Position summary:
Senior L2 leading major-incident technical response until L3 engagement, owning the detection-content and tuning program day-to-day, and acting as deputy to the L3 Operations Lead.
Key responsibilities
- Lead technical response on major incidents (security and infrastructure) until L3 command engages.
- Own the detection-content backlog and tuning program execution with the L3 lead.
- Approve and execute high-risk changes; run problem management to eliminate recurring incidents.
- Own log-pipeline integration health: collectors, GCP Pub/Sub feeds, custom sources (Redfish listener,
- Aravolta webhooks, Hubble exporter) with escalation into engineering.
- Cross-train the L1 bench across towers; deputize for the L3 lead.
- Drive shift-quality audits and post-incident reviews.
Must-have
- 8–11 years with prior senior/lead experience in SOC or NOC and genuine cross-domain fluency.
- Incident command capability; deep SIEM content and query skills.
- Advanced network troubleshooting; automation mindset.
Positive-to-have
- GCIH/GCIA, JNCIP, or CCIE written.
- MSSP/managed-services background; AI-SOC tooling exposure.
📌 Security Operations Lead (Pune)
🏢 Gruve
📍 Pune