30 Sep
|
Infosec Arabia Company Information Systems
|
Kozhikode
30 Sep
Infosec Arabia Company Information Systems
Kozhikode
Role & responsibilities
- Lead and manage SOC analysts and security engineers, including workload allocation, escalations, mentoring, and service delivery.
- Oversee daily SOC operations, incident management, threat hunting, and complex security investigations.
- Develop and improve SOC procedures, playbooks, escalation workflows, and operational processes.
- Manage and optimize SIEM, EDR/XDR, firewalls, IDS/IPS, VPN, WAF, DLP, NAC, Email Security, and related security platforms.
- Oversee SIEM use cases, detection rules, alert tuning, dashboards, log integrations, and detection coverage aligned with MITRE ATT&CK.;
- Lead major incident response activities including containment, recovery, root cause analysis, and post-incident review.
- Support cybersecurity governance, risk, audit, and compliance activities aligned with ISO 27001, NIST, and customer requirements.
- Review and maintain security policies, procedures, standards, and operational documentation.
- Coordinate with customers, vendors, infrastructure, network, cloud, application, and business teams on security matters.
- Track SOC KPIs, SLAs, incident trends, and service performance, and prepare management and executive-level reports.
Preferred candidate profile
- Bachelor's degree in Cyber Security, Information Security, Computer Science, Information Technology, or related discipline.
- Minimum 89 years of experience in cybersecurity, SOC operations, security engineering, or related security roles.
- Previous experience leading SOC analysts, cybersecurity engineers, or security operations teams.
- Robust hands-on experience with SIEM administration and detection engineering.
- Experience with Microsoft Sentinel and other enterprise SIEM platforms.
- Strong experience with EDR/XDR technologies including SentinelOne, Microsoft Defender for Endpoint, CrowdStrike, or equivalent platforms.
- Strong knowledge of enterprise firewall technologies including Palo Alto, Fortinet, and Cisco.
- Experience with IDS/IPS, VPN, WAF, DLP, NAC, Email Security, and vulnerability management technologies.
- Strong understanding of incident response, threat hunting, security monitoring, and forensic investigation processes.
- Experience developing SOC processes, incident response procedures, detection use cases, and security playbooks.
- Knowledge of NIST, MITRE ATT&CK;, ISO 27001, and cybersecurity governance principles.
- Experience supporting security audits, risk assessments, and compliance activities.
- Strong troubleshooting, analytical, and technical decision-making capabilities.
- Strong documentation, reporting, presentation, and stakeholder management skills.
Preferred Certifications
Relevant certifications may include
- CISSP
- CISM
- Microsoft Security Certifications
- GIAC / Incident Response / SOC-related certifications
- CEH
- Palo Alto PCNSA / PCNSE
- Fortinet FCP / FCSS or equivalent
Key Skills
- SOC Leadership &
- Team Management
- Security Operations Management
- Security Engineering
- SIEM Engineering &
- Administration
- Detection Engineering
- Incident Response &
- Forensics
- Threat Hunting
- Threat Intelligence
- Security Architecture &
- Infrastructure
- ISO 27001 &
- NIST Cybersecurity Framework
📌 SOC Team Lead / Senior Cyber Security Engineer (Kozhikode)
🏢 Infosec Arabia Company Information Systems
📍 Kozhikode