Security Operations Centre Manager
Triskele Labs · Melbourne, Victoria, Australia · 2026-08-31
About this role
Triskele Labs is one of Australia’s leading sovereign cyber security firms, delivering Managed Detection & Response (MDR), Digital Forensics & Incident Response (DFIR), Offensive Security, and Governance, Risk & Compliance (GRC) services to regulated enterprises, government, and the higher education sector. Built over more than a decade, founder-led and independently owned, we partner with clients operating under some of Australia’s most demanding regulatory regimes.
Our Security Operations Centre runs 24x7x365 and remains completely onshore, and we are the largest CREST Registered Penetration Testing company in Melbourne. Sovereign Australian ownership, deep technical capability, and front-line threat intelligence from one of the most active DFIR practices in the country sit at the centre of how we differentiate.
We are hiring a SOC Manager to lead the operational performance of our Australian Security Operations Centres. You will manage our L1 to L3 analyst structure, you will own rostering and capacity across a 24x7x365 operation, own the SOC’s workflow and triage automation roadmap through your SOC Automation Analyst, and be accountable for how well our MDR service actually runs in front of the client.
The role sits alongside our Platform Engineering Manager, and the two roles carry the MDR service between them. Platform Engineering owns what the service can detect, hunt and validate: detection engineering, cyber threat intelligence, threat hunting and breach attack simulation. The SOC owns how well that capability is operated: triage quality, service levels, escalation handling, client communication, the development of the analysts doing the work, and the workflow and triage automation that makes the operation scale.
That boundary is deliberate and it is the most important thing to understand about this role. You are not building the detection capability. You are leading the function that consumes it well, and will need to be the peer who tells Platform Engineering the truth about what is and is not working in the queue. The partnership is at a minimum a weekly operating rhythm and joint prioritisation, not an escalation path used after something has gone wrong.
Automation runs the other way. Workflow and triage automation belongs to the SOC, and the SOC Automation Analyst reports to you. You decide what gets automated next, you hold the quality bar on playbook design, and you partner with the SOAR Engineer and the DevOps team, who provide the platform capability, integrations and infrastructure underneath.
This is a hands-on operational leadership role, not a reporting layer. You will need enough technical depth to challenge an analyst’s conclusion, review playbook logic rather than just its outcomes, and judge the operational impact of a detection or automation change before it reaches the live queue.
You must be able to weigh the risk and the benefit of those decisions, to keep our service at the forefront of our clients’ cyber security concerns while supporting our team to do their work effectively and safely.
Key Responsibilities
Leadership
• Lead, coach and manage the SOC analyst team from L1 through to L3, and the SOC Automation Analyst, across state-based Security Operations Centres, owning performance reviews, career development and succession planning.
• Own rostering, scheduling and capacity across a 24x7x365 operation, including roster fairness, fatigue monitoring, mental health awareness and analyst wellbeing.
• Refine and drive the analyst development pathway from L1 through to L3 and onward into Platform Engineering, DFIR or engineering specialisations, identifying training needs and knowledge gaps and acting on them.
Operational management
• Ensure day-to-day SOC operations meet SLA, KPI and incident response commitments, and act as the key operational escalation point for the team.
• Oversee escalations across the L1 to L3 tiers and coordinate high-severity incident response, shift standups and handoffs.
• Own workflow and triage automation and the SOC automation roadmap, agreed with the Head of Managed Services and delivered through the SOC Automation Analyst who reports to you: deciding what gets automated next, reviewing playbook design and logic, and holding delivery and quality.
• Maintain SOC processes, SOPs, runbooks and knowledge management aligned to ISO 20000, ISO 27001 and SOC 2, and support audit preparation and evidence rigour.
• Drive incident simulation planning, and support post-incident reviews so that what is learned reaches the runbooks.
Client service
• Act as a senior escalation contact for key MDR clients, and attend client meetings during onboarding, escalation and service review.
• Own the operational readiness of new client onboarding into the SOC: tooling, alerting, runbooks and analyst enablement in place before the client goes live.
• Ensure the quality, consistency and timeliness of incident documentation, case categorisation, remediation guidance, threat briefs and monthly service reporting.
Capability and tooling
• Drive the evolution of the SOC’s tooling and automation, SIEM, SOAR and EDR, from the operational side, and evaluate emerging technology for what it would genuinely do for triage quality, response time and analyst effort.
• Define the SOC’s operational requirements for tooling and workflow, and work with Engineering, DevOps and Platform Engineering to see them delivered.
Platform Engineering partnership
• Hold the peer relationship with the Platform Engineering Manager: weekly operational alignment, joint prioritisation of detection improvements, and integration of client feedback into their roadmap.
• Own the SOC side of the feedback loop, ensuring false-positive patterns, noisy alerts and missed-detection observations reach Detection Engineering in a structured, actionable form.
• Ensure Platform Engineering output, validated detections, enriched indicators, hunt findings and BAS gap data, is…
Skills asked for
- penetration testing
- devops
- power bi
Similar jobs
- Senior Security Operations AnalystKPMG Australia · Melbourne
- Advisory Solution Consultant (Pre-Sales), Security Operations – Sydney or MelbourneServiceNow · Melbourne
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.