Security Operations Center Lead - Cyber Operations (India)

Security Operations Center Lead - Cyber Operations (India)

16 Sep
|
Employee Forums
|
India

16 Sep

Employee Forums

India

Role : Security Operations Center (SOC) Lead

Department : Cyber Operations &

- Engineering

Location : Mumbai

Experience Required : 8 - 10 Years

Reporting To : Head of Cybersecurity / CISO

Role Summary :

The SOC Lead oversees 24x7 security operations, advanced detection engineering, and high-severity incident response. This role combines technical leadership across SIEM, SOAR, and EDR platforms with operational governance - mentoring Tier-1 and Tier-2 analysts, optimizing runbooks, and ensuring swift threat containment across enterprise environments.

Key Responsibilities :

- Incident Response &
- Escalations : Serve as the final escalation point for critical (P1/P2) security incidents; direct end-to-end containment, eradication, forensics, and post-incident root cause analysis (RCA).
- Detection Engineering &
- Tuning : Oversee SIEM correlation rule creation, use-case mapping to the MITRE ATT&CK; framework, and alert tuning to eliminate noise and reduce false positives.
- SOAR &
- Automation : Direct the development of automated incident response playbooks integrated with EDR, firewalls, IAM, and ITSM to consistently lower MTTR and MTTD.
- Threat Hunting &
- Intelligence : Integrate actionable threat intelligence (CTI) into monitoring workflows and guide proactive threat-hunting exercises across network, endpoint, and cloud assets.
- Operational Governance &
- Mentorship : Manage analyst shift rotations, define SOC SOPs and runbooks, conduct tabletop simulations,



and mentor Tier-1 and Tier-2 engineers.
- Metrics &
- Executive Reporting : Track and report core operational KPIs (MTTD, MTTR, coverage gaps) and present threat summaries and security posture updates to executive leadership and audit teams.

Required Technical Skills &

Qualifications :

- Experience : 8 - 10 years in cyber operations, with at least 3 years in a senior, L3, or lead capacity within an enterprise SOC or MSSP.
- SIEM/SOAR Expertise : Deep architectural and operational mastery of modern SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, Google SecOps) and SOAR tools (e.g., Cortex XSOAR, Splunk SOAR).
- Threat Detection : Proven ability to map detections to MITRE ATT&CK;, investigate complex lateral movement, and analyze advanced attack vectors (ransomware, living-off-the-land techniques).
- Scripting &
- Telemetry : Hands-on experience analyzing endpoint telemetry (CrowdStrike, Defender, SentinelOne), network logs, and identity systems; working knowledge of Python, PowerShell, or KQL for log query optimization and automation.
- Leadership : Solid track record in team coaching, crisis decision-making, and stakeholder communication.

Preferred Certifications :

- CISSP, CISM, or CCISO
- GIAC Certifications (GCIH, GCFA, GCED, or GNFA)
- Certified SIEM/SOAR Architect (e.g., Splunk Certified Enterprise Security Admin, Microsoft Sentinel SC-200)

📌 Security Operations Center Lead - Cyber Operations (India)
🏢 Employee Forums
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security operations center lead - cyber operations (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: security operations center lead - cyber operations (india) / india