17 Sep
|
HCLSoftware
|
Bengaluru
17 Sep
HCLSoftware
Bengaluru
Job Description
SOC Principal
/n
HCL Software | Office of the CISO
/n
Location: India - Bangalore / Noida / Remote
/n
About the Role
/n
HCL Software is seeking a SOC Principal to serve as the most senior technical authority inside our
/n
Security Operations Center. This is a hands-on individual contributor role for someone who wants
/n
depth and influence rather than a management span, and it sits at the point where detection quality,
/n
investigation rigor, and incident command all converge.
/n
You will set the technical bar for how the SOC detects, investigates, and closes out threats across a
/n
global multi-cloud and SaaS estate, while our detection platform modernizes and our telemetry
/n
pipeline is rebuilt.
/n
You will work alongside SOC Engineering, Vulnerability Management, Red Team, and Product
/n
Security, and you will be the person the organization escalates to when an incident is genuinely
/n
ambiguous.
/n
Key Responsibilities
/n
Investigation and Incident Response
/n
- Act as a technical incident commander for severity-1 and severity-2 events, coordinating across
/n
IT, engineering, legal, communications, and customer-facing teams.
/n
- Own the deep-dive analysis that junior tiers cannot complete: host and memory forensics,
/n
cloud control-plane reconstruction, identity abuse chains, and lateral movement tracing.
/n
- Drive root cause to conclusion and convert every significant incident into concrete detection,
/n
control, and process changes with named owners.
/n
- Set and enforce evidence handling, chain of custody, and case documentation standards
/n
suitable for customer, regulator, and audit scrutiny.
/n
Detection and Content Engineering
/n
- Define detection content standards covering test coverage, version control, peer review, and
/n
promotion through a detection-as-code pipeline.
/n
- Maintain an ATT&CK-aligned; coverage map, identify blind spots, and prioritize current content
/n
against threat intelligence and business risk.
/n
- Govern tuning and suppression decisions so false-positive reduction never quietly removes real
/n
visibility.
/n
- Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source
/n
onboarding during platform migration.
/n
Threat Hunting and Intelligence
/n
- Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed
/n
adversary tradecraft relevant to enterprise software companies.
/n
- Operationalize intelligence into detections, hunt queries, and watchlists rather than leaving it as
/n
reading material.
/n
- Collaborate with Red Team on purple-team exercises and validate that emulated tradecraft is
/n
actually detected.
/n
Technical Leadership
/n
- Mentor analysts across shifts, run investigation retrospectives, and raise consistency in triage
/n
and escalation decisions.
/n
- Author and maintain the runbook and playbook library, keeping it accurate as the platform
/n
estate changes.
/n
- Represent the SOC in design discussions with architecture, cloud, and product engineering
/n
teams.
/n
- Produce clear written analysis for leadership that separates what is known, what is suspected,
/n
and what is still open.
/n
Required AI Expertise
/n
- Hands-on experience implementing and evaluating AI-driven security automation, automated
/n
triage, and generative AI investigation workflows within a modern SOC environment.
/n
- Strong understanding of threat landscapes targeting AI/ML systems, including prompt injection,
/n
model poisoning, data exfiltration via LLMs, MCP, and securing enterprise AI infrastructure.
/n
- Ability to design detection strategies for AI-assisted attack vectors and adversary tradecraft
/n
leveraging autonomous or AI-enhanced tools.
/n
Required Qualifications
/n
- 8+ years in security operations, incident response, or threat detection, including senior or lead
/n
responsibility for major incidents.
/n
- Demonstrated incident command experience on severity-1 events, with the judgment to make
/n
containment calls under incomplete information.
/n
- Deep hands-on expertise with SIEM platforms and detection content development, including
/n
query languages, correlation logic, and detection tuning.
/n
- Strong working knowledge of EDR telemetry, identity and SSO attack patterns, and cloud
/n
security operations across AWS, Azure, or GCP.
/n
- Fluency with MITRE ATT&CK; as an operational tool rather than a slide, including coverage
/n
mapping and gap analysis.
/n
- Practical scripting and automation ability (Python, Power Shell, or equivalent) for enrichment,
/n
analysis, and tooling.
/n
- Excellent written communication, including the ability to produce incident narratives that hold up
/n
in front of executives, customers, and auditors.
/n
Preferred Qualifications
/n
- Experience through a SIEM platform migration, including detection content translation,
/n
parallel-run validation, and log pipeline rework.
/n
/n
- Experience with leading technologies (Wiz, Crowdstrike
/n
- Background in a software or product company, with an understanding of how enterprise SOC
/n
/n
work connects to customer trust and product security.
/n
- Familiarity with detection-as-code practices, CI/CD for content, and automated detection
/n
testing.
/n
/n
- Experience investigating attacks against SaaS, CI/CD, and software supply chain targets.
/n
- Exposure to AI-assisted triage and investigation workflows, with a considered view of where
/n
/n
human judgment remains mandatory.
/n
- Certifications valued but not required: GCIA, GCIH, GCFA, GNFA, GDAT, or equivalent.
📌 SOC Principal (Bengaluru)
🏢 HCLSoftware
📍 Bengaluru