05 Aug
|
Important Business
|
Chennai
05 Aug
Important Business
Chennai
Position: Cybersecurity – SOC Lead (AI & Automation)
Location: Chennai - Onsite/Hybrid/Remote
Shift Timing: 5.30PM - 2.30AM IST (US Eastern Time)
Engagement Type: Full Time
Role Summary:
Lead offshore SOC execution for Customer,
combining operational leadership, detection governance, case quality oversight,
and practical automation. This role must drive disciplined day-to-day
performance while improving the use of built-in AI / automation features across
the CLW security stack without sacrificing analyst judgement, traceability, or
investigation fidelity.
Key Responsibilities:
- Lead the offshore SOC pod across L1 and L2 activities, ensure queue
health, review investigation quality, and maintain strong stakeholder alignment
with Customer security leadership.
- Own daily operational governance including case quality, severity
calibration, shift handoffs, SLA adherence, and escalation discipline for major
incidents.
- Drive continuous improvement in Splunk ES / Mission Control
operations, detection logic review, alert noise reduction, and visibility gap
identification.
- Coordinate across CrowdStrike, Proofpoint, Qualys, Palo Alto,
Dragos, ServiceNow, and automation workflows to improve response effectiveness.
- Translate technical events into concise business risk language for
U.S. stakeholders and support weekly service reviews, KPI reporting, and
corrective action tracking.
- Promote responsible use of AI-assisted summarization, enrichment,
and workflow acceleration within approved guardrails.
Tool Workplace:
Splunk ES / Mission Control, CrowdStrike,
Qualys, Proofpoint, Palo Alto, Dragos, ServiceNow, Teams, M365 / Entra context,
automation / SOAR capabilities where approved.
Required Experience & Skills:
- Strong security operations leadership experience, including direct
management of analysts or provider teams in a 24x7 or follow-the-sun model.
- Advanced proficiency in Splunk-based SOC operations and solid
working knowledge of endpoint, network, email, and vulnerability telemetry.
- Ability to coach analysts, review investigations, and enforce
consistent case quality and operational rigor.
- Robust executive-facing communication and ability to run governance
reviews with facts, metrics, and remediation actions.
- Experience working with offshore teams serving U.S.-based
stakeholders.
Preferred Qualifications:
- Manufacturing / OT security exposure, especially where
corporate-to-plant visibility and escalation discipline matter.
- Experience with ServiceNow workflows, playbook optimization, and
approved automation / SOAR patterns.
- Awareness of MITRE ATT&CK-aligned; detection engineering and
risk-based incident prioritization.
Offshore India Operating Model:
- Work as an embedded offshore team member supporting U.S.-based
stakeholders with dependable daily communication, disciplined documentation,
and clear ownership of actions and follow-ups.
- Operate with strong handoff hygiene across shifts, including concise
status updates, ticket notes, evidence capture, and risk-based escalation to Customer
leads.
- Support a manufacturing-aware operating model where uptime, safety,
OT change sensitivity, and controlled execution are treated as essential
requirements.
- Use ServiceNow and Microsoft Teams effectively for workflow
coordination, incident tracking, approvals, and stakeholder communication.
- Be prepared to align with late afternoon / evening IST overlap with
U.S. Eastern time and participate in critical incident bridges when required.
Success Measures:
- Stable, measurable SOC operations with better case quality, tighter
escalation hygiene, and improved visibility coverage.
- Documented reduction in alert noise and stronger detection fidelity
across the CLW stack.
- Clear governance cadence and dependable offshore team performance.
📌 Cybersecurity SOC Lead (AI & Automation) (Chennai)
🏢 Important Business
📍 Chennai