SOC Principal (Bengaluru)

SOC Principal (Bengaluru)

14 Sep
|
HCLSoftware
|
Bengaluru

14 Sep

HCLSoftware

Bengaluru

SOC Principal

nHCL Software | Office of the CISO

nLocation: India - Bangalore / Noida / Remote

nAbout the Role

nHCL Software is seeking a SOC Principal to serve as the most senior technical authority inside our

nSecurity Operations Center. This is a hands-on individual contributor role for someone who wants

ndepth and influence rather than a management span, and it sits at the point where detection quality,

ninvestigation rigor, and incident command all converge.

nYou will set the technical bar for how the SOC detects, investigates, and closes out threats across a

nglobal multi-cloud and SaaS estate, while our detection platform modernizes and our telemetry

npipeline is rebuilt.

nYou will work alongside SOC Engineering, Vulnerability Management, Red Team, and Product

nSecurity, and you will be the person the organization escalates to when an incident is genuinely

nambiguous.

nKey Responsibilities

nInvestigation and Incident Response

n• Act as a technical incident commander for severity-1 and severity-2 events, coordinating across

nIT, engineering, legal, communications, and customer-facing teams.

n• Own the deep-dive analysis that junior tiers cannot complete: host and memory forensics,

ncloud control-plane reconstruction, identity abuse chains, and lateral movement tracing.

n• Drive root cause to conclusion and convert every significant incident into concrete detection,

ncontrol, and process changes with named owners.

n• Set and enforce evidence handling, chain of custody, and case documentation standards

nsuitable for customer, regulator, and audit scrutiny.

nDetection and Content Engineering

n• Define detection content standards covering test coverage, version control, peer review, and

npromotion through a detection-as-code pipeline.

n• Maintain an ATT&CK-aligned; coverage map, identify blind spots, and prioritize new content

nagainst threat intelligence and business risk.





n• Govern tuning and suppression decisions so false-positive reduction never quietly removes real

nvisibility.

n• Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source

nonboarding during platform migration.

nThreat Hunting and Intelligence

n• Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed

nadversary tradecraft relevant to enterprise software companies.

n• Operationalize intelligence into detections, hunt queries, and watchlists rather than leaving it as

nreading material.

n• Collaborate with Red Team on purple-team exercises and validate that emulated tradecraft is

nactually detected.

nTechnical Leadership

n• Mentor analysts across shifts, run investigation retrospectives, and raise consistency in triage

nand escalation decisions.

n• Author and maintain the runbook and playbook library, keeping it accurate as the platform

nestate changes.

n• Represent the SOC in design discussions with architecture, cloud, and product engineering

nteams.

n• Produce clear written analysis for leadership that separates what is known, what is suspected,

nand what is still open.

nRequired AI Expertise

n• Hands-on experience implementing and evaluating AI-driven security automation, automated

ntriage, and generative AI investigation workflows within a modern SOC setting.

n• Strong understanding of threat landscapes targeting AI/ML systems, including prompt injection,

nmodel poisoning, data exfiltration via LLMs, MCP, and securing enterprise AI infrastructure.





n• Ability to design detection strategies for AI-assisted attack vectors and adversary tradecraft

nleveraging autonomous or AI-enhanced tools.

nRequired Qualifications

n• 8+ years in security operations, incident response, or threat detection, including senior or lead

nresponsibility for major incidents.

n• Demonstrated incident command experience on severity-1 events, with the judgment to make

ncontainment calls under incomplete information.

n• Deep hands-on expertise with SIEM platforms and detection content development, including

nquery languages, correlation logic, and detection tuning.

n• Strong working knowledge of EDR telemetry, identity and SSO attack patterns, and cloud

nsecurity operations across AWS, Azure, or GCP.

n• Fluency with MITRE ATT&CK; as an operational tool rather than a slide, including coverage

nmapping and gap analysis.

n• Practical scripting and automation ability (Python, PowerShell, or equivalent) for enrichment,

nanalysis, and tooling.

n• Excellent written communication, including the ability to produce incident narratives that hold up

nin front of executives, customers, and auditors.

nPreferred Qualifications

n• Experience through a SIEM platform migration, including detection content translation,

nparallel-run validation, and log pipeline rework.

n

n
- Experience with leading technologies (Wiz, Crowdstrike
n
- Background in a software or product company, with an understanding of how enterprise SOC
n

nwork connects to customer trust and product security.

n• Familiarity with detection-as-code practices, CI/CD for content, and automated detection

ntesting.

n

n
- Experience investigating attacks against SaaS, CI/CD, and software supply chain targets.
n
- Exposure to AI-assisted triage and investigation workflows, with a considered view of where
n

nhuman judgment remains mandatory.

n• Certifications valued but not required: GCIA, GCIH, GCFA, GNFA, GDAT, or equivalent.

📌 SOC Principal (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: soc principal (bengaluru) / bengaluru