Position: Cybersecurity Lead
Location: Pune, India
Work Mode: On-site / Work from Office
Working Days: Monday to Friday
Shift Timing: 5:30 PM to 2:30 AM IST (aligned to Canada Eastern business hours)
Client Support: International clients, primarily based in Canada
Reports to: VP Engineering & Operations (Canada), with dotted-line coordination with the Pune Site Director.
Company: Pathway Communications (Pune Office)
About Pathway Communications
Pathway Communications is a managed IT services, cybersecurity, ISP, VoIP and cloud services provider headquartered in Markham, Ontario, operating in Canada since 1995. Our Pune office delivers 24x7 technical operations for our North American clients across Managed IT (ITO), Cybersecurity/SOC, Service Desk (TSD) and Engineering.
We are seeking to hire a senior cybersecurity operations leader to join us in our Pune office. This is a hands-on leadership role responsible for managing cybersecurity operations, SOC delivery, incident response, threat detection, client communication and continuous improvement for global environments, with meaningful involvement in project delivery, solution design, and pre-sales support.
This role is suited to a solid technical leader who can guide teams, improve security operations, handle escalations, use modern security and AI tools effectively, contribute to client-facing project and pre-sales work, and keep complex client environments secure and resilient.
Key Responsibilities
•Lead the India-based SOC and cybersecurity operations team supporting international clients.
•Oversee 24x7 managed cybersecurity operations including monitoring, triage, incident response, escalation and reporting.
•Act as the senior technical escalation point for high-severity incidents such as ransomware, phishing, malware, credential compromise, cloud compromise, data exfiltration and insider threats.
•Manage the full incident response lifecycle including detection, analysis, containment, eradication, recovery, root cause review and lessons learned.
•Drive SIEM, SOAR and XDR operations on our primary platform Rapid7 InsightIDR including log onboarding, alert tuning, dashboards, automation playbooks and detection use cases. Exposure to Microsoft Sentinel, Splunk or similar is an asset.
•Lead proactive threat hunting using MITRE ATT&CK;, threat intelligence, endpoint telemetry, cloud logs, identity signals and network indicators.
•Oversee vulnerability management using Rapid7 InsightVM including risk prioritization, remediation tracking, patch coordination and exposure reporting.
•Monitor and improve endpoint, network, cloud, email, identity, firewall, IDS/IPS, DLP, IAM, EDR, XDR and PAM security controls, including day-to-day operations on our primary endpoint stack (Microsoft Defender for Endpoint / Defender XDR and Rapid7 InsightIDR endpoint agents).
- Support cloud security operations across Azure, AWS or GCP, including IAM risks, suspicious activity detection, cloud posture and workload protection.
- Manage client communication, governance calls, incident updates, monthly security reviews,
SLA/KPI reporting and executive-level summaries.
- Maintain SOC runbooks, SOPs, escalation matrices, shift handovers, documentation standards and ticket quality.
- Mentor analysts, build technical depth across the team, review performance and improve team accountability.
- Improve SOC maturity through automation, AI-assisted workflows, false-positive reduction, process improvement and measurable MTTA/MTTR improvement.
- Use AI tools responsibly in day-to-day work for threat research, investigation summaries, detection logic, reporting, documentation, automation ideas and productivity, while maintaining confidentiality and data security.
- Support governance, audit and compliance requirements such as ISO 27001, SOC 2, NIST, CIS Controls,
PHIPA (Ontario healthcare clients) and client-specific security obligations.
- Contribute to cybersecurity project delivery for new and existing clients, including solution design,
security architecture input, technical implementation oversight and hand-off to steady-state operations.
- Support pre-sales and business development activities including responses to RFPs and RFIs, solution scoping, effort estimation, Statement of Work (SOW) input, client discovery sessions and technical demonstrations.
- Contribute to the evolution of Pathway’s cybersecurity service catalogue, evaluate new tools and technologies, and provide input to vendor selection and our Vendor of Record (VOR) program.
- Collaborate closely with the Managed IT (ITO), Service Desk (TSD) and Engineering teams on shared client environments to ensure consistent service delivery and cross-functional alignment.
Requirements
This is an important senior position and requires the following:
- 10+ years of cybersecurity experience, including 4+ years in SOC leadership, cybersecurity operations,
MDR/MSSP or enterprise security management.
- Strong experience working in a 24x7 security operations environment with global or international client exposure.
- Hands-on experience with SIEM/SOAR tools . Direct experience with Rapid7 InsightIDR and Microsoft
Sentinel / Defender XDR is strongly preferred; exposure to Splunk, QRadar, LogRhythm or Cortex
XSIAM/XSOAR is an asset.
- Hands-on experience with EDR/XDR tools . Direct experience with Microsoft Defender for Endpoint /
Defender XDR and Rapid7 InsightIDR endpoint agents is strongly preferred; exposure to CrowdStrike
Falcon, Bitdefender, SentinelOne, Cortex XDR, Sophos or Carbon Black is an asset.
- Strong understanding of incident response, threat hunting, detection engineering, malware/phishing analysis, vulnerability management, risk management and log analysis.
- Good understanding of cloud and identity security across Azure, AWS, GCP, Microsoft Entra ID/Azure
AD, IAM, MFA, CASB,
CSPM and CWPP.
- Good exposure to network and security technologies such as firewalls, IDS/IPS, VPN, WAF, DNS security, email security, DLP, NAC, PAM and vulnerability scanners.
- Experience managing client escalations, critical incidents, service reviews, dashboards, reporting and
SLA-driven delivery.
- Strong working knowledge of ITSM processes (incident, problem, change, request, service-level and knowledge management) and comfort operating within a ticket-driven managed services environment.
- Demonstrated involvement in pre-sales and project work, including RFP contributions, solution scoping,
technical write-ups and client-facing presentations.
- Proficiency with Microsoft 365 productivity apps (Word, Excel, PowerPoint) for producing reports,
Statements of Work, technical documentation and client presentations.
- Excellent written and spoken English, with strong client communication and stakeholder management skills.
- Ability to work on site in Pune during the 5:30 PM to 2:30 AM IST shift.
Education
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering or equivalent practical experience. Advanced technical certifications will be an advantage.
Preferred Certifications
- CISSP, CISM, CCSP, GIAC/GCIH/GCIA/GCFA, CompTIA Security+, CEH or ISO 27001 LA/LI.
- Microsoft Cybersecurity Architect Expert (SC-100), Microsoft Security Operations Analyst Associate (SC-
200), Microsoft Azure Security Engineer Associate (AZ-500) or equivalent Microsoft security certifications are strongly preferred given our platform stack. Additional certifications from Rapid7 (InsightIDR /
InsightVM), CrowdStrike, Palo Alto, Cisco or Fortinet are an asset.
Preferred Attributes
- Strong ownership mindset and calm decision-making during incidents.
- Ability to balance leadership responsibilities with hands-on technical work.
- Experience with automation, scripting, AI-assisted cybersecurity operations or analyst productivity tools.
- Continuous-improvement mindset with the ability to improve processes, people capability and service quality.
- Comfort operating across managed services, project delivery and pre-sales contexts, and moving fluidly between technical, client-facing and commercial conversations.
Compensation
Market-leading salary, performance-linked incentives and benefits.
Why Join Us
This is not only a supervisory role. It is a senior technical leadership position with significant management responsibility and visibility. You will help shape cybersecurity operations, improve SOC maturity, mentor teams and support global clients in a fast-moving managed services environment, while also contributing directly to solution design, project delivery and new business wins.
If you are seeking a role with strong learning opportunities, meaningful ownership, global exposure and scope to make significant contributions, this position may be for you.
To Apply
Please send your resume to
[email protected] with current compensation, expected compensation, notice period and current location.
📌 Cyber Security Lead (Pune)
🏢 Pathway Communications
📍 Pune