Job Summary :
We are seeking an experienced and strategic Senior IT Manager SOC / IT Audit to lead and oversee our enterprise-level Security Operations Center and internal IT audit functions. This role combines technical security leadership, audit and compliance oversight, and cross-functional collaboration to ensure the organization's security posture and regulatory compliance. You will be responsible for threat detection and response, internal security audits, risk assessment, and supporting compliance with industry standards such as ISO 27001, NIST, SOC 2, PCI-DSS, or HIPAA.
Key Responsibilities :
- Lead 24x7 SOC operations, including real-time threat monitoring, incident detection, response, and escalation.
- Manage and enhance security tools such as SIEM, SOAR, IDS / IPS, EDR, and threat intelligence platforms.
- Establish threat detection use cases, analytics, and dashboards for visibility into the security landscape.
- Coordinate with IT, application, and infrastructure teams during major security incidents and forensic investigations.
- Maintain runbooks and playbooks to standardize security event responses.
- Lead internal IT audits to assess compliance with security policies, frameworks (ISO, NIST, SOC 2), and regulatory requirements.
- Develop audit strategies and execute audit plans for infrastructure, applications, networks, and cloud environments.
- Prepare reports and presentations for senior management, audit committees, and external regulators.
- Work with external auditors and regulatory bodies during formal audit assessments and ensure successful closure of findings.
- Develop and maintain the enterprise IT risk register and support risk mitigation planning.
- Conduct vulnerability assessments and ensure regular penetration testing and remediation follow-ups.
- Drive policy creation and enforcement around access control, data protection, change management, and system hardening.
- Ensure governance around third-party risk, vendor assessments, and security due diligence.
- Lead and mentor a team of SOC analysts, security engineers, and audit professionals.
- Develop KPIs and operational metrics to continuously evaluate team performance and process effectiveness.
- Collaborate with CISO and IT leadership to align security initiatives with business objectives.
- Stay current with emerging cyber threats, tools, and trends to evolve the organizations defense strategy.
Required Qualifications :
Bachelors or Masters degree in Information Security, Computer Science, or a related field.10+ years of experience in IT security, including at least 5 years in a leadership role.Proven experience managing a SOC environment and / or conducting IT audits.Strong understanding of network and system security, incident response, and cybersecurity frameworks.Hands-on experience with SIEM platforms (e.g., Splunk, IBM QRadar, Sentinel), EDR, and security analytics tools.Familiarity with compliance and audit frameworks : ISO 27001, SOC 2, NIST CSF, PCI-DSS, HIPAA, etc.Certifications such as CISSP, CISA, CISM, CEH, or GIAC are highly preferred.ref : hirist.tech)