Position Overview:
- Position: SOC L3 Lead / Subject Matter Expert (SME)
- Experience: 7+ years of core cybersecurity operations experience
- Core Focus: Hands-on Microsoft Security stack management, root-cause analysis, advanced threat investigation, and remediation orchestration.
Key Responsibilities:
- Advanced Threat Investigation &
- RCA: Lead deep-dive investigations into complex incidents escalated by L1/L2 analysts; perform comprehensive Root Cause Analysis (RCA); track adversary behavior using frameworks like MITRE ATT&CK.;
- Microsoft Security Stack Execution: Architect, configure, and optimize Microsoft Sentinel SIEM/XDR environments; develop advanced KQL queries for custom analytic rules and threat hunting; build automated playbooks within Microsoft Sentinel and Azure Logic Apps to optimize SOAR capabilities.
- Remediation &
- Transition Planning: Design strategic transition plans to migrate legacy SOC operations to modern frameworks; formulate containment strategies during active high-priority incidents; provide blueprints to engineering teams for long-term threat neutralization.
- Leadership &
- Stakeholder Management: Act as the technical SME and contact point for enterprise customers; mentor L1 and L2 security analysts; maintain documentation for incident playbooks, post-mortem reports,
and compliance audits.
Required Skills &
- Qualifications:
- Technical Expertise: Hands-on mastery of Microsoft Sentinel, Azure Logic Apps, and the Microsoft Defender suite.
- Query Languages: Exceptional proficiency in writing and tuning KQL queries.
- Automation: Proven experience building complex conditional workflows and integrations in Azure DevOps or Logic Apps.
- Incident Response: Deep knowledge of network protocols, operating system forensics (Windows/Linux), and cloud security vectors.
- Qualified Attributes: Exceptional analytical mind, flexibility to work between the corporate office and client sites, and clear communication skills.
Preferred Certifications:
- Microsoft Certified: Security Operations Analyst Associate (SC-200)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
- GIAC Certified Incident Handler (GCIH) or Certified Information Systems Security Professional (CISSP)
Job Types: Full-time, Permanent
Pay: ₹1,800,000.00 - ₹2,500,000.00 per year
Ability to commute/relocate
- Bengaluru, Karnataka: Reliably commute or planning to relocate before starting work (Required)
Experience
- Cybersecurity: 6 years (Required)
Work Location: In person
📌 Cyber Security Lead (Bengaluru)
🏢 [email protected]
📍 Bengaluru