07 Aug
|
iValue InfoSolutions
|
Bengaluru
07 Aug
iValue InfoSolutions
Bengaluru
Job Summary
We are seeking an experienced SOC Team Lead to lead our Security Operations Center (SOC) within the Managed Security Services (MSSP) business. This role is responsible for managing day-to-day SOC operations, leading a team of security analysts, ensuring high-quality incident detection and response, maintaining service delivery excellence, and building strong customer relationships. The ideal candidate will possess strong technical expertise, leadership skills, and operational experience in managing enterprise security operations.
About the Role
SOC Operations & Service Delivery
Lead day-to-day Security Operations Center (SOC) operations across multiple customer environments.
Ensure effective 24x7 security monitoring, incident detection, investigation, response, and resolution in accordance with defined SLAs.
Act as the primary operational escalation point for critical and high-severity security incidents.
Coordinate major incident response activities with customers, internal technical teams, and external stakeholders.
Monitor operational KPIs, service quality, and SLA compliance, driving continuous service improvements.
Review and approve incident reports, root cause analysis (RCA), and post-incident review documentation.
Ensure accurate incident documentation and timely communication throughout the incident lifecycle.
Security Monitoring & Threat Detection
Oversee continuous monitoring using SIEM, SOAR, EDR/XDR, and other security technologies.
Review, validate, and optimize SIEM correlation rules, detection use cases, alert tuning, and dashboards.
Lead threat hunting initiatives and support proactive identification of advanced threats.
Work closely with Threat Intelligence teams to operationalize Indicators of Compromise (IOCs) and emerging threat intelligence.
Ensure timely investigation and escalation of suspicious activities and security events.
Team Leadership
Lead, mentor, and manage a team of L1, L2, and L3 Security Analysts, fostering a culture of collaboration, accountability, and continuous learning.
Provide technical guidance and support during complex investigations and major security incidents.
Conduct performance reviews, one-on-one mentoring, and technical coaching sessions.
Manage analyst shift schedules, workload allocation, resource planning, and escalation management to ensure seamless 24x7 SOC coverage.
Identify training needs and support professional development through knowledge-sharing sessions, simulations, and tabletop exercises.
Review analyst investigations and incident handling to ensure quality, consistency, and adherence to operational procedures.
Customer & Stakeholder Management
Serve as the primary operational point of contact for assigned MSSP customers.
Conduct regular service review meetings and provide updates on incidents, threats, and SOC performance.
Present security metrics, operational reports, and improvement recommendations to customer stakeholders.
Build trusted relationships with customer security and IT teams by ensuring proactive communication and service excellence.
Coordinate with customers during incident response activities and major security events.
Process Improvement & Governance
Develop, maintain, and continuously improve SOC Standard Operating Procedures (SOPs), runbooks, and incident response playbooks.
Drive automation initiatives using SOAR platforms, scripting, and workflow optimization to improve operational efficiency.
Ensure adherence to internal security policies, operational processes, and customer-specific requirements.
Support internal and external audits by maintaining operational documentation and evidence.
Drive continual service improvement through metrics analysis, lessons learned, and operational reviews.
Cross-Functional Collaboration
Collaborate with Engineering, Threat Intelligence, Vulnerability Management, Cloud Security, IAM, and GRC teams to improve service delivery.
Support customer onboarding activities by defining monitoring requirements, security use cases, and operational processes.
Provide operational support during pre-sales discussions, customer transitions, and solution implementations.
About You
8-12 years of experience in Cybersecurity, including at least 3-5 years leading Security Operations Center (SOC) teams .
Strong experience managing Security Operations within an MSSP or enterprise SOC environment.
Proven experience leading teams of L1, L2, and L3 Security Analysts.
Strong expertise in Incident Response, Security Monitoring, Threat Detection, Threat Hunting, and Security Operations.
Hands-on experience with SIEM platforms such as Google SecOps, Microsoft Sentinel, Splunk Enterprise Security, IBM QRadar, or ArcSight.
Experience working with SOAR platforms and security automation technologies.
Hands-on experience with EDR/XDR solutions such as Microsoft Defender XDR, CrowdStrike Falcon, SentinelOne, Cortex XDR, or Trend Vision One.
Strong understanding of network security, endpoint security, cloud security, identity security, malware analysis, and attack methodologies.
Working knowledge of frameworks such as MITRE ATT&CK;, Cyber Kill Chain, NIST Cybersecurity Framework (CSF), ISO/IEC 27001, CIS Controls, PCI DSS, and SOC 2.
Experience with vulnerability management tools such as Qualys, Tenable, or Rapid7 is preferred.
Excellent analytical, troubleshooting, and decision-making skills with the ability to perform under pressure during major incidents.
Solid communication, stakeholder management, and customer-facing skills.
Preferred Certifications
CISSP - Certified Information Systems Security Professional
CISM - Certified Information Security Manager
GCIH - GIAC Certified Incident Handler
GCIA - GIAC Certified Intrusion Analyst
CEH - Certified Ethical Hacker
Microsoft Certified: Security Operations Analyst (SC-200)
Google Professional Cloud Security Engineer (Preferred)
Splunk Enterprise Security Certified Admin/Consultant (Preferred)
Technical Skills
Security Operations
Security Operations Center (SOC)
Incident Response
Threat Detection & Analysis
Threat Hunting
Malware Analysis
Root Cause Analysis (RCA)
Digital Forensics Fundamentals
Security Monitoring
Log Analysis
Security Event Correlation
Security Platforms
Google SecOps
Microsoft Sentinel
Splunk Enterprise Security
IBM QRadar
ArcSight
Microsoft Defender XDR
CrowdStrike Falcon
SentinelOne
Cortex XDR
Trend Vision One
Cortex XSOAR
Splunk SOAR
Security Technologies
SIEM
SOAR
EDR/XDR
IDS/IPS
Firewall Technologies
Email Security
Identity & Access Management (IAM)
Vulnerability Management
Endpoint Security
Network Security
Cloud Security
Governance & Frameworks
MITRE ATT&CK;
NIST Cybersecurity Framework (CSF)
ISO/IEC 27001
CIS Controls
PCI DSS
SOC 2
Soft Skills
Team Leadership
People Management
Customer Relationship Management
Incident Management
Communication & Presentation
Decision Making
Problem Solving
Stakeholder Management
Mentoring & Coaching
Time & Priority Management
Continuous Improvement
Key Performance Indicators (KPIs)
SLA compliance for incident response and resolution.
Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR).
Security incident handling quality and closure effectiveness.
Customer satisfaction (CSAT) and service delivery performance.
Reduction in false positives through SIEM tuning and automation.
Threat detection coverage and operational efficiency improvements.
Analyst productivity, training completion, and team development.
Quality and timeliness of operational reports and customer communications.
Compliance with internal governance, audit, and documentation requirements.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 SOC Team Lead (Bengaluru)
🏢 iValue InfoSolutions
📍 Bengaluru