18 Sep
|
Baseel Partners
|
Bengaluru
18 Sep
Baseel Partners
Bengaluru
SOC Manager
Role Overview
We are looking for an experienced SOC Manager to own and lead the end-to-end Security Operations Center (SOC) function for a fast-paced Indian FinTech environment. This is a senior, hands-on leadership role requiring 712 years of experience, reporting to the CISO, and based in Bengaluru with a hybrid working model (3 days a week in the office). The role is responsible for 24x7 security monitoring, incident detection and response, threat hunting, SIEM engineering, cloud security incident response, attack surface management, security incident SLAs, audit readiness, and continuous improvement of the organisation’s security operations capability.
The ideal candidate should be equally comfortable operating as a hands-on L3/L4 security incident responder and leading the SOC function strategically, working closely with Cloud, Infrastructure, Application Security, DevSecOps, Data Security, Fraud/Risk, IT, Compliance, and external security partners.
Key Responsibilities
End-to-End SOC Management
- Own the end-to-end SOC function, including people, processes, technology, monitoring, incident response, and continuous improvement.
- Manage day-to-day SOC operations and ensure effective 24x7 security monitoring and incident response.
- Define and maintain SOC operating procedures, playbooks, escalation matrices, and incident response processes.
- Establish and track SOC KPIs, KRIs and operational metrics.
- Manage internal SOC teams and coordinate with MSSP/SOC service providers where applicable.
- Drive SOC maturity improvements through automation, orchestration, process optimization, and technology enhancements.
- Ensure appropriate coverage across endpoints, network, applications, cloud, identity, data, and third-party environments.
L3/L4 Security Incident Response
- Act as the L3/L4 escalation point for complex and high-severity security incidents.
- Lead investigation, containment, eradication, and recovery of sophisticated cyber incidents.
- Perform deep-dive analysis of security alerts, logs, network traffic, endpoint telemetry, cloud activity, and identity events.
- Lead response to incidents such as account compromise, malware/ransomware, phishing and BEC, credential theft, privilege escalation, data exfiltration, cloud compromise, web/API attacks, insider threats, and supply-chain/third-party security incidents.
- Coordinate incident response across Cloud, IT, DevOps, Application Security, IAM, Data Security, Fraud, Legal, Risk, and Compliance teams.
- Lead post-incident reviews and ensure root-cause analysis and corrective/preventive actions are completed.
Security Incident SLA Management
- Own and maintain strong security incident SLAs, including detection, triage, escalation, containment, and resolution timelines.
- Define severity-based response and escalation criteria.
- Monitor SOC performance against agreed SLAs and drive corrective actions for SLA breaches.
- Ensure critical/high-severity incidents receive appropriate management escalation.
- Prepare regular incident and SLA reports for senior management/CISO.
AWS Cloud Security
- Lead investigation and response to AWS cloud security incidents.
- Monitor and investigate activities across services such as AWS CloudTrail, GuardDuty, Security Hub, IAM, VPC Flow Logs, WAF, S3, EC2, EKS/ECS, Lambda, and KMS.
- Investigate cloud account compromise, excessive privileges, suspicious API activity, exposed resources, data leakage, credential compromise, and anomalous workloads.
- Work closely with Cloud Security/DevSecOps teams to improve AWS detection and response capabilities.
- Develop and maintain cloud-specific incident response playbooks.
External Threat & Attack Surface Management
- Own/coordinate external attack surface management (EASM) activities.
- Identify and monitor internet-facing assets, domains, IPs, applications, APIs, cloud resources, and exposed services.
- Identify vulnerabilities, misconfigurations, exposed credentials/secrets, shadow IT, and unauthorized assets.
- Prioritize remediation based on exploitability, business criticality, threat intelligence, and exposure.
- Monitor external threat intelligence and indicators relevant to the organization.
- Coordinate with Application Security, Infrastructure, Cloud, and Engineering teams for remediation.
Data Security & Data Protection
- Work closely with Data Security/DLP teams to detect and investigate potential data leakage and exfiltration.
- Investigate suspicious access to sensitive/regulated data.
- Support monitoring of sensitive data movement across endpoints, cloud, databases, applications, and third parties.
- Understand security controls around PII, financial data, payment data, credentials, secrets, and other sensitive information.
- Support implementation and tuning of DLP/data security monitoring use cases.
SIEM Engineering, Use Cases & Fine-Tuning
- Own/lead SIEM operations and engineering.
- Develop, implement, review, and continuously fine-tune SIEM detection use cases.
- Build correlation rules and detection logic based on threat intelligence, MITRE ATT&CK;, security incidents, and vulnerability information.
- Reduce false positives while improving detection coverage.
- Perform continuous tuning of alerts and correlation rules.
- Map SIEM use cases to MITRE ATT&CK; techniques and tactics.
- Identify detection gaps and develop new use cases.
- Ensure appropriate log collection, parsing, normalization, retention, and monitoring coverage.
AI Security
- Develop security monitoring and incident response capabilities for AI/ML environments and GenAI applications.
