IT service delivery

SmartSuite for the Security Operations Manager

The Security Operations Manager leads the SOC and security incident response: alert triage, playbooks, containment, escalation and the metrics that show how fast threats are detected and closed. They coordinate analysts and responders and report SOC performance to the CISO.

What you own

  • Run the security operations centre and shift coverage
  • Own alert triage, prioritisation and escalation
  • Maintain response playbooks for high-priority incidents and breaches
  • Lead security incident response and post-incident reviews
  • Coordinate with IT operations, crisis management and legal during incidents
  • Report SOC metrics such as MTTD, MTTR and SLA adherence

Where the role sits

Each name opens that role's page.

Reports to

Chief Information Security Officer

Chief Information Security Officer

See the role
Information Security Officer

Information Security Officer

See the role

Direct reports

Security Analyst

Security Analyst

See the role

Works closely with

Incident and Problem Manager

Incident and Problem Manager

See the role
Crisis Management Lead

Crisis Management Lead

See the role
IT Risk Manager

IT Risk Manager

See the role
Data Protection Officer

Data Protection Officer

See the role

GRC processes

The shared GRC process map, highlighted for this role.

Owns

accountable for the process

Touches

contributes or approves

Depends on

consumes its output

How SmartSuite helps, suite by suite

Each card is the persona record from that suite's Users tab.

How they use SmartSuite

How they use SmartSuite

Incident Coordination

‍Assigns responders and tracks progress to resolution.

Shift Oversight

‍Reviews workload and coverage across sites.

Escalation Management

‍Ensures high-severity incidents are handled promptly.

How they use the Cyber & IT Risk suite

Alert management

Prioritizes, categorizes, and routes alerts automatically based on severity.

Response automation

Executes pre-configured workflows for containment, communication, and escalation.

Dashboards

Reviews live SOC metrics like alert volume, time-to-response, and closure rates.

How they use the Cyber & IT Risk suite

Incident oversight

Tracks security incidents, escalations, investigations, and closure timelines.

Team coordination

Manages assignments and automated tasks for analysts and responders.

Performance tracking

Monitors SOC metrics such as MTTR, MTTC, and SLA adherence.

Suites that serve this role

How SmartSuite supports this role

Incident. Launches structured playbooks for high-priority incidents and breaches and tracks cross-functional actions during investigations.

Monitoring event. Prioritises, categorises and routes alerts automatically by severity.

Security. Documents root causes, lessons learned and improvement actions from post-incident reviews.

Reporting. Reviews live SOC metrics such as alert volume, time to response and closure rates.

Industry reference

NIST SP 800-61 Rev. 3 (2025) and NIST CSF 2.0's Detect and Respond functions define the function; MITRE ATT&CK underpins detection engineering and ISO/IEC 27035 covers incident management. Reporting clocks shape the playbooks: SEC four-business-day disclosure of material incidents, the 36-hour bank notification rule, NYDFS 72-hour notice, DORA and NIS2 staged reporting from 24 hours, HIPAA's 60-day breach rule and one-hour reporting to CISA for US federal agencies.

In their words

Related roles

Chief Information Security Officer

Chief Information Security Officer

See the role
Information Security Officer

Information Security Officer

See the role

See SmartSuite for your role

Start a free trial, or book a demo and we will walk through your role's workflows in SmartSuite.