04 Sep
|
Triskele Labs
|
Melbourne
04 Sep
Triskele Labs
Melbourne
Twelve years ago Triskele Labs was one person and an idea about how cyber security should actually be delivered. Today we run a 24x7x365 Security Operations Centre (SOC) that never leaves Australian soil, an MDR practice protecting regulated enterprise, government and higher education, and one of the busiest DFIR benches in the country. Still founder-led. Still independently owned. Still Australian.
We are looking for the leader who takes the SOC further.
The Role
You own how well our MDR service runs in front of the client.
That means the L1 to L3 analyst team across our state-based SOCs. It means rostering, capacity and fatigue across a round-the-clock operation. It means triage quality, service levels, escalation handling and the development of every analyst doing the work. And it means the SOC's workflow and triage automation roadmap, delivered through your SOC Automation Analyst.
This is a hands-on operational leadership role, not a reporting layer. You will need the depth to challenge an analyst's conclusion, read playbook logic rather than just its outcomes, and judge what a detection or automation change will do to the live queue before it gets there.
The Detail The role sits alongside our Platform Engineering Manager. Between you, you carry the MDR service.
Platform Engineering owns what the service can detect, hunt and validate: detection engineering, threat intelligence, threat hunting, breach attack simulation. The SOC owns how well that capability is operated.
You are not building the detection capability. You are leading the function that consumes it well, and you are the peer who tells Platform Engineering the truth about what is and isn't working in the queue. Weekly rhythm and joint prioritisation, not an escalation path used after something has already gone wrong.
Automation runs the other way. Workflow and triage automation belongs to you.
You decide what gets automated next and you hold the quality bar on playbook design, with the SOAR Engineer and DevOps providing the platform underneath.
Clear lines, real ownership, a genuine peer to argue with. That boundary is deliberate, and it's the most important thing to understand about the job.
The Position
- Leading, coaching and developing the analyst team: performance, career pathways, succession
- Roster fairness, fatigue monitoring and analyst wellbeing across a 24x7 operation
- SLA, KPI and incident response commitments, and acting as the senior operational escalation point
- The SOC automation roadmap, agreed with the Head of Managed Services
- Operational readiness for recent client onboarding: tooling, alerting, runbooks and analysts ready before go-live
- Senior escalation contact for key MDR clients, and the quality of what we put in front of them
- SOC processes, SOPs and runbooks aligned to ISO 20000, ISO 27001 and SOC 2
- Driving the operational evolution of our SIEM, SOAR and EDR tooling
- The analyst development pathway from L1 through to L3 and onward into Platform Engineering, DFIR or engineering specialisations
Your Fit
You have run a SOC, not just worked in one. You can hold a technical argument with an L3 and win it on the merits. You have opinions about what should and shouldn't be automated, and scars from getting it wrong. You take rostering and analyst burnout as seriously as MTTR. And you can sit in front of a client during a bad week and be the reason they stay calm.
What we provide A SOC with real scale and real clients, sovereign and onshore. Front-line threat intelligence from an active DFIR practice. A founder-owned business where the decision-maker is in the building. And the mandate to build the operation you think a SOC should be.
Application A cover letter addressed to Brad Morgan, Head of Managed Services, is mandatory. Applications without one will not be considered.
Tell us about a SOC you have run, and one operational problem you fixed that the metrics can prove.
📌 Security Operations Centre (SOC) Manager (Melbourne)
🏢 Triskele Labs
📍 Melbourne