N
Services Delivery Manager
Noventiq Seven Seas Technology
Dubai, United Arab Emirates · Full Time
Be the first to apply
- Experience
- 10+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Overview
We are seeking an experienced Services Delivery Manager to lead Security Operations Center (SOC) functions ensuring 24x7 monitoring, incident response, and team management in a dynamic operational setting based in Dubai.
Primary Duties
- Lead SOC operations encompassing round-the-clock monitoring, triage, incident investigation, and response including managing escalation and on-call protocols.
- Develop, enforce, and audit SOC operational runbooks, playbooks, service level agreements, and quality benchmarks ensuring consistent analyst performance.
- Act as incident commander during high-severity security incidents liaising with IT, legal, communications, and executive management across resolution and post-incident analysis.
- Recruit, onboard, and retain SOC team members ranging from L1 to L3 analysts, threat hunters, and detection engineers, managing staffing schedules and career development.
- Facilitate structured training programs, simulated incident exercises, and collaborative purple team sessions; establish performance goals and conduct evaluations.
- Promote a culture focused on continuous process enhancement, extensive documentation, and knowledge dissemination.
- Oversee the entire detection engineering lifecycle including use-case creation, tuning for false positives, and coverage assessment aligned with MITRE ATT&CK and critical threat actors.
- Lead implementation of Security Orchestration, Automation, and Response (SOAR) solutions to reduce manual tasks in triage and enrichment workflows.
- Integrate cyber threat intelligence into detection content, threat hunting strategies, and stakeholder advisories.
- Optimize security telemetry from SIEM, EDR/XDR, network detection, email, and cloud security tools to close operational visibility gaps.
- Establish and report on key SOC metrics including mean time to detect (MTTD), mean time to respond (MTTR), alert fidelity, coverage, SLA compliance, and analyst utilization for leadership and clients.
- Maintain SOC documentation and audit evidence supporting compliance frameworks such as ISO 27001, SOC 2, NIST CSF, and relevant regional regulations.
- Manage budgets related to SOC tooling, vendor relationships, licensing, and renewals, preparing business cases for new technologies.
- Engage stakeholders through incident reports, threat briefings, and service performance presentations to senior leadership and client executives.
- Serve as a trusted advisor on security posture enhancements based on SOC findings.
- For managed security service providers, support pre-sales activities including service scoping, SLA creation, and client onboarding.
Required Experience and Qualifications
- Over 10 years in cybersecurity with a minimum of 3 years leading or managing SOC or incident response teams in a 24x7 operational setting.
- Proven experience overseeing SOC operations within large enterprises or managed security service providers supporting multiple clients or business units.
- Deep practical experience with SIEM platforms such as Sentinet or Securonix, EDR/XDR solutions including CrowdStrike, Microsoft Defender, SentinelOne, and SOAR tools.
- Documented incident command leadership during severe incidents like ransomware, business email compromise, insider threats, and cloud breaches, from detection to recovery and lessons learned.
- Comprehensive understanding of attacker methodologies, frameworks like MITRE ATT&CK, cyber kill chain concepts, and threat-informed defensive strategies.
- Working knowledge of security telemetry across network, endpoint, identity, email, and cloud environments (Azure, AWS, GCP).
- Experience defining and communicating SOC metrics and SLAs to executive stakeholders.
- Strong track record in recruiting, mentoring, and retaining security operations staff.
- Excellent verbal and written communication skills with the ability to translate technical details for varied audiences.
Certifications (Preferred)
- GIAC certifications such as GCIH, GCIA, GCFA, GMON, GSOM, CISSP, CISM.
- Relevant vendor certifications.
Additional Desired Skills
- Experience establishing or transforming SOC capabilities including greenfield builds, tool migrations, or maturity uplift initiatives.
- Skills in threat hunting and detection-as-code using tools like Sigma, KQL, SPL, YARA, and managing Git-based content pipelines.
- Fundamentals of digital forensics and malware analysis.
- Familiarity with operational technology (OT), industrial control systems (ICS), or cloud-native security environments.
- Knowledge of regulatory and industry frameworks.
- Proficiency in scripting or automation languages like Python and PowerShell.
Location and Work Details
This full-time position is based onsite in Dubai, United Arab Emirates.
Industry
CybersecuritySkills
How they work
Stress Management
required