Overview
SOC Manager / Security Operations Center Lead (SIEM, Incident Response) Jobs in Jakarta, Indonesia at Millennium Technology Services
Title: SOC Manager / Security Operations Center Lead (SIEM, Incident Response)
Company: Millennium Technology Services
Location: Jakarta, Indonesia
SOC Manager / Security Operations Center Lead (SIEM, Incident Response) – Jakarta (On-site)
Job Summary
We are looking for an experienced SOC Manager / SOC Lead to oversee end-to-end Security Operations Center (SOC) functions within a large enterprise environment.
This role requires a hands-on leader who can manage SOC operations (L1–L3), lead incident response, and work closely with stakeholders during high-severity security incidents.
The ideal candidate will have a strong balance of SOC operational leadership, SIEM expertise, and the ability to clearly articulate security incidents and response strategies.
Key Responsibilities
- Lead and manage 24/7 SOC operations, including L1, L2, and L3 teams
- Oversee real-time security monitoring, alert triage, and incident response
- Act as incident commander for high-severity (P1/P2) cybersecurity incidents
- Drive incident investigation, containment, remediation, and post-incident review
- Develop and improve SIEM use cases, detection rules, and SOC playbooks
- Work closely with threat intelligence and threat hunting teams to enhance detection capabilities
- Define and track SOC KPIs such as MTTD, MTTR, and SLA adherence
- Coordinate with internal teams, vendors, and stakeholders during incidents
- Provide clear communication and reporting to technical teams and business stakeholders
- Continuously improve SOC processes, automation (SOAR), and operational efficiency
Key Requirements
- 10–20 years of experience in IT / Cybersecurity, with strong SOC leadership experience
- Proven experience managing SOC operations (L1–L3) in enterprise or MSSP environments
- Hands-on experience with SIEM platforms (e.g. Splunk, QRadar, Sentinel, ArcSight)
- Strong experience in incident response, threat detection, and escalation handling
- Ability to explain incident scenarios clearly and confidently (important)
- Experience handling ransomware, APT, or major security incidents
- Familiarity with SOAR, EDR/XDR, and threat intelligence platforms
- Strong understanding of SOC workflows, playbooks, and escalation processes
- Excellent communication and stakeholder management skills
Good to Have
- Experience in banking, telco, or large enterprise environments
- Exposure to regional or global SOC operations
- Relevant certifications (e.g. CISSP, CISM, CEH, GIAC, Splunk)
- Experience in SOC transformation / implementation projects