Terralogic is hiring a SOC L3 Lead/SME (Cybersecurity Operations) for our Bangalore office to spearhead advanced threat detection, incident response, and security automation.
Position Overview
- Position: SOC L3 Lead / Subject Matter Expert (SME)
- Experience: 7+ years of core cybersecurity operations experience
- Location: Bangalore, Karnataka
- Core Focus: Hands-on Microsoft Security stack management, root-cause analysis, advanced threat investigation, and remediation orchestration.
Key Responsibilities
Advanced Threat Investigation & RCA
- Lead deep-dive investigations into complex, multi-stage security incidents escalated by L1/L2 analysts.
- Perform comprehensive Root Cause Analysis (RCA) to identify underlying vulnerabilities and system gaps.
- Track adversary behavior across the network using cyber threat intelligence frameworks (e.g., MITRE ATT&CK;).
Microsoft Security Stack Execution
- Architect, configure, and optimize Microsoft Sentinel SIEM/XDR environments.
- Develop advanced KQL (Kusto Query Language) queries for custom analytic rules, threat hunting, and watchlists.
- Build automated playbooks within Microsoft Sentinel and Azure Logic Apps to optimize SOAR capabilities and reduce Mean Time to Respond (MTTR).
Remediation & Transition Planning
- Design strategic transition plans to migrate legacy SOC operations into modern, automated frameworks.
- Formulate containment and remediation strategies during active high-priority incidents.
- Provide actionable blueprints to engineering teams for long-term threat neutralization and system hardening.
Leadership & Stakeholder Management
- Act as the technical SME and point of contact for enterprise customers, handling in office deployments and crisis communication when required.
- Mentor and upscale L1 and L2 security analysts through technical workshops and incident simulations.
- Maintain rigorous documentation for incident playbooks, post-mortem reports, and compliance audits.
Qualifications
Technical Expertise
- Expertise: Hands-on mastery of Microsoft Sentinel, Azure Logic Apps, and Microsoft Defender suite.
- Query Languages: Exceptional proficiency in writing and tuning KQL queries.
- Automation: Proven experience building complex conditional workflows and integrations in Azure DevOps or Logic Apps.
- Incident Response: Deep knowledge of network protocols, operating system forensics (Windows/Linux), and cloud security vectors.
Professional Attributes
- Problem Solving: Exceptional analytical mind capable of connecting disparate security events.
- Flexibility: Willingness to work dynamically between the Terralogic corporate office and client sites.
- Communication: Clear verbal and written skills to translate technical cyber risks to non-technical client stakeholders.
Preferred Skills but not mandatory
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- GIAC Certified Incident Handler (GCIH) or Certified Information Systems Security Professional (CISSP)