13 Sep
|
HCLSoftware
|
Bengaluru
13 Sep
HCLSoftware
Bengaluru
SOC Principal
HCL Software | Office of the CISO
Location: India - Bangalore / Noida / Remote
About the Role
HCL Software is seeking a SOC Principal to serve as the most senior technical authority inside our
Security Operations Center. This is a hands-on individual contributor role for someone who wants depth and influence rather than a management span, and it sits at the point where detection quality,
investigation rigor, and incident command all converge.
You will set the technical bar for how the SOC detects, investigates, and closes out threats across a global multi-cloud and SaaS estate, while our detection platform modernizes and our telemetry pipeline is rebuilt.
You will work alongside SOC Engineering, Vulnerability Management, Red Team, and Product
Security, and you will be the person the organization escalates to when an incident is genuinely ambiguous.
Key Responsibilities
Investigation and Incident Response
- Act as a technical incident commander for severity-1 and severity-2 events, coordinating across
IT, engineering, legal, communications, and customer-facing teams.
- Own the deep-dive analysis that junior tiers cannot complete: host and memory forensics,
cloud control-plane reconstruction, identity abuse chains, and lateral movement tracing.
- Drive root cause to conclusion and convert every significant incident into concrete detection,
control, and process changes with named owners.
- Set and enforce evidence handling, chain of custody, and case documentation standards suitable for customer, regulator, and audit scrutiny.
Detection and Content Engineering
- Define detection content standards covering test coverage, version control, peer review, and promotion through a detection-as-code pipeline.
- Maintain an ATT&CK-aligned; coverage map, identify blind spots, and prioritize new content against threat intelligence and business risk.
- Govern tuning and suppression decisions so false-positive reduction never quietly removes real visibility.
- Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source onboarding during platform migration.
Threat Hunting and Intelligence
- Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed adversary tradecraft relevant to enterprise software companies.
- Operationalize intelligence into detections, hunt queries, and watchlists rather than leaving it as reading material.
- Collaborate with Red Team on purple-team exercises and validate that emulated tradecraft is actually detected.
Technical Leadership
- Mentor analysts across shifts, run investigation retrospectives, and raise consistency in triage and escalation decisions.
- Author and maintain the runbook and playbook library, keeping it accurate as the platform estate changes.
- Represent the SOC in design discussions with architecture, cloud, and product engineering teams.
- Produce explicit written analysis for leadership that separates what is known, what is suspected,
and what is still open.
Required AI Expertise
- Hands-on experience implementing and evaluating AI-driven security automation, automated triage, and generative AI investigation workflows within a modern SOC environment.
- Strong understanding of threat landscapes targeting AI/ML systems, including prompt injection,
model poisoning, data exfiltration via LLMs, MCP, and securing enterprise AI infrastructure.
- Ability to design detection strategies for AI-assisted attack vectors and adversary tradecraft leveraging autonomous or AI-enhanced tools.
Required Qualifications
- 8+ years in security operations, incident response, or threat detection, including senior or lead responsibility for major incidents.
- Demonstrated incident command experience on severity-1 events, with the judgment to make containment calls under incomplete information.
- Deep hands-on expertise with SIEM platforms and detection content development, including query languages, correlation logic, and detection tuning.
- Strong working knowledge of EDR telemetry, identity and SSO attack patterns, and cloud security operations across AWS, Azure, or GCP.
- Fluency with MITRE ATT&CK; as an operational tool rather than a slide, including coverage mapping and gap analysis.
- Practical scripting and automation ability (Python, PowerShell, or equivalent) for enrichment,
analysis, and tooling.
- Excellent written communication, including the ability to produce incident narratives that hold up in front of executives, customers, and auditors.
Preferred Qualifications
- Experience through a SIEM platform migration, including detection content translation,
parallel-run validation, and log pipeline rework.
- Experience with leading technologies (Wiz, Crowdstrike
- Background in a software or product company, with an understanding of how enterprise SOC
work connects to customer trust and product security.
- Familiarity with detection-as-code practices, CI/CD for content, and automated detection testing.
- Experience investigating attacks against SaaS, CI/CD, and software supply chain targets.
- Exposure to AI-assisted triage and investigation workflows, with a considered view of where
human judgment remains mandatory.
- Certifications valued but not required: GCIA, GCIH, GCFA, GNFA, GDAT, or equivalent.
📌 SOC Principal (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru