Detection Engineering: ability to design, validate and maintain detection logic across SIEM, EDR and cloud security platforms; deep understanding of alert triage, runbook development and false-positive reduction.
3. Threat Intelligence & Threat Modeling: knowledge of top attack scenarios (ATO, credential theft, privilege escalation, data exfiltration, cloud key compromise) and ability to map detections to threat models (MITRE ATT&CK).
4. Vulnerability & Exposure Management: experience prioritizing vulnerabilities using CVSS, asset criticality, exploitability and business impact; track record of reducing exposure aging.
5. SIEM/SOAR Platforms: hands-on experience with at least one enterprise SIEM (Splunk, Microsoft Sentinel, Chronicle, Elastic) and SOAR tooling.
6. Cloud Security: understanding of cloud-native security controls and monitoring in AWS, GCP or Azure; experience with cloud-specific threat scenarios.
7. Identity & Access Security: understanding of IAM, PAM, SSO and identity-related attack vectors relevant to detection and response.
8. Security Metrics & Reporting: ability to define, track and communicate security KPIs and operational dashboards to technical and executive audiences.
9. At least 3 years in a security management or team lead role with direct people management experience.

Requirements soft skills

1. Leadership & people management: ability to build, motivate and develop a security team; sets clear direction and fosters accountability.
2. Structured thinking under pressure: stays calm and decisive during active incidents; able to prioritize and coordinate across teams in high-stress situations.
3. Stakeholder management: communicates complex security topics clearly to non-technical audiences (C-level, Legal, Product, Business).
4. Cross-functional collaboration: works effectively with IT, Platform, IAM, Product, GRC and Legal; builds trust across organizational boundaries.
5. Ownership mindset: takes full accountability for outcomes; drives follow-through on commitments and continuously pushes for improvement.
6. Data-driven decision making: sets measurable goals, tracks progress against KPIs and uses metrics to drive operational decisions.
7. Adaptability: comfortable working in a fast-paced, evolving environment; able to balance operational firefighting with strategic process building.

Responsibilities

1. Own Cyber Defense execution across SOC, detection, incident response, containment and exposure remediation.
2. Lead alert triage quality, escalation standards, incident command and response coordination.
3. Prioritize critical vulnerabilities and exposures using asset criticality, exploitability and business impact.
4. Manage Cyber Defense dashboards, runbooks, remediation follow-up and operational metrics.
5. Coordinate with IT, Platform, IAM, Product, GRC, Legal and business owners during incidents and remediation.
6. Build and develop the Cyber Defense team: hire, onboard, mentor and retain security talent.
7. Drive continuous improvement of detection coverage, response playbooks and security controls based on lessons learned and threat intelligence.
8. Report on Cyber Defense performance, incidents and risk posture to security leadership and stakeholders.

Will be a plus

- Experience in fintech, e-commerce or other high-risk industries with complex threat landscapes.
- Hands-on background as a SOC analyst, incident responder or detection engineer prior to moving into management.
- Experience building a SOC or Cyber Defense function from scratch or significantly maturing an existing one.
- Familiarity with threat intelligence platforms and threat-informed defense methodologies.
- Relevant certifications: CISSP, CISM, GIAC (GSOM, GCED, GCIH) or equivalent is a plus.

Apply at job-boards.eu.greenhouse.io