Impress employers and recruiters.
Choose from hundreds of resume examples.

Impress employers and recruiters.
Choose from hundreds of resume examples.
Tailor your resume to this Head of Security Operations role.
Rezi rewrites your resume against Sokin's job description. Free.

Tailor your resume to this Head of Security Operations role.
Rezi rewrites your resume against Sokin's job description. Free.
Don't guess if your resume is good enough.
See how it scores against the Head of Security Operations posting at Sokin — free, in seconds.

Don't guess if your resume is good enough.
See how it scores against the Head of Security Operations posting at Sokin — free, in seconds.
About the Role
You will own security operations at Sokin, building, running, and growing the function. This includes detection strategy, incident response, vulnerability management, and identity governance, with day-to-day triage handled by an outsourced SOC. You will shape the split between MSSP and in-house responsibilities as the function matures.
Responsibilities
- Define and maintain the detection strategy, mapped to MITRE ATT&CK.
- Set standards and review Microsoft Sentinel content authored by MSSP or in-house.
- Own detection-as-code practices, including version control, peer review, and testing.
- Develop bespoke detections for areas the MSSP cannot cover, such as payments/fraud-specific logic.
- Onboard new log sources and integrate security tooling like Defender XDR, Wiz, Cloudflare, and Zscaler.
- Translate threat intelligence into detection and hunting priorities.
- Build and maintain SOAR automation for alert enrichment, triage, and response actions.
- Manage the MSSP/outsourced SOC relationship, including SLAs and quality.
- Shape the boundary between MSSP and in-house scope as the team and platform mature.
- Lead incident response, including L3 investigation and forensic analysis.
- Own incident management end to end, including major incident declaration and executive notification.
- Coordinate with legal and communications on regulatory notification timelines.
- Develop and maintain incident response playbooks and runbooks, and test them regularly.
- Drive post-incident reviews and RCAs, feeding lessons back into detection and playbook updates.
- Own vulnerability management as a program, including scanning, prioritization, and remediation.
- Own identity governance within security operations, including privileged access monitoring and access anomaly detection.
- Own operational metrics such as MTTD and MTTR, and drive them down.
- Manage the security operations team, including direct line management and hiring plans.
- Manage SOC systems, tooling, and processes, including budget and licensing.
- Support the CISO on incident communication, board/customer reporting, and post-incident reviews.
Requirements
- Deep Microsoft Sentinel experience, including KQL proficiency and ability to author/review detection rules, workbooks, and playbooks.
- Experience onboarding new data sources into a SIEM and scaling detection coverage.
- Hands-on incident response and digital forensics experience across cloud and endpoint.
- Experience sharing ownership of the incident management process, including major incident declaration and executive communication.
- Applied MITRE ATT&CK knowledge used in detection engineering.
- Experience running vulnerability management as a program.
- Working knowledge of identity governance and access risk as it applies to security operations.
- Experience managing an MSSP/outsourced SOC relationship.
- Experience running tabletop exercises or equivalent IR plan testing.
- Experience with cloud security telemetry (AWS CloudTrail, Azure Monitor, GCP audit logs).
- Strong written communication skills for incident reports and RCAs.
- Prior people management or mentoring experience in a SOC or detection engineering team (nice to have).
- Experience with Defender XDR (nice to have).
- Wiz or equivalent CSPM integration experience (nice to have).
- Fintech, payments, or regulated environment background (nice to have).
- Formal threat intelligence platform experience (nice to have).
- Python or PowerShell for automation (nice to have).
- Relevant certifications (SC-200, AZ-500, GCIA, GCIH, GCFE, GCFA, or equivalent applied experience) (valued, not required).
Skills
- Microsoft Sentinel
- KQL
- Detection Engineering
- Incident Response
- Digital Forensics
- Vulnerability Management
- Identity Governance
- SOAR Automation
- MITRE ATT&CK
- Cloud Security Telemetry
- Written Communication
- People Management
- Mentoring
- Defender XDR
- CSPM
- Threat Intelligence
- Python
- PowerShell
Experience Level
- Senior
About the Company
- Sokin is a next-generation B2B financial services provider enabling businesses to make and receive global payments with greater speed, lower cost, and total transparency.
- Our mission is to simplify global business so businesses thrive wherever they choose to grow.
- We deliver services across global payments and receivables, Foreign Exchange (FX), treasury management, and finance reconciliations.
- We are rapidly expanding with presence in EMEA, APAC, and North America, backed by a strong global infrastructure and industry-leading partners.
- We are redefining how businesses move money worldwide.
- Our clients span industries from sports and entertainment to logistics and travel.
- We are building a team of exceptional people who share our ambition to transform the future of global payments.
Equal Opportunity
- Candidates will need to have the right to work in the jurisdiction that they are looking to work in.