SOC Manager

Accesa

Job details

  • REMOTE
  • FULL_TIME
  • Cluj-Napoca
  • ro
  • Verified 2026-10-02
  • Source: Accesa public SMARTRECRUITERS source

Original job description

Company Description

Accesa is a leading technology company headquartered in Cluj-Napoca, with offices in Oradea and 20 years of experience in turning business challenges into opportunities and growth.

A value-driven organisation, it has established itself as a partner of choice for major brands in Retail, Manufacturing, Finance, and Banking. It covers the complete digital evolution journey of its customers, from ideation and requirements setup to software development and managed services solutions.

With more than 1,200 IT professionals, Accesa also has a fast-growing footprint, establishing itself as an employer of choice for IT professionals who are passionate about problem-solving through technology. Coming together in strong tech teams with a customer-centric approach, they enable businesses to grow, delivering value for our clients, partners, industry, and community.

Job Description

Role Overview

The SOC Manager is responsible for the overall operational delivery, performance, and continuous improvement of Accesa’s Security Operations Center services.

The role combines operational leadership, people management, client interaction, service governance, and technical security oversight. The SOC Manager ensures that SOC services are delivered according to agreed SLAs, processes, and quality standards while continuously improving detection, response, automation, and operational efficiency.

The role oversees SOC Analysts and Security Engineers across L1/L2 activities and works closely with Security Engineering, Delivery Management, Cloud & Infrastructure teams, and client stakeholders.

Key Responsibilities

SOC Operations & Service Delivery

  • Lead and coordinate day-to-day SOC operations, including continuous security monitoring, alert triage, investigation, escalation, and incident response.
  • Ensure effective operation of 24/7 monitoring services and appropriate coverage across shifts and on-call arrangements.
  • Ensure incidents and security alerts are handled according to defined SLAs, escalation paths, and incident response procedures.
  • Oversee the handling of critical security incidents and act as an escalation point for complex or high-severity situations.
  • Ensure operational procedures, runbooks, escalation processes, and RACI models are documented, maintained, and followed.
  • Monitor service capacity, workload distribution, shift coverage, and operational bottlenecks.
  • Coordinate activities between SOC Analysts, Security Engineers, infrastructure teams, application teams, and client stakeholders.

Service Governance & Client Management

  • Own the operational performance of SOC services delivered to clients.
  • Monitor and report against agreed KPIs, SLAs, response times, incident volumes, detection effectiveness, and service quality.
  • Lead regular operational and service review meetings with clients.
  • Provide clear reporting on security incidents, trends, emerging threats, risks, and improvement measures.
  • Manage operational escalations and ensure timely communication during major security incidents.
  • Identify risks to service delivery and coordinate appropriate mitigation actions.
  • Support Delivery Management and commercial stakeholders in service planning, scope clarification, and managed service governance.

Detection, Incident Response & Security Operations

  • Ensure effective monitoring and detection capabilities across endpoint, identity, cloud, network, application, and infrastructure environments.
  • Support and oversee incident investigation, containment, remediation, and post-incident activities.
  • Ensure proper escalation from L1 monitoring to L2/L3 Security Engineering or specialized technical teams.
  • Drive improvements in detection quality, alert prioritization, false-positive reduction, and security use cases.
  • Support threat hunting, threat intelligence, and security investigation activities.
  • Ensure lessons learned from incidents are translated into improvements to detections, processes, and response procedures.

Security Platforms & Engineering Oversight

  • Coordinate the operational use and continuous improvement of SIEM, EDR/XDR, and SOAR technologies.
  • Work closely with Security Engineers responsible for detection engineering, platform engineering, integrations, and automation.
  • Support the onboarding of new log sources, applications, infrastructure, and customers into the SOC.
  • Drive automation of repetitive SOC activities using SOAR playbooks and security tooling.
  • Ensure monitoring platforms remain operational, properly configured, and aligned with service requirements.

