26 Aug
|
Good Co India
|
India
26 Aug
Good Co India
India
Role & responsibilities
- Lead and manage 247 Security Operations Center (SOC) activities, ensuring continuous monitoring, detection, investigation, and response to security threats.
- Manage SOC analysts and security engineers across L1/L2/L3 operations, including staffing, shift planning, performance management, and capability development.
- Establish and maintain security monitoring, incident response, escalation, and investigation processes.
- Oversee security incidents from detection through containment, eradication, recovery, and post-incident review.
- Drive effective use and optimization of SIEM, SOAR, EDR/XDR, threat intelligence, and security analytics platforms.
- Develop and continuously improve detection rules, use cases, correlation logic, and threat-hunting processes.
- Lead threat hunting and proactive detection activities using frameworks such as MITRE ATT&CK.;
- Coordinate major incident response and act as the escalation point for high-severity cybersecurity incidents.
- Monitor SOC performance through SLAs, KPIs, incident metrics, MTTD, MTTR, alert volumes, false-positive rates, and detection coverage.
- Ensure effective integration of SOC operations with vulnerability management, threat intelligence, network security, cloud security, and IT teams.
- Conduct regular security incident reviews, root-cause analysis, and lessons-learned exercises.
- Ensure compliance with relevant security policies, regulatory requirements, audit controls, and organizational security standards.
- Manage relationships with MSSPs, security vendors, technology partners, and internal stakeholders.
- Prepare security operations reports, dashboards, and risk summaries for CISO and senior management.
- Drive SOC automation and process improvements to improve detection accuracy, response speed, and operational efficiency.
Preferred candidate profile
- 5 to 10 years of experience in cybersecurity, SOC operations, security monitoring, incident response, or information security, with demonstrated experience leading SOC teams.
- Strong hands-on experience with SIEM, SOAR, EDR/XDR, threat intelligence, incident response, and security monitoring technologies.
- Proven experience managing 247 SOC operations, including shift teams, incident escalation, SLAs, and operational governance.
- Robust understanding of network security, endpoint security, cloud security, identity security, malware, vulnerabilities, and common attack techniques.
- Experience developing and tuning SIEM correlation rules, detection use cases, alerts, dashboards, and security automation workflows.
- Strong knowledge of MITRE ATT&CK;, incident-response lifecycle, threat hunting, digital forensics, and security operations best practices.
- Experience handling and coordinating P1/P2 security incidents and cyber crisis situations.
- Strong analytical and investigative skills with the ability to make sound decisions under pressure.
- Demonstrated ability to lead, coach, mentor, and develop SOC analysts and security engineers.
- Strong stakeholder-management and communication skills, including the ability to present cybersecurity risks and incidents to CISO/CIO-level leadership.
- Experience managing MSSPs, security vendors, SOC tools, budgets, and service-level agreements is an advantage.
- Working knowledge of Python, PowerShell, or other scripting/automation technologies is preferred.
- Bachelor's degree in Computer Science, IT, Cybersecurity, Information Security, Electronics, or a related technical discipline.
- Relevant certifications such as CISSP, CISM, GCIH, GCIA, GCED, CEH, Security+, CCSP, or leading SIEM/EDR certifications are preferred.
- Strong security leadership, ownership, problem-solving, communication, and crisis-management capabilities.
📌 SOC Manager (India)
🏢 Good Co India
📍 India