17 Sep
|
Anveta Manpower Solutions
|
Hyderabad
17 Sep
Anveta Manpower Solutions
Hyderabad
Reporting To:
Manager, Security Operations Event Response team (L1)
Brief Job Description:
The SOC Lead is a senior individual contributor who provides functional leadership, technical direction and operational oversight for SOC capabilities. The role focuses on strengthening threat detection, incident response and continuous improvement across cybersecurity operations.
Technical Skills Required:
- Incident detection, triage, and investigation in a 24x7 SOC environment
- Sentinel One EDR -alert investigation, Deep Visibility, Event Search (PowerQuery), exclusion and policy management
- Email threat investigation using Mimecast gateway - phishing triage, sender policy review, whitelisting verification
- SIEM: Microsoft Sentinel, Rapid7, or IBM QRadar - query writing, alert rule tuning, use case development
- MITRE ATT&CK; framework - independently mapping observed indicators to adversary TTPs
- SOP authoring and Playbook development for SOC operations
- Post-incident analysis and Root Cause Analysis documentation
- Windows and Linux systems including scripting - PowerShell, Bash, or Python.
Technologies Required:
- Sentinel One EDR - primary detection and response platform
- Mimecast - email security gateway
- Tenable (or equivalent) vulnerability management tool (preferred)
- ServiceNow - ticketing, SLA management, and dashboard reporting
- Microsoft Entra ID / Azure AD - identity investigation and conditional access
- Rapid7 & IBM Qradar: SIEM and SOAR
- AWS Security: GuardDuty, CloudTrail, EC2 investigation (preferred)
Verbal / Written Skills Required:
- Clear and structured written and verbal communication — able to brief senior stakeholders concisely during active incidents
- Ability to produce investigation reports, RCA documents, and management dashboards without editorial support
- Proficiency in drafting SOPs and Playbooks that analysts can execute independently without managerial guidance
Teamwork / Adaptability Requirements:
- Ability to lead and hold a shift team to investigation quality standards without requiring escalation for enforcement decisions
- Comfortable operating in a high-pressure, post-incident environment with multiple concurrent priorities
- Commitment to continuous learning and active knowledge sharing across the team
- Adaptable to multi-region APAC operational requirements across Singapore, Malaysia, Korea, China, and Indonesia
Shift Work / Travel Required:
Yes - 24x7 rotational shift operations. No international travel required in standard operations. APAC time zone coverage required.
Years of Experience Required
(Min~Max):
Minimum 7 Years | Maximum 10 Years - with at least 2+ years in a technical lead or senior analyst role in a 24x7 SOC environment.
Education Required:
Any Graduate: Preferred: Bachelor’s degree in computer science, Information Technology, or Cybersecurity (or equivalent experience).
Preferred: CompTIA Security+ | CySA+ | GSEC | SC-200 | CISSP | SentinelOne Certification | Mimecast Certification
Date Recruitment to be Filled:
(On or before)
Immediate
Role Summary:
This role leads a team that supports a High-impact incident management process and resolutions. The SOC Lead is a senior individual contributor who provides functional leadership, technical direction and operational oversight for SOC capabilities. The role focuses on strengthening threat detection, incident response and continuous improvement across cybersecurity operations.
This role requires robust expertise in SOC operations, incident response, detection engineering and security platforms along with guiding analysts and deliver scalable operational improvements.
Core Responsibilities
- Hands-on experience with SIEM platforms including query writing, alert rule tuning, and use case development from scratch.
- Strong understanding of SIEM use case lifecycle from threat scenario identification through detection logic design, testing, and ongoing tuning to reduce false positives
- Provide functional leadership and operational coordination for 247 SOC shift activities including shift handover ownership, coverage planning, and analyst task assignment
- Independently triage and investigate security events in SentinelOne EDR and Mimecast email gateway - from alert to documented conclusion, not just to mitigation
- Develop, maintain, and enforce Standard Operating Procedures and Playbooks for the Event Response team covering alert triage, escalation, containment, and closure
- Conduct alert quality reviews - validate that analyst investigation outputs answer the investigative question before tickets are closed in ServiceNow
- Build and maintain ServiceNow dashboards for incident tracking, SLA visibility, and team performance reporting for management consumption
- Enrich and contextualise alerts with threat intelligence - identify TTPs used by threat actors and map findings to MITRE ATT&CK;
- Analyse security events, collect evidence, and support deeper investigations in coordination with the L2 Threat Management team and external MDR partners
- Maintain incident reporting systems and knowledge databases; contribute to post-incident analysis, RCA documentation, and continuous improvement actions
- Guide and coach L1 analysts on investigation technique, documentation standards, and tool usage during shift operations
Key Requirements:
- Strong expertise in SOC operations and incident response in a 247 environment with demonstrated ability to independently close critical severity alerts
- Hands-on experience with SentinelOne EDR - alert investigation, Deep Visibility, Event Search (Power Query), exclusion and policy management
- Experience in Vulnerability assessment, Tenable (or equivalent) vulnerability management tool (preferred)
- Proficiency in Mimecast email gateway -phishing triage, sender policy review, and whitelisting with appropriate verification
📌 SOC LEAD (Hyderabad)
🏢 Anveta Manpower Solutions
📍 Hyderabad