- Understand and monitor risks associated with prompt injection, data leakage, model abuse, sensitive information exposure, AI-generated attacks, malicious use of AI, and LLM/application security.
- Work with Application Security, AI/ML, and Engineering teams to establish appropriate security controls and monitoring.
- Track emerging AI-related threats and incorporate relevant detections into the SOC.
RBI / PCI DSS / Regulatory Audits
- Act as the SOC/security operations point of contact for RBI, PCI DSS and other regulatory/security audits.
- Work directly with internal/external audit teams and compliance stakeholders.
- Track and close audit observations and remediation actions.
- Ensure SOC processes and controls remain audit-ready throughout the year rather than only during audit periods.
- Stay current with applicable RBI cybersecurity requirements, PCI DSS requirements, CERT-In directions, and relevant regulatory expectations.
Threat Hunting
- Lead proactive threat hunting activities across endpoints, network, identity, cloud, applications, and data.
- Develop hypotheses based on threat intelligence and emerging attack techniques.
- Hunt for advanced persistent threats, lateral movement, credential abuse, persistence, privilege escalation, and data exfiltration.
- Convert successful threat-hunting findings into permanent SIEM/EDR/cloud detection use cases.
MITRE ATT&CK;
- Use the MITRE ATT&CK; framework to develop detection strategies, map SIEM/EDR/cloud detections, identify monitoring gaps, design threat-hunting activities, and assess SOC detection maturity.
- Maintain an appropriate mapping between threats, attack techniques, and available security controls.
Firewall & WAF Security Reviews
- Lead/perform periodic firewall rule reviews.
- Review network security policies for unnecessary, overly permissive, obsolete, or risky rules.
- Perform Web Application Firewall (WAF) policy/rule reviews.
- Investigate WAF alerts and web attack patterns.
- Work with Network Security and Application Security teams to improve firewall/WAF controls.
- Support review of network segmentation and controls around critical systems.
Threat Intelligence
- Establish and maintain a threat intelligence capability relevant to the FinTech sector.
- Monitor financial-sector threats, ransomware groups, credential theft campaigns, phishing infrastructure, dark-web exposure, brand impersonation, leaked credentials/data, and emerging vulnerabilities.
- Translate intelligence into actionable detection and hunting use cases.
Team Leadership & Capability Development
- Lead, mentor, and develop SOC analysts and engineers.
- Define skill matrices and training plans.
- Conduct technical reviews and knowledge-sharing sessions.
- Build an effective escalation model between L1/L2/L3/L4 teams.
- Participate in hiring and technical evaluation of SOC/security engineering resources.
Required Skills & Expertise Deep, hands-on expertise across several of the following areas is required:
- SIEM: Elastic or equivalent
- EDR/XDR: CrowdStrike (preferred) / Microsoft Defender / SentinelOne or equivalent
- Cloud Security: Strong AWS security experience
- AWS: IAM, CloudTrail, GuardDuty, Security Hub, WAF, VPC, S3, EC2, EKS/ECS, Lambda, KMS
- Network Security: Firewalls, IDS/IPS, VPN, network segmentation
- WAF: WAF policy management, tuning and attack investigation
- Threat Intelligence: IOC/IOA analysis and enrichment
- Threat Hunting: Proactive investigation and hypothesis-driven hunting
- MITRE ATT&CK;: Detection mapping and threat hunting
- Incident Response: L3/L4 investigation and containment
- Digital Forensics: Basic-to-advanced forensic investigation capability
- Data Security/DLP: Data leakage and exfiltration detection
- Attack Surface Management: EASM/external exposure monitoring
- Vulnerability Management: Risk-based prioritization and remediation
- IAM: Identity and privileged access monitoring
- Web/API Security: OWASP concepts, API attacks and web attack detection
- AI/GenAI Security: Understanding of emerging AI security threats and controls
- Security Automation: Python/PowerShell/Bash or equivalent scripting is desirable
Education
- Bachelor of Engineering or Bachelor of Technology (Computer Science, Information Technology, or related field).
- Certificate, Degree, or Diploma in Cybersecurity (advantageous but not mandatory).
Preferred Certifications Not mandatory, but advantageous, one or more of:
- CISSP
- CISM
- GIAC certifications such as GCIH, GCIA, GCFA, GNFA, or relevant SANS certifications
- AWS Security Specialty
- Microsoft/Splunk/SIEM-specific certifications
- PCI Professional / PCI-related certifications
- CEH or equivalent — where relevant
Compensation:
- Full time Role up to INR 20 lakh per annum
- Onsite working
- Immediate start
- This is a Full time consultant role.
- Possibility of onsite travel
Baseel: Baseel Partners LLP (Baseel.com) is a company initially focused on cybersecurity and data protection. Today, Baseel Group has expanded significantly, providing a comprehensive suite of IT services and products to clients in over 100 countries. A distinguished global entity, Baseel Partners LLP has established a solid network of partners across Europe, the UK, Asia, and MENA countries. Baseel has some clients in the area of Data Governance who are looking for MDM implementation.
📌 SOC Manager - Office Based - Bangaluru (Bengaluru)
🏢 Baseel Partners
📍 Bengaluru