MSS Operations Lead

Cyberani
Riyadh
Workplace: OnsiteFull timeFunction: Business OperationsExperience: 6+ yearsEducation: bachelorsSkills: ["Problem-solving","Analytical thinking","Communication","Stakeholder management","Leadership"]

Lead day-to-day SOC/MSS operations to ensure service quality and SLA adherence across clients. Serve as L3 technical oversight for complex incidents—triaging, investigating, containing, remediating, and driving recovery—while coordinating incident bridges with Incident Response, Threat Intelligence, and Engineering. Oversee shift scheduling and analyst coaching, maintain SOC playbooks/escalation matrices, report KPIs/SLAs/SLOs, review RCAs and deliverables, and support onboarding and detection-quality improvements.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cyberani
Cyberani
4 months ago

MSS Operations Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Lead day-to-day SOC/MSS operations to ensure service quality and SLA adherence across clients. Serve as L3 technical oversight for complex incidents—triaging, investigating, containing, remediating, and driving recovery—while coordinating incident bridges with Incident Response, Threat Intelligence, and Engineering. Oversee shift scheduling and analyst coaching, maintain SOC playbooks/escalation matrices, report KPIs/SLAs/SLOs, review RCAs and deliverables, and support onboarding and detection-quality improvements.
Location: Riyadh
Workplace: Onsite
Employment Type: Full time
Job Function: Business Operations
Seniority: Manager level

Key Responsibilities

  • •Lead day-to-day SOC operations to ensure service quality and SLA adherence across clients.
  • •Provide L3 technical oversight for complex security incidents, including triage, investigation, containment, eradication, and recovery, with timely escalation.
  • •Coordinate major incident management activities with Incident Response, Threat Intelligence, and Engineering; lead incident bridges and stakeholder communications.
  • •Oversee shift operations, analyst scheduling, and workload prioritization; coach and mentor analysts to improve performance and investigation quality.
  • •Define, maintain, and continuously improve SOC operational processes, escalation matrices, and playbooks/runbooks; review incident reports/RCAs and support service reviews and onboarding.

Key Requirements

  • •Bachelor’s degree in computer science or a related field with professional certification.
  • •6+ years proven experience in security operations.
  • •Senior SOC experience leading advanced incident triage, investigation, containment, and remediation across multiple clients/environments.
  • •Hands-on capability with SIEM/SOAR, EDR/NDR, vulnerability management, and threat intelligence for root-cause analysis and detection tuning.
  • •Strong communication, analytical problem-solving, and L3 incident handling decision-making under pressure; able to mentor analysts and govern processes.
Experience:6+ yearsSOCSecurity operationsSIEM/SOARIncident responseManaged security services
Education:Bachelor's
Skills:Problem-solvingAnalytical thinkingCommunicationStakeholder managementLeadership
Certifications:Professional certification
Languages:English
Tech Stack:SIEMSOAREDRNDRVulnerability managementThreat intelligenceKPISLASLOPlaybooksRunbooksIncident reportsRCAs

Eligibility

Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Cyberani
Saudi cybersecurity company providing managed security services, threat detection, incident response, and security consulting for organizations. It focuses on protecting critical digital infrastructure and helping enterprises strengthen resilience against cyber threats.
Industry: Cybersecurity
Headquarters: Riyadh, Saudi Arabia
WebsiteLinkedIn