SOC Manager

Old National BankPlainfield, IL
$98,400 - $199,000

About The Position

Old National Bank is seeking a hands-on Security Operations Center (SOC) Manager to transform their Microsoft Sentinel and Microsoft Defender XDR foundation into a high-performing, intelligence-driven SOC. This technical leader will be responsible for guiding internal analysts and MSSP-supported operations, with a focus on enhancing detection quality, investigation workflows, incident response, automation, telemetry management, KPI/KRI dashboards, and analyst development. The ideal candidate will possess senior/Tier 3-level SOC experience and be prepared to establish the operating model, metrics, capabilities, and team culture necessary to elevate the cyber defense program.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field, or equivalent hands-on experience.
  • 7+ years of hands-on cybersecurity operations experience, including at least 2 years in a SOC manager, SOC lead, or senior/Tier 3 technical SOC role.
  • Experience managing SOC staffing, coverage models, shift handoffs, on-call expectations, workload distribution, or capacity planning in an internal, MSSP-supported, or hybrid SOC environment.
  • Experience hiring, onboarding, coaching, and performance-managing SOC analysts or security operations team members.
  • Strong hands-on experience with Microsoft Sentinel and log pipeline tooling such as Cribl, including KQL, analytics rules, incidents, workbooks, automation, parser development, SIEM tuning, and cost-aware telemetry decisions that shape, filter, enrich, route, and optimize security logs before they reach Sentinel or longer-term storage.
  • Strong hands-on experience with Microsoft Defender XDR and related Defender products, especially endpoint, identity, email, cloud app, incident correlation, advanced hunting, and response workflows.
  • Demonstrated ability to build, track, visualize, and improve SOC KPIs, KRIs, dashboards, and operational reporting that show security value, risk reduction, and team effectiveness.
  • Deep understanding of incident response, security monitoring, telemetry, identity-based attacks, cloud security, malware behaviors, adversary tactics, and the development of playbooks, escalation models, detection logic, threat hunting methods, and analyst enablement materials.
  • Experience with scripting or automation using PowerShell, Python, KQL, Logic Apps, APIs, or similar tools.
  • Familiarity with MITRE ATT&CK, threat modeling, cyber kill chain concepts, and mapping detections to adversary behaviors.
  • Experience managing or partnering with an MSSP, MDR provider, or outsourced SOC function, including service expectations, escalation quality, operational handoffs, continuous improvement, shared metrics, and vendor accountability.
  • Ability to set clear expectations, prioritize work, hold teams accountable, and create a culture of operational excellence and continuous improvement.
  • Strong communication skills with the ability to explain technical findings, operational risk, and incident status to technical teams, business stakeholders, and leadership.

Nice To Haves

  • Experience leading SOC modernization, SIEM migration, Defender XDR rollout, Sentinel detection content lifecycle management, or security automation initiatives.
  • Experience in financial services, banking, regulated environments, or organizations with mature governance, risk, compliance, audit, and privacy expectations.
  • Relevant certifications such as CISSP, GCIH, GCIA, GCFA, GNFA, GMON, SC-200, AZ-500, MS-500, OSCP, or equivalent practical experience.
  • Experience with cloud security across Azure, AWS, or GCP, including cloud logging, identity, workload protection, and incident response.
  • Experience designing purple-team scenarios, validating detections, and turning exercise results into measurable improvements.
  • Experience with malware analysis, forensics, endpoint investigation, memory analysis, or advanced incident response techniques.
  • Knowledge of regulatory and control frameworks such as NIST CSF, NIST 800-53, FFIEC, ISO 27001, PCI DSS, CIS Controls, or related guidance.

Responsibilities

  • Lead daily SOC operations across internal and MSSP-supported monitoring, alert triage, investigation, escalation, incident response, threat hunting, and continuous improvement.
  • Own and evolve the MSSP relationship, including eyes-on-glass coverage, initial triage, handoffs, escalation quality, shared metrics, service improvement, and alignment to the internal SOC operating model.
  • Implement, evaluate, and govern AI-assisted investigation and response capabilities that improve speed, consistency, evidence quality, and analyst effectiveness.
  • Ensure appropriate SOC staffing, workload balance, shift handoffs, on-call readiness, and escalation coverage across internal, MSSP-supported, and hybrid operating models.
  • Define, visualize, and improve SOC KPIs and KRIs through dashboards and recurring reporting that connect operational performance, control effectiveness, risk trends, and business impact.
  • Mature Microsoft Sentinel capabilities, including analytics rules, KQL, workbooks, automation, playbooks, data connectors, parsing, and cost-aware log ingestion decisions that route high-value telemetry to Sentinel and lower-value or historical data to lake, archive, or cold storage.
  • Use Microsoft Defender XDR to connect signals across endpoint, identity, email, and cloud app activity, improving incident correlation, advanced hunting, investigation quality, and response speed.
  • Improve detection quality through false-positive reduction, coverage-gap closure, MITRE ATT&CK alignment, threat intelligence, hunting, validation testing, and purple-team lessons learned.
  • Establish detection and use-case lifecycle governance, including ownership, documentation, testing, tuning, retirement, and periodic coverage reviews.
  • Lead, coach, and develop SOC analysts through mentoring, technical reviews, structured training, investigation walk-throughs, tabletop exercises, and hands-on skill development.
  • Coordinate major incident response, including playbook execution, escalation paths, evidence handling, executive-ready communications, after-action reviews, and response improvement.
  • Partner with infrastructure, cloud, endpoint, identity, vulnerability management, governance, legal, compliance, privacy, and business teams to improve visibility, control effectiveness, and response readiness.

Benefits

  • competitive compensation with our salary and incentive program
  • medical, dental, and vision insurance
  • 401K
  • continuing education opportunities
  • employee assistance program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service