Roles &
Responsibilities :
- Lead and manage the Security Operations Center (SOC) function, ensuring 24x7 monitoring, detection, investigation, and response to cybersecurity incidents.
- Own the operational security posture by managing threat detection, incident response, vulnerability management, and security monitoring processes.
- Develop and maintain SOC processes, playbooks, escalation procedures, and incident response workflows aligned with industry standards.
- Lead a team of security analysts, engineers, and incident responders; provide mentoring, coaching, and performance management.
- Monitor and analyze security alerts from SIEM, EDR, IDS/IPS, firewalls, cloud security platforms, and other security tools.
- Drive incident investigations, root cause analysis, containment, remediation, and post-incident reviews.
- Manage threat intelligence operations, including identifying emerging threats, indicators of compromise (IOCs), and attack patterns.
- Improve SOC maturity through automation, SOAR implementation, process optimization, and operational metrics.
- Define and track SOC KPIs/KRIs, including incident response time, detection effectiveness, false positives, and threat trends.
- Collaborate with infrastructure, cloud, application, and compliance teams to strengthen security controls.
- Support security audits, regulatory compliance requirements, and risk assessments.
- Ensure alignment with cybersecurity frameworks such as ISO 27001, NIST CSF, MITRE ATT&CK;, and industry best practices.
- Coordinate with external vendors, managed security service providers (MSSPs), and incident response partners when required.
- Prepare executive-level security reports, dashboards, and risk updates for senior management.
Preferred Candidate Profile:
- Experience: 815 years of experience in cybersecurity, with significant experience leading SOC operations, incident response, or security monitoring teams.
- Proven experience managing a SOC team in an enterprise environment, preferably in UAE/GCC markets.
- Strong hands-on experience with:
1.
SIEM platforms: Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, LogRhythm, or similar
2.
EDR/XDR solutions: CrowdStrike, SentinelOne, Microsoft Defender, Palo Alto Cortex, etc.
- Threat intelligence and security analytics platforms
- Vulnerability management tools
- Cloud security monitoring (Azure/AWS/GCP)
- Strong understanding of:
- Security incident lifecycle management
- Threat hunting methodologies
- Malware analysis fundamentals
- Network security concepts
- Identity and access management (IAM)
- Security architecture and controls
- Experience developing SOC processes, operational procedures, and automation workflows.
- Ability to lead investigations involving advanced persistent threats (APTs), phishing, ransomware, and insider threats.
- Robust stakeholder management skills with the ability to communicate security risks to technical and business leadership.
- Experience working with compliance and regulatory requirements such as ISO 27001, NIST, PCI-DSS, GDPR, UAE regulatory frameworks, or similar.
Preferred Certifications :
- CISSP (Certified Information Systems Security Professional)
- CISM (Certified Information Security Manager)
- GIAC certifications (GCIH, GCIA, GCFA, etc.)
- OSCP / OSCE
- CEH (preferred but not mandatory)
- CCSP / Azure Security Engineer / AWS Security Specialty
- ISO 27001 Lead Auditor / Lead Implementer
📌 Security Operations Lead - SIEM Tools (India)
🏢 Good
📍 India