Salmon Group
Salmon Group

SOC Manager

TLDR

Set monitoring, detection, and response across cloud, identity, endpoints, SaaS, and containerised environments using Sentinel, KQL, and MITRE ATT&CK.

Salmon is a technology-driven financial company building a banking and lending platform across Southeast Asia, starting in the Philippines.

We combine global fintech expertise with deep local market knowledge to make financial services simple, accessible, and useful for millions of people across the region.

7M+ app downloads. 2M+ monthly active users. 7,000+ partner stores. US$310M+ raised from leading global investors.

Manila-based, globally distributed, and hybrid-first — our team spans 45+ countries.

If you want to solve complex problems at scale and impact how millions of people access and manage money, come build with us.

Southeast Asia's fintech moment starts here.

About the role

You'll own Security Operations at group level across a regulated bank, consumer finance business, and shared technology platform, working directly with the Group CISO.

What you'll do

  • Set the direction for monitoring, detection, and response across cloud, identity, endpoints, SaaS, and containerised environments

  • Lead the technical response during significant cyber incidents and coordinate the teams involved

  • Select, manage, and hold MSSP/MDR providers accountable, deciding when to build in-house versus buy

What you'll own

  • Own the monitoring architecture and telemetry strategy: SIEM design, data sources, retention, forensic readiness, and telemetry cost management

  • Define the threat scenarios that matter most to Salmon, maintain detection coverage against them, and drive threat hunting and detection validation using MITRE ATT&CK

  • Own incident readiness — playbooks, escalation, forensic readiness, post-incident reviews, and tabletop exercises — and take part in complex investigations hands-on, including KQL and telemetry analysis

  • Own Vulnerability and Exposure Management, setting remediation priorities and expectations and governing the risk acceptance process for exceptions

  • Own the operational side of DLP and selected access governance controls, including SSO coverage, privileged access monitoring, and access reviews

  • Set priorities for the Security Operations team and vendors, define metrics on coverage, detection quality, response performance, and provider performance, and own technical readiness for BSP and PCI DSS assurance activities

What makes you a strong fit

  • Practical experience managing MSSP/MDR or other security service providers, including selection, negotiation, escalation, or replacement

  • Hands-on depth with Microsoft Sentinel and KQL, and experience with Microsoft Defender XDR / Defender for Endpoint

  • Working knowledge of Microsoft 365 security and audit telemetry, identity and access telemetry, and cloud security monitoring in complex environments

  • Experience with containerised platforms and workloads, and with SIEM data flows, retention, tiering, and cost management

  • Track record of independently assessing a security function, prioritising against risk and cost, and leading through serious incidents with incomplete information

  • Comfortable communicating with engineers, providers, the CISO, senior management, Risk, and Internal Audit

What we offer

Ownership and flexibility

  • Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)

  • Company-provided tools and equipment

Health and time off

  • Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits

  • Access to an internal mental health support specialist

  • 22 vacation days, Philippine public holidays, and 15 sick days

Growth and team experience

  • Opportunities to learn and share your expertise through internal expert meetups, external conferences, speaking opportunities, and industry publications

  • Company-sponsored trips to Manila to meet and work with your team in person

  • High-performing teams can earn a dedicated beach house week in Southeast Asia

We believe strong teams are built by people with different backgrounds, experiences, and points of view. Salmon is an equal opportunity employer, and we make hiring decisions based on skills, experience, and potential.

Benefits

Health Insurance

Medical insurance support for you and your family through co-funding or reimbursement, depending on your location and subject to policy limits

Home Office Stipend

Company-provided tools and equipment

Learning Budget

Opportunities to learn and share your expertise through internal expert meetups, external conferences, speaking opportunities, and industry publications

Beach house week in Southeast Asia

High-performing teams can earn a dedicated beach house week in Southeast Asia

Paid Time Off

22 vacation days, Philippine public holidays, and 15 sick days

Remote-Friendly

Fully remote work with core collaboration hours from 12:00 to 6:00 PM Manila time (UTC+8)

Wellness Stipend

Access to an internal mental health support specialist

Salmon Group is a dynamic consumer FinTech enterprise establishing a credit-led, technology-driven bank in Southeast Asia, with a focus on providing accessible financial services in the Philippines. Leveraging a team of seasoned finance and tech experts, Salmon is dedicated to enhancing financial inclusivity and convenience for millions of Filipinos, operating seamlessly year-round.

Employees
1-10 employees
Industry
business supplies and equipment
View company profile