16 Sep
|
Employee Forums
|
India
16 Sep
Employee Forums
India
Role : Security Operations Center (SOC) Lead
Department : Cyber Operations &
- Engineering
Location : Mumbai
Experience Required : 8 - 10 Years
Reporting To : Head of Cybersecurity / CISO
Role Summary :
The SOC Lead oversees 24x7 security operations, advanced detection engineering, and high-severity incident response. This role combines technical leadership across SIEM, SOAR, and EDR platforms with operational governance - mentoring Tier-1 and Tier-2 analysts, optimizing runbooks, and ensuring swift threat containment across enterprise environments.
Key Responsibilities :
- Incident Response &
- Escalations : Serve as the final escalation point for critical (P1/P2) security incidents; direct end-to-end containment, eradication, forensics, and post-incident root cause analysis (RCA).
- Detection Engineering &
- Tuning : Oversee SIEM correlation rule creation, use-case mapping to the MITRE ATT&CK; framework, and alert tuning to eliminate noise and reduce false positives.
- SOAR &
- Automation : Direct the development of automated incident response playbooks integrated with EDR, firewalls, IAM, and ITSM to consistently lower MTTR and MTTD.
- Threat Hunting &
- Intelligence : Integrate actionable threat intelligence (CTI) into monitoring workflows and guide proactive threat-hunting exercises across network, endpoint, and cloud assets.
- Operational Governance &
- Mentorship : Manage analyst shift rotations, define SOC SOPs and runbooks, conduct tabletop simulations,
and mentor Tier-1 and Tier-2 engineers.
- Metrics &
- Executive Reporting : Track and report core operational KPIs (MTTD, MTTR, coverage gaps) and present threat summaries and security posture updates to executive leadership and audit teams.
Required Technical Skills &
Qualifications :
- Experience : 8 - 10 years in cyber operations, with at least 3 years in a senior, L3, or lead capacity within an enterprise SOC or MSSP.
- SIEM/SOAR Expertise : Deep architectural and operational mastery of modern SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, Google SecOps) and SOAR tools (e.g., Cortex XSOAR, Splunk SOAR).
- Threat Detection : Proven ability to map detections to MITRE ATT&CK;, investigate complex lateral movement, and analyze advanced attack vectors (ransomware, living-off-the-land techniques).
- Scripting &
- Telemetry : Hands-on experience analyzing endpoint telemetry (CrowdStrike, Defender, SentinelOne), network logs, and identity systems; working knowledge of Python, PowerShell, or KQL for log query optimization and automation.
- Leadership : Solid track record in team coaching, crisis decision-making, and stakeholder communication.
Preferred Certifications :
- CISSP, CISM, or CCISO
- GIAC Certifications (GCIH, GCFA, GCED, or GNFA)
- Certified SIEM/SOAR Architect (e.g., Splunk Certified Enterprise Security Admin, Microsoft Sentinel SC-200)
📌 Security Operations Center Lead - Cyber Operations (India)
🏢 Employee Forums
📍 India