05 Aug
|
HCL Technologies
|
Bengaluru
05 Aug
HCL Technologies
Bengaluru
Tower Lead - Security Investigations, SIEM
Experience: 5 to 10 years
Location: Bengaluru, India
Skills: SIEM, SOAR, Splunk, Microsoft Sentinel, XSIAM, EDR, XDR, Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto, KQL, SPL, advanced hunting queries, Log and telemetry correlation, Windows, Linux, macOS internals, Identity systems, AD, Entra ID, Network fundamentals, attack techniques, MITRE ATT&CK;, NIST 800-61, GCIH, GCIA, GCED, SC-200, AZ-500, CISSP, CISM
Job Summary
Responsible for leading the investigation, containment, eradication, and recovery of security incidents across enterprise environments. This role acts as the final escalation point within the SOC, handling high‑severity and complex incidents, performing forensic analysis, coordinating response actions, and driving post‑incident improvements to detections and controls.
Key Responsibilities
1. Ensure Timely Resolution Of Escalations By Leading Security Event Investigations Through Soar And Siem Tools, Adhering To Agreed Sla Norms To Deliver Optimal Outcomes.
2. Oversee The Generation Of Tower-Level Ee And En Revenue By Implementing Strategic Initiatives And Optimizing Resource Allocation Within The Support Operations.
3.
Validate And Oversee Operational Hygiene By Reviewing Reports And Ensuring That Services Are Delivered In Accordance With The Statement Of Work (Sow).
4. Promote Positive Custom
Skill Requirements
Robust experience with SIEM/SOAR platforms (Splunk, Microsoft Sentinel, XSIAM)
Hands‑on EDR/XDR experience (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto)
Proficiency in: KQL / SPL / advanced hunting queries
Log and telemetry correlation
Deep understanding of: Windows, Linux, macOS internals
Identity systems (AD, Entra ID)
Network fundamentals and attack techniques
Familiarity with: MITRE ATT&CK;
NIST 800‑61 (Incident Response)
Experience & Qualifications
5–10 years in SOC, Incident Response, or Cyber Defense roles
Experience operating in 24×7 SOC environments
Certifications (preferred): GCIH, GCIA, GCED, SC‑200, AZ‑500, CISSP
Other Requirements
1. Optional But Valuable Certifications: Certified Information Systems Security Professional (Cissp), Certified Information Security Manager (Cism), And Security Operations Center (Soc) Management Certification
📌 Tower Lead Security Investigations, SIEM (Bengaluru)
🏢 HCL Technologies
📍 Bengaluru