16 Sep
|
HCLSoftware
|
Bengaluru
16 Sep
HCLSoftware
Bengaluru
SOC Principal /n HCL Software | Office of the CISO /n Location: India - Bangalore / Noida / Remote /n About the Role /n HCL Software is seeking a SOC Principal to serve as the most senior technical authority inside our /n Security Operations Center. This is a hands-on individual contributor role for someone who wants /n depth and influence rather than a management span, and it sits at the point where detection quality, /n investigation rigor, and incident command all converge. /n You will set the technical bar for how the SOC detects, investigates, and closes out threats across a /n global multi-cloud and SaaS estate, while our detection platform modernizes and our telemetry /n pipeline is rebuilt. /n You will work alongside SOC Engineering, Vulnerability Management, Red Team, and Product /n Security, and you will be the person the organization escalates to when an incident is genuinely /n ambiguous. /n Key Responsibilities /n Investigation and Incident Response /n • Act as a technical incident commander for severity-1 and severity-2 events, coordinating across /n IT, engineering, legal, communications, and customer-facing teams. /n • Own the deep-dive analysis that junior tiers cannot complete: host and memory forensics, /n cloud control-plane reconstruction, identity abuse chains, and lateral movement tracing. /n • Drive root cause to conclusion and convert every significant incident into concrete detection, /n control, and process changes with named owners. /n • Set and enforce evidence handling, chain of custody, and case documentation standards /n suitable for customer, regulator, and audit scrutiny. /n Detection and Content Engineering /n • Define detection content standards covering test coverage, version control, peer review, and /n promotion through a detection-as-code pipeline. /n • Maintain an ATT&CK-aligned; coverage map, identify blind spots, and prioritize new content /n against threat intelligence and business risk.
/n • Govern tuning and suppression decisions so false-positive reduction never quietly removes real /n visibility. /n • Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source /n onboarding during platform migration. /n Threat Hunting and Intelligence /n • Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed /n adversary tradecraft relevant to enterprise software companies. /n • Operationalize intelligence into detections, hunt queries, and watchlists rather than leaving it as /n reading material. /n • Collaborate with Red Team on purple-team exercises and validate that emulated tradecraft is /n actually detected. /n Technical Leadership /n • Mentor analysts across shifts, run investigation retrospectives, and raise consistency in triage /n and escalation decisions. /n • Author and maintain the runbook and playbook library, keeping it accurate as the platform /n estate changes. /n • Represent the SOC in design discussions with architecture, cloud, and product engineering /n teams. /n • Produce clear written analysis for leadership that separates what is known, what is suspected, /n and what is still open. /n Required AI Expertise /n • Hands-on experience implementing and evaluating AI-driven security automation, automated /n triage, and generative AI investigation workflows within a modern SOC workplace. /n • Strong understanding of threat landscapes targeting AI/ML systems, including prompt injection, /n model poisoning, data exfiltration via LLMs, MCP, and securing enterprise AI infrastructure.
/n • Ability to design detection strategies for AI-assisted attack vectors and adversary tradecraft /n leveraging autonomous or AI-enhanced tools. /n Required Qualifications /n • 8+ years in security operations, incident response, or threat detection, including senior or lead /n responsibility for major incidents. /n • Demonstrated incident command experience on severity-1 events, with the judgment to make /n containment calls under incomplete information. /n • Deep hands-on expertise with SIEM platforms and detection content development, including /n query languages, correlation logic, and detection tuning. /n • Strong working knowledge of EDR telemetry, identity and SSO attack patterns, and cloud /n security operations across AWS, Azure, or GCP. /n • Fluency with MITRE ATT&CK; as an operational tool rather than a slide, including coverage /n mapping and gap analysis. /n • Practical scripting and automation ability (Python, PowerShell, or equivalent) for enrichment, /n analysis, and tooling. /n • Excellent written communication, including the ability to produce incident narratives that hold up /n in front of executives, customers, and auditors. /n Preferred Qualifications /n • Experience through a SIEM platform migration, including detection content translation, /n parallel-run validation, and log pipeline rework. /n /n
- Experience with leading technologies (Wiz, Crowdstrike
/n
- Background in a software or product company, with an understanding of how enterprise SOC
/n /n work connects to customer trust and product security. /n • Familiarity with detection-as-code practices, CI/CD for content, and automated detection /n testing. /n /n
- Experience investigating attacks against SaaS, CI/CD, and software supply chain targets.
/n
- Exposure to AI-assisted triage and investigation workflows, with a considered view of where
/n /n human judgment remains mandatory. /n • Certifications valued but not required: GCIA, GCIH, GCFA, GNFA, GDAT, or equivalent.
📌 SOC Principal (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru