SOC Manager
- Bucharest
- IT Management
- ICON Full Service & Corporate Support
- Office Based
About the role
This vacancy has now expired. Please click here to view live vacancies.
ICON plc is a world-leading healthcare intelligence and clinical research organisation. From molecule to medicine, we advance clinical research providing outsourced services to pharmaceutical, biotechnology, medical device and government and public health organisations.
With our patients at the centre of all that we do, we help to accelerate the development of drugs and devices that save lives and improve quality of life.
Our people are our greatest strength, are at the core of our culture, and the driving force behind our success. ICON people have a mission to succeed and a passion that ensures what we do, we do well.
The Role
ICON is seeking to hire a SOC Manager to join their Cyber Security Operations Center (SOC) team.
The team are proud winners of a recent CSO50 award for the PRA Integration project. The CSO50 Awards recognize 50 security projects and initiatives that demonstrate outstanding business value and thought leadership. We give all our staff SANS training every year and are fully supportive of enabling our team members to get to security conferences.
The SOC Manager plays a vital role in managing the SOC program and processes to quickly detect, respond and resolve security threats and incidents.
Key Responsibilities
Reporting to the Director of Cyber Resilience, the successful SOC Manager is responsible for the following:
Enhances and maintains the SOC program and executes initiatives to protect, detect and respond to security threats and incidents.
Responsible for a team of SOC analysts who continuously perform monitoring and triage of alerts and execute incident response playbooks.
Oversee activities of service providers to deliver effective and efficient SOC operations while ensuring fulfilment of SLAs
Review and enhance policies, procedures and playbooks to ensure adequate detection, prevention and incident response levels.
Review and continuously enhance SOAR playbooks.
Leads cyber security incident investigations and acts as Lead Incident Investigator / Manager
Work with vendors or consultants as appropriate for services or implementation of new technologies or enhancement of existing capabilities
Work with Security Engineering function to address SOC identified control gaps or solution enhancements
Collaborate with the Cyber Threat Intel and Red Team functions to identify priority detection and prevention enhancement across the control and security solutions environment
Work with Cyber & Information Security management to continue to mature the SOC
Plan and execute regular incident response and tabletop exercises.
Develop and maintain objectives, trend analysis, metrics and KPIs supporting the department’s strategic direction and continuously improve SOC capabilities
Advise management on cybersecurity tool selection to satisfy SOC functions and to address security gaps
Skills & Experience
The successful candidate will have experience of operating in a technically complex, fast changing and dynamic environment.
The ideal candidate will have a genuine passion for Cybersecurity, must have the ability to maintain composure under pressure and work calmly during an emergency.
Solid grasp of common cyber frameworks and models such as NIST, the MITRE ATT&CK, D3FEND, Cyber Kill Chain and modern penetration testing techniques
Solid understanding of incident response processes, workflows, communications and reporting, analytical issues and cross-department collaboration
Experience working in a security operations center, red team or blue team operations and ability to think both like an attacker and defender
Strong leadership and communication skills with senior management
Excellent organizational skills with ability to handle multiple high visibility issues simultaneously
Familiarity of the cyber threat landscape including threat actors, tactics, tools and procedures, and effective countermeasures. Additionally, knowledge of common techniques used by malware and threat actors
Deep technical understanding of SIEM, SOAR, EDR, NDR, firewalls, IDPS, WAF, load balancing, network, web and email security tools with a variety of enterprise IT and cloud-based architectures and technologies, such as networking, server infrastructure, operating systems, web applications, databases and containerization.
Be a self-starter, work independently and able to quickly adjust to changing priorities
Strong verbal and written communication skills with ability to analyse, summarize, and communicate large volumes of information in a clear and succinct manner with careful attention to detail
Qualifications & Experience:
5+ years of technical security experience, with 3+ years of experience leading a cyber incident response or security operations team within a large enterprise organization
Bachelor’s degree in information security, computer science, or other related program
Information security related certification desired (e.g., GCIA, GCIH, GSFA, GSOC, GSOM or similar professional certifications)
Benefits of Working in ICON:
Our success depends on the quality of our people. That’s why we’ve made it a priority to build a culture that rewards high performance and nurtures talent.
We offer very competitive salary packages. And to keep them competitive, we regularly benchmark them against our competitors. Our annual bonuses reflect delivery of performance goals – both ours and yours.
We also provide a range of health-related benefits to employees and their families and offer competitive retirement plans – and related benefits such as life assurance – so you can save and plan with confidence for the years ahead.
But beyond the competitive salaries and comprehensive benefits, you’ll benefit from an environment where you are encouraged to fulfil your sense of purpose and drive lasting change.
ICON is an equal opportunity and inclusive employer and is committed to providing a workplace free of discrimination and harassment. All qualified applicants will receive equal consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.
If, because of a medical condition or disability, you need a reasonable accommodation for any part of the application process, or in order to perform the essential functions of a position, please let us know through the form below.
Impactful work. Meaningful careers. Quality rewards.
At ICON, our employees are our greatest strength. That’s why we are committed to empowering you to live your best life, both inside and outside of work. Whether your ambition is lead a global team, become a deep scientific or technical expert, work in-house with our customers or gain experience in a variety of different ICON functions, we will support you in realising your full potential. See all locations Learn more about Our Culture at ICON
Day in the life
.jpg)
Teaser label
Inside ICONContent type
BlogsPublish date
01/17/2025
Summary
Five Reasons Why You Should Work at a Contract Research Organization Contract research organisations (CROs) play a pivotal role in advancing medical science, offering career opportunities that are
.jpg)
Teaser label
Career ProgressionContent type
BlogsPublish date
05/10/2024
Summary
Although many employers are returning to the office, we’re still seeing a mix of both video and in-person interviews in application processes. Early in 2020, the number of companies using video interv
.png)
Teaser label
Career ProgressionContent type
BlogsPublish date
12/21/2022
Summary
Salary expectations used to be something discussed after an interview process but now it’s something most recruiters typically ask within the first conversation. This is to ascertain if the remune
Similar jobs at ICON
We are sorry but your search has returned no results.
Please try some of the links below to find what you are looking for: