Position Overview:
Position: SOC L3 Lead / Subject Matter Expert (SME)
Experience: 7+ years of core cybersecurity operations experience
Core Focus: Hands-on Microsoft Security stack management, root-cause analysis, advanced threat investigation, and remediation orchestration.
Key Responsibilities:
Advanced Threat Investigation &
RCA: Lead deep-dive investigations into complex incidents escalated by L1/L2 analysts; perform comprehensive Root Cause Analysis (RCA); track adversary behavior using frameworks like MITRE ATT&CK.;
Microsoft Security Stack Execution: Architect, configure, and optimize Microsoft Sentinel SIEM/XDR settings; develop advanced KQL queries for custom analytic rules and threat hunting; build automated playbooks within Microsoft Sentinel and Azure Logic Apps to optimize SOAR capabilities.
Remediation &
Transition Planning: Design strategic transition plans to migrate legacy SOC operations to modern frameworks; formulate containment strategies during active high-priority incidents; provide blueprints to engineering teams for long-term threat neutralization.
Leadership &
Stakeholder Management: Act as the technical SME and contact point for enterprise customers; mentor L1 and L2 security analysts; maintain documentation for incident playbooks, post-mortem reports,
and compliance audits.
Required Skills &
Qualifications:
Technical Expertise: Hands-on mastery of Microsoft Sentinel, Azure Logic Apps, and the Microsoft Defender suite.
Query Languages: Exceptional proficiency in writing and tuning KQL queries.
Automation: Proven experience building complex conditional workflows and integrations in Azure DevOps or Logic Apps.
Incident Response: Deep knowledge of network protocols, operating system forensics (Windows/Linux), and cloud security vectors.
Qualified Attributes: Exceptional analytical mind, flexibility to work between the corporate office and client sites, and clear communication skills.
Preferred Certifications:
Microsoft Certified: Security Operations Analyst Associate (SC-200)
Microsoft Certified: Azure Security Engineer Associate (AZ-500)
GIAC Certified Incident Handler (GCIH) or Certified Information Systems Security Skilled (CISSP)
Job Types: Full-time, Permanent
Pay: ₹1,800,000.00 - ₹2,500,000.00 per year
Ability to commute/relocate
Bengaluru, Karnataka: Reliably commute or planning to relocate before starting work (Required)
Experience
Cybersecurity: 6 years (Required)
Work Location: In person
📌 Cyber Security Lead Bengaluru
🏢 [email protected]
📍 Bengaluru