People Leadership

  • Lead, mentor, and develop SOC Analysts and Security Engineers.
  • Define responsibilities and expectations across L1, L2, and engineering functions.
  • Support recruitment, onboarding, training, and career development within the SOC.
  • Establish and maintain structured training and development paths for SOC team members.
  • Ensure knowledge sharing and appropriate technical coverage within the team.
  • Monitor team performance, workload, and operational effectiveness.
  • Foster collaboration between SOC Operations, Security Engineering, Cloud & Infrastructure, and other delivery teams.

Service Development & Continuous Improvement

  • Continuously improve SOC processes, operating models, tooling, automation, and service quality.
  • Identify opportunities to increase SOC efficiency and reduce manual operational effort.
  • Support the development and standardization of Accesa’s Managed Security Services portfolio.
  • Contribute to service definitions, operating models, SLAs, KPIs, staffing models, and delivery processes.
  • Support transition and onboarding of new SOC customers into operational service.
  • Participate in discovery and transition activities for new security services.
  • Contribute to proposals, RFPs, solution design, and customer workshops related to Security Operations.
Qualifications

Required Experience & Skills

  • Strong professional experience in Cyber Security / Security Operations.
  • Previous experience in a SOC environment, ideally progressing through SOC Analyst, Senior Analyst, Incident Response, Security Engineering, or SOC Lead roles.
  • Experience coordinating or managing operational security teams.
  • Good understanding of:
    • Security monitoring and alert triage
    • Incident response and escalation
    • SIEM and detection engineering
    • EDR/XDR technologies
    • SOAR and security automation
    • Threat intelligence and threat hunting
    • Cloud security
    • Identity and endpoint security
    • Network and infrastructure security
  • Experience working with operational SLAs, KPIs, service reporting, and managed services.
  • Understanding of major security frameworks and concepts such as:
    • MITRE ATT&CK
    • NIST Cybersecurity Framework
    • Incident Response frameworks
    • ISO 27001
  • Strong analytical, organizational, and decision-making skills.
  • Ability to manage operational priorities in high-pressure security situations.
  • Strong stakeholder and client communication skills.
  • Fluent English; German is considered a strong advantage.

 

Nice to Have

  • Experience building or scaling a SOC or Managed Security Service.
  • Experience operating 24/7 security services.
  • Experience with Microsoft Sentinel and Defender XDR.
  • Experience with Palo Alto XSOAR/XSIAM.
  • Experience with detection engineering and security automation.
  • Scripting knowledge in Python or PowerShell.
  • Experience with cloud environments such as Microsoft Azure, AWS, or GCP.
  • Experience supporting RFPs, service transitions, and managed service onboarding.
  • Relevant certifications such as CISSP, CISM, GIAC, Microsoft Security certifications, or equivalent.
Additional Information

As a people-first organisation, we believe diversity strengthens our teams and drives innovation. All employment decisions are based on merit, skills, and performance, without discriminating based on any personal characteristic. This reinforces our commitment to providing an inclusive and respectful workplace.

At Accesa you can:

Enjoy our holistic benefits program that covers the four pillars that we believe come together to support our wellbeing, covering social, physical, emotional wellbeing, as well as work-life fusion.

  • Physical Wellbeing: Our wellbeing program includes medical benefits, gym support, and personalised fitness options for an active lifestyle, complemented by team events and the Healthy Habits Club.
  • Work-Life Fusion: In very dynamic industries such as IT, the line between our professional and personal lives can quickly become blurred. Having a one-size-fits-one approach gives us the flexibility to define the work-life dynamic that works for us.
  • Emotional Wellbeing: We believe that to maintain our overall health, we need to invest in our mental wellbeing just as much as we do in our physical health, social connections or in achieving work-life balance.
  • Social Wellbeing: As a growing community in a hybrid environment, we want to ensure we remain connected not just by the great work we do every day but through our passions and interests.

Related jobs

Apply at company