14 Sep
|
HCLSoftware
|
Bengaluru
14 Sep
HCLSoftware
Bengaluru
Job Description
SOC Principal
n
HCL Software | Office of the CISO
n
Location: India - Bangalore / Noida / Remote
n
About the Role
n
HCL Software is seeking a SOC Principal to serve as the most senior technical authority inside our
n
Security Operations Center. This is a hands-on individual contributor role for someone who wants
n
depth and influence rather than a management span, and it sits at the point where detection quality,
n
investigation rigor, and incident command all converge.
n
You will set the technical bar for how the SOC detects, investigates, and closes out threats across a
n
global multi-cloud and SaaS estate, while our detection platform modernizes and our telemetry
n
pipeline is rebuilt.
n
You will work alongside SOC Engineering, Vulnerability Management, Red Team, and Product
n
Security, and you will be the person the organization escalates to when an incident is genuinely
n
ambiguous.
n
Key Responsibilities
n
Investigation and Incident Response
n
• Act as a technical incident commander for severity-1 and severity-2 events, coordinating across
n
IT, engineering, legal, communications, and customer-facing teams.
n
• Own the deep-dive analysis that junior tiers cannot complete: host and memory forensics,
n
cloud control-plane reconstruction, identity abuse chains, and lateral movement tracing.
n
• Drive root cause to conclusion and convert every significant incident into concrete detection,
n
control, and process changes with named owners.
n
• Set and enforce evidence handling, chain of custody, and case documentation standards
n
suitable for customer, regulator, and audit scrutiny.
n
Detection and Content Engineering
n
• Define detection content standards covering test coverage, version control, peer review, and
n
promotion through a detection-as-code pipeline.
n
• Maintain an ATT&CK-aligned; coverage map, identify blind spots, and prioritize current content
n
against threat intelligence and business risk.
n
• Govern tuning and suppression decisions so false-positive reduction never quietly removes real
n
visibility.
n
• Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source
n
onboarding during platform migration.
n
Threat Hunting and Intelligence
n
• Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed
n
adversary tradecraft relevant to enterprise software companies.
n
• Operationalize intelligence into detections, hunt queries, and watchlists rather than leaving it as
n
reading material.
n
• Collaborate with Red Team on purple-team exercises and validate that emulated tradecraft is
n
actually detected.
n
Technical Leadership
n
• Mentor analysts across shifts, run investigation retrospectives, and raise consistency in triage
n
and escalation decisions.
n
• Author and maintain the runbook and playbook library, keeping it accurate as the platform
n
estate changes.
n
• Represent the SOC in design discussions with architecture, cloud, and product engineering
n
teams.
n
• Produce clear written analysis for leadership that separates what is known, what is suspected,
n
and what is still open.
n
Required AI Expertise
n
• Hands-on experience implementing and evaluating AI-driven security automation, automated
n
triage, and generative AI investigation workflows within a modern SOC environment.
n
• Strong understanding of threat landscapes targeting AI/ML systems, including prompt injection,
n
model poisoning, data exfiltration via LLMs, MCP, and securing enterprise AI infrastructure.
n
• Ability to design detection strategies for AI-assisted attack vectors and adversary tradecraft
n
leveraging autonomous or AI-enhanced tools.
n
Required Qualifications
n
• 8+ years in security operations, incident response, or threat detection, including senior or lead
n
responsibility for major incidents.
n
• Demonstrated incident command experience on severity-1 events, with the judgment to make
n
containment calls under incomplete information.
n
• Deep hands-on expertise with SIEM platforms and detection content development, including
n
query languages, correlation logic, and detection tuning.
n
• Strong working knowledge of EDR telemetry, identity and SSO attack patterns, and cloud
n
security operations across AWS, Azure, or GCP.
n
• Fluency with MITRE ATT&CK; as an operational tool rather than a slide, including coverage
n
mapping and gap analysis.
n
• Practical scripting and automation ability (Python, PowerShell, or equivalent) for enrichment,
n
analysis, and tooling.
n
• Excellent written communication, including the ability to produce incident narratives that hold up
n
in front of executives, customers, and auditors.
n
Preferred Qualifications
n
• Experience through a SIEM platform migration, including detection content translation,
n
parallel-run validation, and log pipeline rework.
n
n
- Experience with leading technologies (Wiz, Crowdstrike
n
- Background in a software or product company, with an understanding of how enterprise SOC
n
n
work connects to customer trust and product security.
n
• Familiarity with detection-as-code practices, CI/CD for content, and automated detection
n
testing.
n
n
- Experience investigating attacks against SaaS, CI/CD, and software supply chain targets.
n
- Exposure to AI-assisted triage and investigation workflows, with a considered view of where
n
n
human judgment remains mandatory.
n
• Certifications valued but not required: GCIA, GCIH, GCFA, GNFA, GDAT, or equivalent.
📌 SOC Principal (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru