Home › Companies › Mobiz › SOC Manager
SOC Manager
Mobiz · Karachi, Pakistan, 75350, Pakistan · On Site · Active · BambooHR
Job facts
| Field | Value |
|---|---|
| Company | Mobiz |
| Title | SOC Manager |
| Normalized title | - |
| Department / team | Service Desk |
| Location | Karachi, Pakistan |
| Work model | On Site |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | BambooHR |
| Posted / first seen | 2026-06-01 / 2026-06-02 |
| Changed / last seen | 2026-06-02 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Mobiz. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through BambooHR. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Karachi. | Open |
| Department jobs | Active postings in Service Desk. | Open |
| Work model jobs | Active On Site postings. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Mobiz |
| Source | 64271ce9-2d64-4d90-9fae-b6f1b6ceb53e |
| ATS provider | BambooHR |
Description
About Mobiz
Mobiz is a global technology services leader, Microsoft-aligned managed services and cloud solutions provider, empowering mid-market and enterprise organizations across North America and the Middle East. We deliver end-to-end IT operations, Modern Work and Security, Data and AI, cybersecurity, infrastructure, and digital transformation services—driving resilience, innovation, and measurable business impact at scale.
With a Solutions Partner designation and active pursuit of Azure Expert MSP status, Mobiz combines the agility of a boutique consultancy with the delivery rigor of a tier-1 integrator. Our NOC and SOC teams operate as the always-on backbone of client environments, monitoring thousands of endpoints, network nodes, and cloud workloads around the clock.
What Can You Expect?
Every day at Mobiz we work with a deep sense of purpose. We continuously innovate. Our mission is to empower our clients to do more through transformation. You’ll work in a collaborative environment alongside highly talented people that improve client operations and exceed expectations. We strive to simplify technology challenges, and no less.
Who Are We Looking For?
The SOC Manager leads Mobiz's Security Operations Center, owning the end-to-end detection, analysis, and response capability that protects client environments across cloud, network, identity, and endpoint attack surfaces. Reporting to the Director of Engineering, this role is accountable for analyst team performance, detection engineering quality, threat intelligence operationalization, and client-facing security reporting. The SOC Manager operates at the intersection of technical depth and operational leadership — capable of reviewing a SIEM detection rule in the morning, leading a ransomware containment call at noon, and presenting a security posture briefing to a client CISO in the afternoon. The ideal candidate brings proven hands-on IR experience, strong familiarity with the Microsoft security stack, and a track record of building high-performing SOC teams in a managed services environment.
Key Responsibilities
1. Detection & Incident Response
Own the full threat lifecycle — alert triage, investigation, escalation, containment, eradication, and post-incident review across all monitored client tenants.
Serve as senior IR authority for P1 security incidents; lead containment decisions, coordinate cross-functional response (NOC, engineering, legal, insurance), and manage client communications throughout.
Direct and quality-review Tier 1 and Tier 2 analyst work; ensure investigation notes, timelines, and evidence are complete and defensible.
Lead post-incident reviews (PIRs) and Lessons Learned sessions for all major security events; track action items through closure.
Maintain and continuously improve incident response playbooks for ransomware, business email compromise (BEC), identity compromise, data exfiltration, and insider threat scenarios.
2. Detection Engineering & Threat Intelligence
Own the detection rule library in Microsoft Sentinel (or equivalent SIEM); drive ongoing tuning, coverage gap analysis, and MITRE ATT&CK alignment.
Develop, test, and deploy new detection rules in response to emerging threats, threat intelligence feeds, and post-incident findings.
Operationalize threat intelligence that translate CTI feeds, vendor advisories, and ISAC alerts into actionable detections, hunts, and hardening recommendations.
Lead proactive threat hunting operations across client environments; document findings, refine TTPs, and convert hunts into persistent detections.
Collaborate with the vulnerability management practice to prioritize remediation based on active threat actor targeting and client exposure.
3. Team Leadership & Analyst Development
Lead, schedule, and develop a team of SOC analysts (Tier 1–3) and detection engineers across shift rotations, including 24×7 on-call coverage.
Define analyst career paths aligned to Mobiz's engineer tiering framework; build and execute individual development plans with certification goals (SC-200, CySA+, GCIH, etc.).
Conduct structured 1:1s, performance reviews, and skills assessments; address performance gaps with coaching plans before they escalate.
Lead shift handover procedures ensuring full operational context — open incidents, active hunts, suppressed alerts — is transferred at each boundary.
Build a team culture of intellectual curiosity, operational discipline, and continuous threat learning.
4. SOC Platform & Tooling
Own the SOC tooling stack including Microsoft Sentinel, Defender XDR (MDE, MDO, MDI, MDCA), CrowdStrike Falcon, and integrated SOAR/automation workflows.
Drive SOAR playbook development to automate repetitive triage tasks, enrichment workflows, and low-complexity response actions.
Maintain integration health between SIEM, EDR, identity (Entra ID / AAD), email security, and ITSM (ServiceNow) platforms.
Evaluate new security tooling and provide recommendations to the Director of Engineering on platform investments and coverage gaps.
Ensure log source coverage completeness across all client tenants; manage onboarding of new data connectors and normalization rules.
5. Client Engagement & Reporting
Prepare and deliver monthly Security Operations Reports (SORs) covering detection metrics, incident summaries, threat landscape context, and recommended hardening actions.
Participate in client security reviews and Quarterly Business Reviews (QBRs); present SOC posture findings to technical and executive audiences.
Manage client communication during active security incidents — status updates, containment milestones, regulatory notification timelines, and post-incident summaries.
Coordinate with legal counsel (BakerHostetler or client-designated), cyber insurance carriers (AIG and others), and DFIR partners (Kroll, Fenix24) during major incidents.
Support presales and proposal efforts by providing SOC capability narratives, detection coverage matrices, and IR SLA definitions.
6. Governance, Compliance & Risk
Maintain SOC policies, procedures, and evidence retention standards in alignment with NIST CSF, CIS Controls, and client contractual requirements.
Support client audit and compliance engagements (SOC 2, ISO 27001, HIPAA, CMMC) by providing SOC operational evidence and control narratives.
Track and report on SOC KPIs to the Director of Engineering; surface capacity risks, coverage gaps, and tooling deficiencies proactively.
Maintain awareness of regulatory and legal obligations (GDPR, CCPA, state breach notification laws) relevant to incident response timelines and client notifications
Candidate Profile: Requirements & Preferred Qualifications
Required Qualifications
Bachelor’s/Master’s degree in Computer Science or related field.
7+ years of information security experience, with at least 3 years in a SOC leadership or senior analyst role.
Proven hands-on experience leading incident response for high-severity events (ransomware, BEC, APT, insider threat) in an MSP or enterprise environment.
Deep expertise with Microsoft Sentinel — rule authoring in KQL, workbook development, data connector management, and SOAR playbook design.
Strong working knowledge of the Microsoft Defender XDR suite: Defender for Endpoint (MDE), Defender for Office 365 (MDO), Defender for Identity (MDI), and Defender for Cloud Apps (MDCA).
Solid understanding of identity-based attack chains — Pass-the-Hash, Pass-the-Ticket, Golden Ticket, token theft, Entra ID OAuth abuse — and corresponding detection/containment strategies.
Familiarity with attacker TTPs mapped to MITRE ATT&CK; ability to build and maintain detection coverage matrices.
Experience with ITSM platforms for incident tracking and SLA governance; ServiceNow strongly preferred.
Excellent communication skills — able to write clear incident timelines, executive summaries, and technical PIR reports.
Preferred Qualifications
Microsoft certifications: SC-200 (Security Operations Analyst), SC-300 (Identity & Access), AZ-500 (Azure Security Engineer), or SC-100 (Cybersecurity Architect).
Industry certifications: GCIA, GCIH, GCFA (GIAC), CySA+ (CompTIA), or CISSP.
Experience with CrowdStrike Falcon — EDR policy management, threat graph analysis, and OverWatch integration.
Hands-on DFIR experience: memory forensics, disk imaging, log correlation, and chain-of-custody evidence handling.
Exposure to OT/ICS environments, SCADA monitoring, or industrial network security.
Familiarity with Palo Alto Cortex XSIAM, Splunk, or QRadar as SIEM alternatives or migration contexts.
Scripting proficiency: KQL (advanced), PowerShell, Python for detection automation, log parsing, and threat hunting.
Experience working alongside legal counsel and cyber insurers during major incident response engagements.
Core Technical Skill Set
The following technologies and platforms are central to success in this role:
SIEM: Microsoft Sentinel (primary) — KQL, Analytics Rules, Workbooks, SOAR Playbooks (Logic Apps)
EDR / XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon (client-dependent)
Email & Identity Security: Defender for Office 365, Defender for Identity, Defender for Cloud Apps
Cloud Security: Microsoft Defender for Cloud, Azure Security Center, Secure Score
Identity Platform: Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access
ITSM: ServiceNow (Incidents, Security Cases, Change, Knowledge)
Network Security: Palo Alto Panorama, Fortinet FortiManager, WatchGuard, Cisco Meraki
Threat Intelligence: Microsoft Threat Intelligence, ISAC feeds, vendor advisories
DFIR Partners: Kroll, Fenix24 (external IR augmentation on major engagements)
Automation & Scripting: PowerShell, KQL, Python, n8n, Azure Logic Apps
Communication & Reporting: Microsoft 365, Teams, Dynamics 365 CRM, SharePoint
Core Competencies (Power Skills)
Threat-Informed Detection Engineering Mindset
Communication Clarity Across Technical and Executive Layers
Emotional Intelligence & Situational Awareness
Governance, Compliance & Risk Accountability
Advanced Analytical Thinking & Forensic Reasoning
Microsoft Security Ecosystem Fluency (Cloud, Identity, Endpoint)
Executive Communication & Client Trust Management
SOC Engineering & Operational Excellence
Critical thinking and decision making
What We Offer
A team of bright, hard-working, and innovative people that will contribute to your growth.
Competitive Salary and comprehensive benefits plan.
A dynamic and collaborative work environment with opportunity to work with cutting-edge technology and innovative solutions.
Other
This is a full-time, on-site position based in Karachi, Pakistan.
Equal Opportunity & Diversity Commitment
At Mobiz, we believe that diverse perspectives, experiences, and backgrounds strengthen our organization and drive innovation. We are committed to fostering an inclusive workplace where all employees are valued, respected, and empowered to succeed. As an equal opportunity employer, we make employment decisions based on qualifications, merit, and business needs, without regard to race, gender, age, religion, disability, national origin, or any other protected characteristic.
What Happens Next?
Thank you for your interest in becoming part of Mobiz. We are committed to attracting exceptional talent and building a team that drives innovation, excellence, and meaningful impact. Every application is reviewed with care and consideration. If your experience and qualifications are a match for the role, a member of our team will connect with you regarding the next stage of the hiring process.
We appreciate your interest in joining Mobiz and wish you success in your career endeavors.
Full job record
| Job ID | a967fe76a8ca3fdbeee83c88aa983b0252e5fc45 |
| Org ID | cd488348-9f92-4e02-b13b-85a6673aefa3 |
| Source ID | 64271ce9-2d64-4d90-9fae-b6f1b6ceb53e |
| Board ID | 64271ce9-2d64-4d90-9fae-b6f1b6ceb53e |
| Provider | bamboohr |
| Provider Job Key | 447 |
| Title | SOC Manager |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Karachi, Pakistan, 75350, Pakistan |
| Department | Service Desk |
| Team | — |
| Employment Type | full_time |
| Workplace Type | on_site |
| Remote Policy | — |
| Country | — |
| Region | Pakistan |
| City | Karachi |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://mobiz.bamboohr.com/careers/447 |
| Apply URL | https://mobiz.bamboohr.com/careers/447 |
| First Seen At | 2026-06-02 10:37:36Z |
| Last Seen At | 2026-06-06 10:30:22Z |
| Last Checked At | 2026-06-06 10:30:22Z |
| Last Changed At | 2026-06-02 10:37:36Z |
| Inactive At | — |
| Source Posted At | 2026-06-01 00:00:00Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=bamboohr/board=mobiz/date=2026-06-06/2026-06-06T10-30-20-716Z-4f6b89bc4d37529b3a3f7e508bd1b9e979e327b05ba3c2b3e11fb3e02bed80c9.json |
Event Fields
{
"content_hash": "24ea6a0823469e378093d1452375f810a3097e94489db29f2c0d4549701e22e3",
"source_hash": "e6ba9586f75e1226f52dbe1e49b2c5e868b0a42c9cec69ebbfdb270639427f70",
"last_changed_at": "2026-06-02T10:37:36.022Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Karachi, Pakistan, 75350, Pakistan",
"city": "Karachi",
"region": "Pakistan",
"country": null,
"is_remote": false,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T10:30:22.714Z",
"launch_scope": {
"reason": "bamboohr_production_catalog",
"included": true,
"location": {
"raw": "Karachi, Pakistan, 75350, Pakistan",
"city": "Karachi",
"region": "Pakistan",
"country": null,
"is_remote": false,
"confidence": 0.8
},
"countries": []
},
"remote_policy": null,
"salary_period": null,
"workplace_type": "on_site",
"salary_currency": null
}Extensions
{}Native Structured
{
"list_job": {
"id": "447",
"isRemote": null,
"location": {
"city": "Karachi",
"state": "Pakistan"
},
"atsLocation": {
"city": null,
"state": null,
"country": null,
"province": null
},
"departmentId": "18564",
"locationType": "0",
"jobOpeningName": "SOC Manager",
"departmentLabel": "Service Desk",
"employmentStatusLabel": "Employee - Full-Time"
},
"detail_errors": [],
"detail_job_opening": {
"location": {
"city": "Karachi",
"state": "Pakistan",
"postalCode": "75350",
"addressCountry": "Pakistan"
},
"datePosted": "2026-06-01",
"atsLocation": {
"city": null,
"state": null,
"country": null,
"countryId": null
},
"description": "<p><span style=\"font-weight: bold\"><span>About Mobiz</span></span></p>\n<p>Mobiz is a global technology services leader, Microsoft-aligned managed services and cloud solutions provider, empowering mid-market and enterprise organizations across North America and the Middle East. We deliver end-to-end IT operations, Modern Work and Security, Data and AI, cybersecurity, infrastructure, and digital transformation services—driving resilience, innovation, and measurable business impact at scale.</p>\n<p>With a Solutions Partner designation and active pursuit of Azure Expert MSP status, Mobiz combines the agility of a boutique consultancy with the delivery rigor of a tier-1 integrator. Our NOC and SOC teams operate as the always-on backbone of client environments, monitoring thousands of endpoints, network nodes, and cloud workloads around the clock.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What Can You Expect?</span></p>\n<p><span>Every day at Mobiz we work with a deep sense of purpose. We continuously innovate. Our mission is to empower our clients to do more through transformation. You’ll work in a collaborative environment alongside highly talented people that improve client operations and exceed expectations. We strive to simplify technology challenges, and no less.</span></p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Who Are We Looking For?</span></p>\n<p>The SOC Manager leads Mobiz's Security Operations Center, owning the end-to-end detection, analysis, and response capability that protects client environments across cloud, network, identity, and endpoint attack surfaces. Reporting to the Director of Engineering, this role is accountable for analyst team performance, detection engineering quality, threat intelligence operationalization, and client-facing security reporting. The SOC Manager operates at the intersection of technical depth and operational leadership — capable of reviewing a SIEM detection rule in the morning, leading a ransomware containment call at noon, and presenting a security posture briefing to a client CISO in the afternoon. The ideal candidate brings proven hands-on IR experience, strong familiarity with the Microsoft security stack, and a track record of building high-performing SOC teams in a managed services environment.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Key Responsibilities </span><br></p>\n<p><span style=\"font-weight: bold\">1. </span><span style=\"font-weight: bold\">Detection & Incident Response</span></p>\n<ul>\n<li>Own the full threat lifecycle — alert triage, investigation, escalation, containment, eradication, and post-incident review across all monitored client tenants.</li>\n<li>Serve as senior IR authority for P1 security incidents; lead containment decisions, coordinate cross-functional response (NOC, engineering, legal, insurance), and manage client communications throughout.</li>\n<li>Direct and quality-review Tier 1 and Tier 2 analyst work; ensure investigation notes, timelines, and evidence are complete and defensible.</li>\n<li>Lead post-incident reviews (PIRs) and Lessons Learned sessions for all major security events; track action items through closure.</li>\n<li>Maintain and continuously improve incident response playbooks for ransomware, business email compromise (BEC), identity compromise, data exfiltration, and insider threat scenarios.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">2. Detection Engineering & Threat Intelligence</span></p>\n<ul>\n<li>Own the detection rule library in Microsoft Sentinel (or equivalent SIEM); drive ongoing tuning, coverage gap analysis, and MITRE ATT&CK alignment.</li>\n<li>Develop, test, and deploy new detection rules in response to emerging threats, threat intelligence feeds, and post-incident findings.</li>\n<li>Operationalize threat intelligence that translate CTI feeds, vendor advisories, and ISAC alerts into actionable detections, hunts, and hardening recommendations.</li>\n<li>Lead proactive threat hunting operations across client environments; document findings, refine TTPs, and convert hunts into persistent detections.</li>\n<li>Collaborate with the vulnerability management practice to prioritize remediation based on active threat actor targeting and client exposure.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">3. Team Leadership & Analyst Development</span></p>\n<ul>\n<li>Lead, schedule, and develop a team of SOC analysts (Tier 1–3) and detection engineers across shift rotations, including 24×7 on-call coverage.</li>\n<li>Define analyst career paths aligned to Mobiz's engineer tiering framework; build and execute individual development plans with certification goals (SC-200, CySA+, GCIH, etc.).</li>\n<li>Conduct structured 1:1s, performance reviews, and skills assessments; address performance gaps with coaching plans before they escalate.</li>\n<li>Lead shift handover procedures ensuring full operational context — open incidents, active hunts, suppressed alerts — is transferred at each boundary.</li>\n<li>Build a team culture of intellectual curiosity, operational discipline, and continuous threat learning.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">4. SOC Platform & Tooling</span></p>\n<ul>\n<li>Own the SOC tooling stack including Microsoft Sentinel, Defender XDR (MDE, MDO, MDI, MDCA), CrowdStrike Falcon, and integrated SOAR/automation workflows.</li>\n<li>Drive SOAR playbook development to automate repetitive triage tasks, enrichment workflows, and low-complexity response actions.</li>\n<li>Maintain integration health between SIEM, EDR, identity (Entra ID / AAD), email security, and ITSM (ServiceNow) platforms.</li>\n<li>Evaluate new security tooling and provide recommendations to the Director of Engineering on platform investments and coverage gaps.</li>\n<li>Ensure log source coverage completeness across all client tenants; manage onboarding of new data connectors and normalization rules.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">5. Client Engagement & Reporting</span></p>\n<ul>\n<li>Prepare and deliver monthly Security Operations Reports (SORs) covering detection metrics, incident summaries, threat landscape context, and recommended hardening actions.</li>\n<li>Participate in client security reviews and Quarterly Business Reviews (QBRs); present SOC posture findings to technical and executive audiences.</li>\n<li>Manage client communication during active security incidents — status updates, containment milestones, regulatory notification timelines, and post-incident summaries.</li>\n<li>Coordinate with legal counsel (BakerHostetler or client-designated), cyber insurance carriers (AIG and others), and DFIR partners (Kroll, Fenix24) during major incidents.</li>\n<li>Support presales and proposal efforts by providing SOC capability narratives, detection coverage matrices, and IR SLA definitions.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">6. Governance, Compliance & Risk</span></p>\n<ul>\n<li>Maintain SOC policies, procedures, and evidence retention standards in alignment with NIST CSF, CIS Controls, and client contractual requirements.</li>\n<li>Support client audit and compliance engagements (SOC 2, ISO 27001, HIPAA, CMMC) by providing SOC operational evidence and control narratives.</li>\n<li>Track and report on SOC KPIs to the Director of Engineering; surface capacity risks, coverage gaps, and tooling deficiencies proactively.</li>\n<li>Maintain awareness of regulatory and legal obligations (GDPR, CCPA, state breach notification laws) relevant to incident response timelines and client notifications</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\"><span>Candidate Profile: Requirements & Preferred Qualifications </span></span><br></p>\n<p><span style=\"font-weight: bold\">Required Qualifications</span></p>\n<ul></ul>\n<ul>\n<li>Bachelor’s/Master’s degree in Computer Science or related field.</li>\n<li>7+ years of information security experience, with at least 3 years in a SOC leadership or senior analyst role.</li>\n<li>Proven hands-on experience leading incident response for high-severity events (ransomware, BEC, APT, insider threat) in an MSP or enterprise environment.</li>\n<li>Deep expertise with Microsoft Sentinel — rule authoring in KQL, workbook development, data connector management, and SOAR playbook design.</li>\n<li>Strong working knowledge of the Microsoft Defender XDR suite: Defender for Endpoint (MDE), Defender for Office 365 (MDO), Defender for Identity (MDI), and Defender for Cloud Apps (MDCA).</li>\n<li>Solid understanding of identity-based attack chains — Pass-the-Hash, Pass-the-Ticket, Golden Ticket, token theft, Entra ID OAuth abuse — and corresponding detection/containment strategies.</li>\n<li>Familiarity with attacker TTPs mapped to MITRE ATT&CK; ability to build and maintain detection coverage matrices.</li>\n<li>Experience with ITSM platforms for incident tracking and SLA governance; ServiceNow strongly preferred.</li>\n<li>Excellent communication skills — able to write clear incident timelines, executive summaries, and technical PIR reports.<br></li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Preferred Qualifications</span></p>\n<ul>\n<li>Microsoft certifications: SC-200 (Security Operations Analyst), SC-300 (Identity & Access), AZ-500 (Azure Security Engineer), or SC-100 (Cybersecurity Architect).</li>\n<li>Industry certifications: GCIA, GCIH, GCFA (GIAC), CySA+ (CompTIA), or CISSP.</li>\n<li>Experience with CrowdStrike Falcon — EDR policy management, threat graph analysis, and OverWatch integration.</li>\n<li>Hands-on DFIR experience: memory forensics, disk imaging, log correlation, and chain-of-custody evidence handling.</li>\n<li>Exposure to OT/ICS environments, SCADA monitoring, or industrial network security.</li>\n<li>Familiarity with Palo Alto Cortex XSIAM, Splunk, or QRadar as SIEM alternatives or migration contexts.</li>\n<li>Scripting proficiency: KQL (advanced), PowerShell, Python for detection automation, log parsing, and threat hunting.</li>\n<li>Experience working alongside legal counsel and cyber insurers during major incident response engagements.