1. Role Summary
We are seeking a hands-on Assistant Manager Information Security with a strong Security Operations (SecOps) background to strengthen our cyber defence capability. The role sits within the Information Security function and works closely with the Security Operations Centre (SOC) to detect, investigate and respond to security threats across the enterprise. The ideal candidate combines deep operational expertise across leading cybersecurity technologies with the maturity to mentor analysts, drive threat detection use-cases, and support the CISO in continuously improving the organisation's security posture.
2. Key Responsibilities
Security Operations & Monitoring
- Oversee day-to-day SOC operations, ensuring analysis of security alerts across the setting.
- Lead investigation and response for security incidents, coordinating containment, eradication and recovery activities.
- Identify indicators of compromise (IoCs) and attacker behaviour.
- Tune, develop and maintain SIEM correlation rules, detection use-cases and alerting logic to reduce false positives and improve detection coverage.
Incident Response & Threat Management
- Conduct root-cause analysis and post-incident reviews, documenting lessons learned and driving corrective actions.
- Leverage threat intelligence to proactively hunt for threats and anticipate emerging attack techniques (MITRE ATT&CK; aligned).
- Coordinate with IT, infrastructure and application teams to remediate vulnerabilities and misconfigurations.
Technology, Governance & Team Enablement
- Administer and optimise cybersecurity tools including SIEM, SOAR, EDR/XDR, firewalls, IPS/IDS, DLP, email and web security gateways.
- Support security automation (SOAR) initiatives to streamline repetitive response actions and improve mean-time-to-respond (MTTR).
- Prepare and present SOC dashboards, metrics and periodic reports for management and the CISO.
- Ensure alignment with regulatory and compliance requirements (e.g., ISO 27001, RBI / SEBI / IRDAI guidelines, CERT-In, and internal policies).
. Required Skills & Experience
- 4 7 years of experience in Information / Cyber Security with a strong Security Operations focus.
- Hands-on expertise with leading SIEM platforms (Crowdstrike NG SIEM).
- Practical experience with EDR/XDR solutions (e.g., CrowdStrike, Microsoft Defender, SentinelOne) and endpoint threat response.
- Solid understanding of network security technologies — firewalls, IPS/IDS, proxy, VPN, WAF.
- Working knowledge of SOAR platforms and security automation concepts.
- Strong grasp of incident response methodologies, MITRE ATT&CK; framework, cyber kill chain and threat intelligence.
- Familiarity with cloud security concepts across Azure, AWS or GCP environments.
- Understanding of operating systems (Windows / Linux), networking fundamentals (TCP/IP, DNS, HTTP) and common attack vectors.
- Strong analytical, problem-solving and communication skills, with the ability to work under pressure during active incidents.
📌 Assistant Manager Information Security (Mumbai)
🏢 Trent
📍 Mumbai