Logo for SALMON ROBOTICS LIMITED

SOC Manager

Role overview

Qualifications

  • Practical experience managing MSSP/MDR or other security service providers
  • Hands-on depth with Microsoft Sentinel and KQL
  • Experience with containerised platforms and workloads
  • Track record of independently assessing a security function

Responsibilities

  • Set the direction for monitoring, detection, and response across various environments
  • Lead technical response during significant cyber incidents
  • Own the monitoring architecture and telemetry strategy
  • Define threat scenarios and maintain detection coverage against them

Key facts

Hard skills

Other skills

  • Governance
  • Incident Reporting
  • Communication
  • Problem Solving
  • Team Leadership
  • Negotiation

About the company

SALMON ROBOTICS LIMITED logo

SALMON ROBOTICS LIMITED

Banking

SALMON ROBOTICS LIMITED is a business supplies and equipment company based out of 46 MISBOURNE ROAD, UXBRIDGE, United Kingdom.

Company details

IndustryBanking
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Salmon is a technology-driven financial company building a banking and lending platform across Southeast Asia, starting in the Philippines.

We combine global fintech expertise with deep local market knowledge to make financial services simple, accessible, and useful for millions of people across the region.

7M+ app downloads. 2M+ monthly active users. 7,000+ partner stores. US$310M+ raised from leading global investors.

Manila-based, globally distributed, and hybrid-first — our team spans 45+ countries.

If you want to solve complex problems at scale and impact how millions of people access and manage money, come build with us.

Southeast Asia's fintech moment starts here.

About the role

You'll own Security Operations at group level across a regulated bank, consumer finance business, and shared technology platform, working directly with the Group CISO.

What you'll do

  • Set the direction for monitoring, detection, and response across cloud, identity, endpoints, SaaS, and containerised environments

  • Lead the technical response during significant cyber incidents and coordinate the teams involved

  • Select, manage, and hold MSSP/MDR providers accountable, deciding when to build in-house versus buy

What you'll own

  • Own the monitoring architecture and telemetry strategy: SIEM design, data sources, retention, forensic readiness, and telemetry cost management

  • Define the threat scenarios that matter most to Salmon, maintain detection coverage against them, and drive threat hunting and detection validation using MITRE ATT&CK

  • Own incident readiness — playbooks, escalation, forensic readiness, post-incident reviews, and tabletop exercises — and take part in complex investigations hands-on, including KQL and telemetry analysis

  • Own Vulnerability and Exposure Management, setting remediation priorities and expectations and governing the risk acceptance process for exceptions

  • Own the operational side of DLP and selected access governance controls, including SSO coverage, privileged access monitoring, and access reviews

  • Set priorities for the Security Operations team and vendors, define metrics on coverage, detection quality, response performance, and provider performance, and own technical readiness for BSP and PCI DSS assurance activities

What makes you a strong fit

  • Practical experience managing MSSP/MDR or other security service providers, including selection, negotiation, escalation, or replacement

  • Hands-on depth with Microsoft Sentinel and KQL, and experience with Microsoft Defender XDR / Defender for Endpoint

  • Working knowledge of Microsoft 365 security and audit telemetry, identity and access telemetry, and cloud security monitoring in complex environments

  • Experience with containerised platforms and workloads, and with SIEM data flows, retention, tiering, and cost management

  • Track record of independently assessing a security function, prioritising against risk and cost, and leading through serious incidents with incomplete information

  • Comfortable communicating with engineers, providers, the CISO, senior management, Risk, and Internal Audit

What we offer

Ownership and flexibility

  • Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)

  • Company-provided tools and equipment

Health and time off

  • Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits

  • Access to an internal mental health support specialist

  • 22 vacation days, Philippine public holidays, and 15 sick days

Growth and team experience

  • Opportunities to learn and share your expertise through internal expert meetups, external conferences, speaking opportunities, and industry publications

  • Company-sponsored trips to Manila to meet and work with your team in person

  • High-performing teams can earn a dedicated beach house week in Southeast Asia

We believe strong teams are built by people with different backgrounds, experiences, and points of view. Salmon is an equal opportunity employer, and we make hiring decisions based on skills, experience, and potential.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at SALMON ROBOTICS LIMITED

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.