07 Aug
|
KPMG Assurance and Consulting Services
|
Mumbai
07 Aug
KPMG Assurance and Consulting Services
Mumbai
Role Summary
We are seeking an experienced SOC Manager with strong hands-on expertise in Splunk, Cyber Threat Intelligence (CTI), and Threat Hunting (TH) to lead and enhance our Security Operations Center (SOC). The ideal candidate will have 8+ years of cybersecurity experience, with proven capabilities in managing security operations, incident response, threat intelligence programs, and proactive threat hunting initiatives.
Key Responsibilities
Security Operations Management
- Lead and manage daily SOC operations, ensuring effective monitoring, detection, analysis, and response to security incidents.
- Oversee security event monitoring, incident triage, investigation, containment, eradication, and recovery activities.
- Develop and improve SOC processes, playbooks, runbooks, and operational metrics.
- Mentor and guide SOC analysts across L1, L2, and L3 functions.
Splunk Administration & Engineering
- Design, implement, and maintain Splunk infrastructure and security use cases.
- Develop and optimize SIEM correlation rules, dashboards, alerts, reports, and threat detection content.
- Integrate multiple security tools and data sources into Splunk.
- Analyze logs and security events to identify indicators of compromise (IOCs) and suspicious activities.
Cyber Threat Intelligence (CTI)
- Lead the CTI program by collecting, analyzing, and operationalizing threat intelligence.
- Monitor emerging threats, vulnerabilities, malware campaigns, and threat actor activities.
- Translate intelligence into actionable detection rules and response strategies.
- Develop intelligence reports and communicate threat insights to stakeholders and leadership.
Threat Hunting
- Conduct proactive threat hunting activities across enterprise environments.
- Identify advanced threats, anomalous behaviors,
and potential compromise indicators.
- Leverage MITRE ATT&CK; framework and threat intelligence to develop hunting hypotheses.
- Collaborate with incident response teams for investigation and remediation.
Incident Response & Security Governance
- Lead major incident investigations and coordinate response efforts.
- Perform root cause analysis and recommend remediation measures.
- Ensure compliance with security standards, policies, and best practices.
- Develop SOC KPIs, reporting dashboards, and executive-level presentations.
Required Skills & Qualifications
- 8+ years of experience in Cybersecurity, Security Operations, or Incident Response.
- Strong hands-on experience with Splunk SIEM administration, use-case development, and content tuning.
- Proven expertise in Cyber Threat Intelligence (CTI) and intelligence lifecycle management.
- Hands-on experience in Threat Hunting across endpoint, network, and cloud environments.
- Robust understanding of:
- SIEM, SOAR, EDR/XDR technologies
- Incident Response methodologies
- MITRE ATT&CK; Framework
- Cyber Kill Chain
- Network Security & Security Monitoring
- Malware Analysis concepts
- Threat Actor TTPs
- Experience with log analysis, IOC management, and threat detection engineering.
- Strong leadership, stakeholder management, and communication skills.
Preferred Qualifications
- Certifications such as:
- Splunk Enterprise Security Certified Admin
- CISSP
- GIAC (GCIH, GCIA, GCFA, GCTI)
- CEH
- CompTIA Security+
- Experience with cloud security monitoring (Azure, AWS, GCP).
- Exposure to SOAR platforms and automation workflows.
Key Competencies
- Security Operations Leadership
- Splunk Engineering & Administration
- Cyber Threat Intelligence
- Threat Hunting
- Incident Response
- Detection Engineering
- Team Management
- Stakeholder Communication
📌 Security Operation Manager - SIEM ( Splunk) - Theat Hunting / CTI (Mumbai)
🏢 KPMG Assurance and Consulting Services
📍 Mumbai