The Subject Matter Expert – Security Operations Center (SOC) oversees advanced security monitoring and incident management activities within the Cyber Security function. This role serves as the primary escalation point for complex or high-severity security incidents, providing technical leadership and validation before handover to Incident Response teams.
The SME leads deep-dive investigations using SIEM, IDS/IPS, firewalls, endpoint detection, and network telemetry, and applies frameworks such as MITRE ATT&CK and DEFEND to strengthen threat-hunting and detection coverage. The role is responsible for designing, tuning, and validating detection rules, developing and maintaining SOC playbooks and runbooks, and ensuring effective monitoring across hybrid infrastructures (on-prem, cloud, and telco cloud).
In addition, the SME mentors SOC engineers, conducts trainings and technical workshops, drives automation opportunities (SOAR playbooks and workflows), and contributes to continuous improvement of SOC processes and content. The role also monitors threat intelligence, tracks emerging threats and vulnerabilities, and communicates findings through clear reports and presentations to security leadership and stakeholders. The SME may participate in RFP processes, providing technical input to help select best-fit security solutions.