SOC Team Lead – Managed Security Services (Bengaluru)

SOC Team Lead – Managed Security Services (Bengaluru)

27 Sep
|
SOCROOM
|
Bengaluru

27 Sep

SOCROOM

Bengaluru

Company Description

SOCRoom by Procain consulting, helps businesses strengthen security operations with continuous monitoring, faster response, and expert SOC support.

We work with organisations that need better visibility, alert handling, incident response, and security operations coverage without building a full SOC in-house.

Our services include Managed SOC, SOC as a Service, SOC Staff Augmentation, Cloud Security Monitoring, threat detection, alert triage, and incident response support.

Built on the principle of Detect. Prevent. Prevail., SOCRoom by Procain consulting, helps teams move from security alerts to real action - faster, sharper, and with greater operational confidence.

Key responsibilities

Team leadership and shift operations

- Lead, mentor and schedule a team of L1/L2 analysts to maintain 24x7 coverage and consistent
- service quality.
- Own shift handovers, ensuring every open incident transfers with current status, next action and
- owner.
- Conduct quality reviews of closed incidents, verifying verdicts (true positive, benign positive,
- false positive) and documentation.
- Coach analysts on investigation methodology, KQL and tooling; drive onboarding and structured
- skills development.

Incident detection and response

- Act as the escalation point for high-severity incidents, including lateral movement, privileged
- account compromise and data exfiltration.
- Direct investigations from initial alert through entity analysis, timeline reconstruction,
- containment and closure.
- Coordinate containment actions with customer IT and security teams, and with L3 / incident
- response specialists where needed.
- Lead post-incident reviews and translate lessons learned into detection and process
- improvements.

Microsoft Sentinel platform ownership

- Oversee analytics rule lifecycle: design, testing, tuning, alert grouping, suppression and
- retirement of noisy rules.




- Develop and review KQL queries, hunting queries, workbooks and watchlists.
- Guide automation using playbooks (Logic Apps) and automation rules to reduce manual triage
- effort.
- Work with engineering teams on data connector onboarding, log source health and ingestion
- cost optimization.

Wazuh operations (where deployed)

- Supervise monitoring of Wazuh-managed customer environments, including agent health, rule
- and decoder tuning, and alert triage.
- Support integration of Wazuh alerts into central SOC workflows and ticketing.

Customer engagement and reporting

- Serve as a technical point of contact for customers during incidents and in regular service
- reviews.
- Produce monthly SOC reports covering incident trends, SLA performance, detection coverage
- and recommendations.
- Ensure adherence to contractual SLAs for time-to-triage, time-to-escalate and time-to-notify.
- Maintain and improve runbooks, escalation matrices and standard operating procedures.

Required qualifications (mandatory)

- Bachelor's degree in Computer Science, Information Security or a related field, or equivalent professional experience.
- 5+ years of experience in a SOC, MSSP or MDR environment, including at least 1–2 years leading or mentoring analysts.
- Hands-on experience with Microsoft Sentinel (minimum 2 years in production), covering analytics rules, incidents, entity investigation, workbooks, watchlists, UEBA and playbooks.
- Robust proficiency in KQL for detection engineering, threat hunting and investigation.




- Working knowledge of the Microsoft security ecosystem: Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID and Azure activity logs.
- Solid understanding of the incident response lifecycle, the MITRE ATT&CK; framework and common attack techniques.
- Good knowledge of networking, Windows and Linux internals, Active Directory and cloud security fundamentals.
- Experience working to customer SLAs in a multi-tenant or managed services environment.
- Excellent written and verbal communication skills, including incident reporting to technical and executive audiences.
- Willingness to work in a 24x7 rotational environment and to be available for on-call escalations.

Preferred qualifications

- Hands-on experience with Wazuh: agent deployment, custom rules and decoders, active response, file integrity monitoring and vulnerability detection.
- Microsoft certifications such as SC-200 (Security Operations Analyst), AZ-500 or SC-100.
- Industry certifications such as GCIH, GCIA, CySA+, BTL1/BTL2, or equivalent incident response credentials.
- Experience with other SIEM/SOAR platforms (Splunk, QRadar, Elastic) and EDR tools (CrowdStrike, SentinelOne).
- Scripting skills in PowerShell or Python for automation and enrichment.
- Exposure to threat intelligence platforms, threat hunting programs and detection-as-code practices.
- Familiarity with compliance frameworks such as ISO 27001, SOC 2, PCI DSS or NIST CSF.

Key competencies

- Leadership: builds a motivated, accountable team and develops analysts into senior contributors.
- Analytical judgment: makes sound, timely decisions under pressure with incomplete information.
- Customer focus: communicates clearly and calmly with customers during active incidents.
- Continuous improvement: uses data to reduce false positives, improve detection coverage and streamline workflows.

📌 SOC Team Lead – Managed Security Services (Bengaluru)
🏢 SOCROOM
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: soc team lead – managed security services (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: soc team lead – managed security services (bengaluru) / bengaluru