Core Operational Responsibilities
Oversee and follow up on SOC alerts generated across various monitored log sources.
Manage the investigation of high rated security alerts.
Lead continuous SIEM upkeep, including the creation and maintenance of custom use-cases to ensure comprehensive security monitoring.
Manage SIEM rule testing, use-case upgradation, log stoppages, and general SOC activities.
Coordinate with SOC MSSP partner, and internal stakeholders to reduce false positives, enhance monitoring coverage and integrate recent technologies.
Ensure log validation and use-case reviews are established as a continuous operational process.
Develop KRIs and KPIs to track SOC efficiency and effectiveness.
Drive incident response by establishing frameworks, documentation, processes and playbooks
Work on SOAR automations for reducing response times
Ensure compliance to regulatory requirements related to SOC
Project Management and Behavioural Traits
Provide regular monthly updates to senior management regarding threat trends, alert counts,
and the security posture of the organization.
Independently track and close security issues and operational bottlenecks by coordinating with IT and Cloud teams.
Demonstrate an ability to drive security outcomes and meet assigned milestones.
Exhibit positive communication skills, with the ability to explain complex security observations and technical problems to diverse stakeholders.
Proficient in MS Office, specifically using Excel for detailed daily/weekly trackers and PowerPoint for management-level reporting.
Necessary Qualifications
Bachelors in relevant fields like Computer Science, Information Technology, or a related Engineering field.
Skilled Certifications: Relevant certifications that will support .
Experience: Minimum of 10 years of overall experience with a minimum of 6 years experience on SOC operations.
Please note this is a WFO role. Please apply only if you are comfortable to travel to M