11 Sep
|
HCLSoftware
|
Bengaluru
11 Sep
HCLSoftware
Bengaluru
Director of Cybersecurity Operations /n Location: India - NCR/Bangalore/Remote /n About the Role : HCL Software is seeking an accomplished security leader as Director of Cybersecurity Operations to head our cybersecurity operations organization. /n This role owns four pillars of our defensive and offensive security program: Function Scope Security Operations Center (SOC) 24×7 monitoring, detection, triage, and incident response SOC Engineering Detection engineering, SIEM/SOAR platform ownership, automation, and telemetry pipeline management Vulnerability Management (VM) CTEM, Enterprise-wide exposure identification, risk-based prioritization, and remediation governance Red Team Adversary emulation, offensive testing, and purple-team collaboration with defenders As Director, you will have full ownership of the cybersecurity operations charter: the people (four teams and their leaders, including hiring, development, and succession), the platforms (the SIEM/SOAR/EDR ecosystem and the vulnerability and offensive-security tooling stack), the budget (headcount, tooling, and vendor/MSSP contracts), and the outcomes (detection and response performance, exposure reduction, and validated resilience against real-world attack techniques). You own the operational results end to end and are the accountable voice for them to the CISO and executive leadership. /n You will lead the continuous maturation of the SOC from a reactive, alert-driven operation toward a proactive, intelligence-led, and engineering-driven function. Establish and execute a maturity roadmap benchmarked against recognized models (e.g., SOC-CMM, NIST CSF), with measurable milestones across people, process, and technology. /n Key Responsibilities Strategy & Leadership /n /n
- Own the multi-year strategy, roadmap, budget, and SOC, SOC Engineering, Vulnerability Management, and Red Team functions.
/n
- Lead the leadership transition: retain institutional knowledge, stabilize the team, and build succession depth across all four pillars. HCL Software – Internal 1
/n
- Hire, develop, mentor, and retain senior security talent; manage managers and build career paths that reduce burnout and attrition.
/n
- Report security posture, operational metrics, and incident status to the CISO, executive leadership, and (as needed) the board — translating technical risk into business terms.
Security
Operations & Detection
/n
- Drive continuous improvement of detection and response: reduce mean time to detect/respond (MTTD/MTTR), dwell time, false-positive rates, and alert fatigue.
/n
- Evaluate and govern the responsible adoption of AI/agentic capabilities in the SOC (AI-assisted triage, investigation summarization, automated enrichment) while maintaining human oversight for consequential decisions.
/n
- Own major incident command: lead cross-functional response with IT, engineering, legal, communications, and customer-facing teams; run post-incident reviews and drive lessons learned to closure.
/n
- Assess current-state SOC maturity and publish a multi-year target-state roadmap with quarterly milestones, reporting progress to the CISO.
/n
- Advance detection maturity: move from vendor-default rules to a threat-informed detection engineering lifecycle with MITRE ATT&CK; coverage mapping, detection-as-code, versioning, and automated testing.
/n
- Mature triage and response through tiered playbook standardization, SOAR-driven automation of repeatable tasks, and progressive elimination of low-value manual work.
/n
- Evolve metrics from activity-based (alert counts, tickets closed) to outcome-based (MTTD/MTTR, dwell time, detection coverage %, automation rate, true-positive ratio) and use them to drive investment decisions. SOC Engineering & Platform
/n
- Own the SIEM/SOAR/EDR/NDR ecosystem strategy: telemetry coverage, log pipeline cost/quality optimization, use-case lifecycle management, and automation-first workflows.
/n
- Set engineering standards for detections (testing, version control, CI/CD) and playbooks (idempotent, measurable, auditable).
/n /n Vulnerability & Exposure Management /n /n
- Evolve traditional scan-and-patch VM toward Continuous Threat Exposure Management (CTEM): attack-surface discovery, attack-path analysis, risk-based prioritization tied to exploitability and business impact, and validation of remediation.
/n
- Establish and enforce remediation SLAs with asset and application owners; report exposure-reduction trends to leadership in business-risk language.
/n
- Cover the full estate: cloud (multi-cloud/SaaS), on-prem, endpoints, identities, containers, and the software we ship (partnering with product security/AppSec).
/n /n Offensive Security / Red Team /n /n
- Set the annual adversary-emulation program: scenario selection informed by threat intelligence and business risk; rules of engagement; safety and legal guardrails.
/n
- Institutionalize purple teaming so red-team findings directly improve detections, playbooks, and control validation. HCL Software – Internal 2
/n
- Extend offensive testing scope to up-to-date targets: cloud, identity/SSO, CI/CD supply chain, and AI/LLM systems.
/n
- Translate findings into prioritized remediation roadmaps with accountable owners — not just reports. Governance & Stakeholder Management
/n
- Align operations to relevant frameworks and obligations (e.g., NIST CSF, ISO 27001, SOC 2, customer contractual commitments) in partnership with GRC.
/n
- Manage key vendor and MSSP/MDR relationships, contracts, and performance.
/n
- Partner with product, engineering, IT, and customer success on security matters affecting HCL Software's products and customers.
/n /n Required Qualifications /n /n
- 12+ years in cybersecurity with 5+ years leading security operations functions (SOC, IR, VM, or offensive security), including experience managing managers and teams of 20+.
/n
- Demonstrated track record maturing a SOC through at least one full transformation cycle — e.g., moving from tiered reactive operations to threat-informed detection engineering, automation, and hunting — with before/after metrics to show for it.
/n
- Demonstrated ownership of each of the four pillars (SOC, detection/SOC engineering, VM, red team) at enterprise scale.
/n
- Proven incident commander for major/severity-1 incidents, including executive and external communications.
/n
- Deep technical grounding: SIEM/SOAR platforms, EDR/NDR, detection engineering practices, MITRE ATT&CK;, threat intelligence integration, cloud security operations (AWS/Azure/GCP), and identity-centric attack patterns.
/n
- Track record modernizing vulnerability management toward risk-based/exposure-driven models (CTEM or equivalent) with measurable exposure reduction.
/n
- Experience commissioning, governing, or leading red-team/adversary-emulation programs and converting findings into defensive improvements.
/n
- Executive communication: able to brief C-suite and board audiences, defend budgets, and translate technical risk into business impact.
/n
- Budget ownership experience (tooling, headcount, MSSP/vendor contracts).
Preferred
Qualifications
/n
- Experience in a software/product development company, understanding the interplay between enterprise security operations and product/customer trust.
/n
- Hands-on familiarity with AI-augmented security operations (agentic triage, LLM-assisted investigation) and with securing/red-teaming AI systems (OWASP LLM Top 10, MITRE ATLAS).
/n
- Experience leading globally distributed teams.
/n
- Familiarity with regulatory/customer assurance contexts common to enterprise software (SOC 2, ISO 27001; FedRAMP exposure a plus). HCL Software – Internal 3
/n
- Certifications valued (not required): CISSP, CISM, GIAC leadership/ops tracks (GSOM, GSOC, GCIH), OSCP/CRTO or equivalent offensive credentials, cloud security certifications. HCL Software – Internal 4
/n
📌 Director of Cyber Security Operations (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru