Mannheim, Baden-Württemberg
SOC Lead
SOC Lead
Ready to Build Something That Doesn't Exist Yet?
Most SOC roles ask you to maintain. This one asks you to create.
A global industrial technology business, over 175 years old and still innovating, has made cyber security a boardroom priority. They're building their CDC from the ground up, and they need a Lead who can architect the entire function: strategy, processes, automation, tooling, and a team of analysts to back it up.
This is a rare opportunity to put your name on something. No inherited processes. No legacy decisions to unpick. Just a clear mandate, executive backing, and the freedom to do it right.
What You'll Be Doing
You'll take end-to-end ownership of the CDC — defining how it operates, how it scales, and how it matures. Day to day, that means:
Designing and owning all CDC processes, SOPs, runbooks, and playbooks — building from scratch, not from a template
Leading an automation-first approach: implementing and continuously improving SOAR capabilities to cut manual workload and sharpen response times
Developing the CDC roadmap with a clear eye on regulatory requirements including NIS2 and ISO 27001
Acting as incident manager for critical events — staying strategic, not getting pulled into the weeds
Integrating OT security requirements into centralised monitoring alongside IT environments
Selecting, optimising, and managing the security technology stack — SIEM, SOAR, XDR
Leading, mentoring, and developing a team of 3–5 security analysts
Reporting CDC performance to senior leadership through meaningful KPIs (MTTD, MTTR)
The Company
You'll be joining a global industrial technology business with a 175-year track record of innovation. The organisation operates across IT and OT environments at scale — which means the security challenges here are genuinely complex, and the investment behind this function is real.
Cyber security has moved firmly onto the executive agenda. You'll have the organisational weight behind you to build this properly.
What You'll Need
Solid experience in a SOC, CDC, or Information Security leadership environment
A process-first mindset — you think in workflows, not just incidents
Hands-on experience with SOAR platforms and an instinct for automation
Familiarity with SIEM and XDR tooling
Working knowledge of relevant frameworks and standards — NIST, SANS, ISO/IEC 27001, NIS2
Experience leading and developing security analysts
Business-level German and strong English — you'll need both
Comfortable with on-call responsibilities and major incident availability
How to Apply
You can apply directly through this page, or reach out to the consultant listed in this advert if you'd prefer a conversation first.
Your CV doesn't need to be polished or up to date — send what you have. If this sounds like the right move, we'd rather hear from you early than not at all.
Learn More