Lead / Principal Cyber Engineer (SOC Product Lead)
What the role is
The SOC Product Lead is the strategic owner of the Cybersecurity Operations Centre's detection and monitoring capabilities, treating the SOC as a continuously evolving product rather than a static operational function. This role bridges business risk, stakeholder demands, compliance obligations, and the threat landscape - translating them into a prioritised roadmap that the Tech Lead and analyst teams execute against.
The Product Lead does not build detection rules they ensure the right capabilities are built, in the right order, for the right outcomes.
Key Responsibilities
SOC Capability Roadmap & Backlog Ownership
- Define, own, and continuously refine the SOC capability roadmap - including detection use cases, automation workflows, tooling enhancements, and analyst enablement initiatives
- Maintain a prioritised product backlog balancing immediate risk reduction with long-term platform maturity
- Write clear user stories and acceptance criteria for detection use cases, SOAR playbooks, and dashboards
- Facilitate sprint planning, backlog refinement, and reviews with technical teams
- Track and report delivery progress, sprint outcomes, and roadmap status
Stakeholder Management & Requirements Gathering
- Act as the primary interface between the SOC and internal stakeholders
- Gather monitoring requirements, regulatory obligations, and threat concerns
- Translate business risks into actionable SOC capability requirements
- Manage stakeholder expectations on timelines, priorities, and trade-offs
- Represent SOC roadmap in governance and risk forums
Threat-Informed Prioritisation
- Continuously assess the threat landscape using threat intelligence, incident learnings, and industry insights
- Prioritise detection use cases based on threat relevance, asset criticality, and exploitability (aligned to frameworks like MITRE ATT&CK)
- Maintain and address detection coverage gaps with technical teams
- Ensure emerging threats (e.g., AI-driven attacks, cloud risks, supply chain threats) are reflected in planning
Tool & Vendor Strategy
- Own SOC technology strategy across SIEM, SOAR, EDR, and threat intelligence platforms
- Lead vendor evaluations, RFPs, and proof-of-concepts
- Manage vendor relationships, contracts, and SLAs
- Track emerging technologies and assess alignment with roadmap
- Own and manage SOC technology budget
Metrics, Reporting & Continuous Improvement
- Define SOC KPIs (e.g., MTTD, MTTR, alert quality, automation rates)
- Build executive dashboards translating technical performance into business risk insights
- Lead operational reviews to identify gaps and improvements
- Drive continuous improvement through use case lifecycle reviews and post-incident learnings
Compliance & Governance Alignment
- Ensure SOC capabilities align with regulatory and compliance frameworks (e.g., ISO, NIST, or equivalent)
- Maintain traceability between controls and detection use cases
- Support audits with evidence of SOC effectiveness
- Align roadmap with organisational risk and compliance objectives
Requirements
- Degree in Computer Science, Engineering, Data Science, or related field
- Strong understanding of security operations, detection workflows, and incident response
- Familiarity with frameworks such as MITRE ATT&CK and common threat vectors
- Working knowledge of SIEM, SOAR, EDR, and threat intelligence platforms
- Experience with cloud security monitoring (e.g., Azure, AWS)
- Ability to define KPIs and communicate performance to diverse stakeholders
- Experience in regulated environments (e.g., financial services, infrastructure, or public sector)
- At least 5 years in cybersecurity, with 2+ years in a strategic or product-focused role
- Experience owning security roadmaps, vendor management, and budgeting
- Strong stakeholder management and communication skills
- Strategic and data-driven mindset
If you believe you fit the requirements for the role,please submit yourapplication below or drop us an email directly quoting thejob title.
Due to an anticipated high volume of applicants, we regret that onlyshortlisted candidates will be notified. The information provided is forrecruitment purposes only.
Know someone who would be a great fit for this role Refer them to us and get rewarded.
Cornerstone Global Partners (EA License Number:19C9859) is an affirmative equal-opportunity employer and recruitment firm. Weevaluate qualified applicants without regard to race, colour, religion, creed,gender, sexual orientation, gender identity, marital status, national origin,age, veteran status, disability, or any other protected class.
Eugene Then
[Confidential Information]
EA Registration Number: R22104742.
Cornerstone Global Partners Pte Ltd (EA License:19C9859)