en
zh
MAKING SUCCESS STORIES HAPPEN
 

 

About the Company

Our client is an international fintech company providing technology-driven financial services to customers across multiple markets. With a strong focus on innovation, security, reliability, and regulatory compliance, the company continues to invest in strengthening its cybersecurity capabilities and building a mature, scalable security operations function.

As the business expands globally, the company is looking for an experienced SOC Team Lead to enhance its security monitoring, incident response, detection engineering, and operational resilience.

About the Role

As the SOC Team Lead, you will lead and develop a team of security analysts and engineers while overseeing the day-to-day operations of the Security Operations Center.

You will be responsible for strengthening incident response capabilities, improving SOC processes, and shaping the strategic direction of security operations, detection capabilities, and security tooling. You will act as the primary escalation point for complex and high-impact security incidents, coordinating cross-functional response efforts and ensuring incidents are contained, investigated, remediated, and resolved effectively.

This role requires strong hands-on experience in security operations, incident response, and cybersecurity technologies, combined with proven leadership and team development capabilities. The ideal candidate should be able to analyze complex threats, make sound decisions under pressure, and clearly communicate risks and recommendations to both technical and non-technical stakeholders.

Key Responsibilities

Team Leadership and Development

  • Lead, mentor, and develop a team of SOC analysts and security engineers.
  • Conduct performance evaluations, identify capability and skill gaps, and establish individual development plans.
  • Promote continuous learning, knowledge sharing, and professional growth across the team.
  • Support recruitment, onboarding, resource planning, and team capability development.

Incident Response and Crisis Management

  • Oversee the end-to-end security incident response lifecycle, including identification, triage, containment, investigation, remediation, recovery, and post-incident review.
  • Act as the primary decision-maker and coordinator during high-severity security incidents.
  • Coordinate incident response activities across security, infrastructure, engineering, legal, compliance, and business teams.
  • Lead root-cause analysis and ensure corrective and preventive actions are properly implemented.

SOC Operations Management

  • Manage daily SOC operations to ensure effective monitoring, alert triage, investigation, escalation, and resolution.
  • Ensure compliance with operational SLAs, incident response targets, and internal security standards.
  • Oversee case prioritization, backlog management, workload allocation, and escalation procedures.
  • Monitor operational performance through metrics such as alert volume, detection accuracy, MTTD, MTTR, false-positive rates, and incident trends.

Process Improvement and Governance

  • Lead the design, review, documentation, and continuous improvement of SOC operating procedures.
  • Develop and maintain incident response playbooks, escalation processes, investigation guidelines, and security monitoring standards.
  • Ensure SOC processes are scalable, measurable, and aligned with industry best practices.
  • Support internal audits, regulatory reviews, risk assessments, and security compliance initiatives.

Security Tooling and Automation

  • Lead the evaluation, proof of concept, implementation, integration, and optimization of security technologies.
  • Manage and improve platforms such as SIEM, SOAR, EDR, XDR, NDR, cloud security, threat intelligence, and vulnerability management solutions.
  • Drive automation initiatives to improve alert enrichment, investigation, containment, and response efficiency.
  • Work with internal stakeholders and external vendors to ensure security tools remain reliable, effective, and aligned with operational requirements.

Detection Engineering and Use Case Management

  • Oversee the development, testing, tuning, and continuous optimization of security detection rules and use cases.
  • Improve detection coverage across endpoint, network, cloud, application, identity, and infrastructure environments.
  • Reduce false positives, duplicate alerts, and unnecessary alert fatigue.
  • Ensure detection capabilities are aligned with evolving threats, business risks, and the organization’s technology environment.

Threat Intelligence and Threat Hunting

  • Lead threat intelligence analysis and proactive threat-hunting activities.
  • Identify emerging threats, suspicious behavior, attack patterns, and potential security weaknesses before they escalate.
  • Translate threat intelligence into actionable detection rules, hunting hypotheses, and mitigation recommendations.
  • Encourage a proactive and intelligence-driven approach to security operations.

Stakeholder Communication and Reporting

  • Communicate SOC performance, incident trends, risk exposure, and the organization’s overall security posture to management and relevant stakeholders.
  • Translate complex technical findings into clear business risks, priorities, and actionable recommendations.
  • Prepare regular reports, dashboards, and incident briefings for technical and non-technical audiences.
  • Build effective working relationships with technology, compliance, risk, legal, audit, and business teams.

Requirements

  • Bachelor’s degree in Information Security, Computer Science, Information Technology, Engineering, or a related discipline.
  • Significant experience in cybersecurity, security operations, incident response, or SOC environments.
  • Proven experience leading or mentoring security analysts, engineers, or incident response professionals.
  • Strong hands-on experience with SIEM, SOAR, EDR, XDR, threat intelligence, log analysis, and security monitoring technologies.
  • Solid understanding of incident response methodologies, threat detection, investigation techniques, and attack lifecycle frameworks.
  • Experience developing SOC procedures, incident response playbooks, detection use cases, and escalation mechanisms.
  • Strong knowledge of network, endpoint, identity, application, and cloud security concepts.
  • Demonstrated ability to manage complex incidents and make decisions in high-pressure situations.
  • Strong analytical, problem-solving, stakeholder management, and communication skills.
  • Ability to communicate effectively in English with regional or global stakeholders.

Preferred Qualifications

  • Experience working within fintech, financial services, digital payments, banking, cryptocurrency, or another highly regulated industry.
  • Experience supporting a regional or global SOC environment.
  • Familiarity with cloud platforms such as AWS, Azure, or Google Cloud.
  • Knowledge of security frameworks and standards such as NIST, MITRE ATT&CK, ISO 27001, PCI DSS, or related regulatory requirements.
  • Experience with security automation, scripting, detection engineering, or threat-hunting methodologies.
  • Relevant professional certifications such as CISSP, CISM, GIAC, CEH, or equivalent credentials.
  • Experience managing security vendors, managed security service providers, or technology implementation projects.

 

Apply for Global Fintech Company: SOC Manager
Reference: GC878132

Please complete all required fields marked *

*

*

*

*

*

MS Word, PDF, HTML and Txt formats.

Issues applying with LinkedIn? Click here

*
Your personal details, submitted whilst completing this form, will be treated conform our Privacy Notice and Terms & Conditions .
I accept the Morgan Philips Privacy Notice and Terms & Conditions.

Global Fintech Company: SOC Manager
Taipei, Northern Taiwan | Permanent
}