<br></li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Core Technical Skill Set</span></p>\n<p>The following technologies and platforms are central to success in this role:</p>\n<ul>\n<li>SIEM: Microsoft Sentinel (primary) — KQL, Analytics Rules, Workbooks, SOAR Playbooks (Logic Apps)</li>\n<li>EDR / XDR: Microsoft Defender for Endpoint, CrowdStrike Falcon (client-dependent)</li>\n<li>Email & Identity Security: Defender for Office 365, Defender for Identity, Defender for Cloud Apps</li>\n<li>Cloud Security: Microsoft Defender for Cloud, Azure Security Center, Secure Score</li>\n<li>Identity Platform: Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access</li>\n<li>ITSM: ServiceNow (Incidents, Security Cases, Change, Knowledge)</li>\n<li>Network Security: Palo Alto Panorama, Fortinet FortiManager, WatchGuard, Cisco Meraki</li>\n<li>Threat Intelligence: Microsoft Threat Intelligence, ISAC feeds, vendor advisories</li>\n<li>DFIR Partners: Kroll, Fenix24 (external IR augmentation on major engagements)</li>\n<li>Automation & Scripting: PowerShell, KQL, Python, n8n, Azure Logic Apps</li>\n<li>Communication & Reporting: Microsoft 365, Teams, Dynamics 365 CRM, SharePoint</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Core Competencies (Power Skills)</span></p>\n<ul>\n<li>Threat-Informed Detection Engineering Mindset</li>\n<li>Communication Clarity Across Technical and Executive Layers</li>\n<li>Emotional Intelligence & Situational Awareness</li>\n<li>Governance, Compliance & Risk Accountability</li>\n<li>Advanced Analytical Thinking & Forensic Reasoning</li>\n<li>Microsoft Security Ecosystem Fluency (Cloud, Identity, Endpoint)</li>\n<li>Executive Communication & Client Trust Management</li>\n<li>SOC Engineering & Operational Excellence</li>\n<li>Critical thinking and decision making</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\"><span>What We Offer</span></span></p>\n<ul>\n<li><span>A team of bright, hard-working, and innovative people that will contribute to your growth.</span></li>\n<li><span>Competitive Salary and comprehensive benefits plan.</span></li>\n<li><span>A dynamic and collaborative work environment with opportunity to work with cutting-edge technology and innovative solutions. </span></li>\n</ul>\n<p><span> </span></p>\n<p><span style=\"font-weight: bold\"><span>Other<br></span></span><span>This is a full-time, on-site position based in Karachi, Pakistan.</span></p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Equal Opportunity & Diversity Commitment</span></p>\n<p><span>At Mobiz, we believe that diverse perspectives, experiences, and backgrounds strengthen our organization and drive innovation. We are committed to fostering an inclusive workplace where all employees are valued, respected, and empowered to succeed. As an equal opportunity employer, we make employment decisions based on qualifications, merit, and business needs, without regard to race, gender, age, religion, disability, national origin, or any other protected characteristic.</span></p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What Happens Next?</span></p>\n<p><span>Thank you for your interest in becoming part of Mobiz. We are committed to attracting exceptional talent and building a team that drives innovation, excellence, and meaningful impact. Every application is reviewed with care and consideration. If your experience and qualifications are a match for the role, a member of our team will connect with you regarding the next stage of the hiring process. </span><br></p>\n<p><span>We appreciate your interest in joining Mobiz and wish you success in your career endeavors.</span></p>\n<p><br><br></p>\n<ul></ul>",
"compensation": null,
"departmentId": "18564",
"locationType": "0",
"seekPromoted": false,
"jobCategoryId": null,
"jobOpeningName": "SOC Manager",
"departmentLabel": "Service Desk",
"jobOpeningStatus": "Open",
"minimumExperience": "Manager/Supervisor",
"jobOpeningShareUrl": "https://mobiz.bamboohr.com/careers/447",
"employmentStatusLabel": "Employee - Full-Time"
}
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/a967fe76a8ca3fdbeee83c88aa983b0252e5fc45?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/cd488348-9f92-4e02-b13b-85a6673aefa3JSONGET https://api.bluedoor.sh/job-postings/v1/sources/64271ce9-2d64-4d90-9fae-b6f1b6ceb53eJSONGET https://api.bluedoor.sh/job-postings/v1/jobs/a967fe76a8ca3fdbeee83c88aa983b0252e5fc45/eventsJSON