30 Sep
|
Relevance Labs
|
Bengaluru
30 Sep
Relevance Labs
Bengaluru
SecOps Lead
Experience
5-6 Years | Cybersecurity / Security Operations
Role Overview
We are looking for a SecOps Lead to lead day-to-day security operations, incident response, threat monitoring, vulnerability management, and security automation across our cloud and enterprise environment. The role requires strong hands-on experience with AWS security, SIEM, EDR, vulnerability management, IAM, and incident response.
Key Responsibilities
Security Operations
- Lead day-to-day SOC/SecOps operations, alert monitoring, triage, investigation and escalation.
- Manage security incidents from detection containment eradication recovery RCA.
- Define and maintain security monitoring rules, use cases, dashboards and playbooks.
- Track and improve MTTD, MTTA and MTTR.
Cloud & Infrastructure Security
- Monitor and secure AWS multi-account environments.
- Review and respond to findings from AWS security services.
- Ensure appropriate logging, monitoring, IAM and security controls across AWS workloads.
Vulnerability Management
- Own vulnerability identification, prioritization and remediation tracking.
- Coordinate remediation of critical/high vulnerabilities with IT, Cloud and Engineering teams.
- Monitor external attack-surface and security-rating findings.
Threat Detection & Response
- Perform threat hunting and investigate suspicious activity across endpoints, identity, network and cloud.
- Maintain Indicators of Compromise (IOCs), detection rules and incident-response playbooks.
- Coordinate malware and endpoint investigations.
Security Automation
- Automate repetitive SecOps activities such as alert enrichment, ticket creation, endpoint isolation,
vulnerability tracking and incident notifications.
- Integrate security platforms with ITSM and collaboration tools.
Key Tools / Technologies
Area
Tools / Technologies
Cloud Security
AWS Security Hub, GuardDuty, Inspector, CloudTrail, AWS Config, IAM, KMS, Secrets Manager
SIEM / Logging
ELK / SIEM platforms, CloudWatch
Endpoint Security
EDR/XDR platforms
Vulnerability Management
Amazon Inspector, Snyk / equivalent, vulnerability scanners
Identity
IAM, IAM Identity Center, Okta / SSO, MFA
Network Security
Palo Alto / Firewalls, VPN, VPC security
DevSecOps
GitHub, CI/CD, SAST, SCA, Container Security, IaC Security
ITSM
Freshservice / ServiceNow / Jira
Automation
Python, PowerShell, Bash, REST APIs
Key Security Processes
Monitor Detect Triage Investigate Contain Remediate Recover RCA Prevent The role will also own/improve:
- Incident Response & Security Incident Management
- Vulnerability Management
- Threat Hunting
- Security Monitoring & Detection Engineering
- Endpoint Security
- Cloud Security Operations
- Security Patch & Remediation Tracking
- Security Automation
- Security Metrics & Reporting
- Audit & Compliance Support – ISO 27001 / SOC 2 / NIST
Desired Profile
- Strong hands-on Security Operations / SOC experience.
- Good understanding of AWS security and cloud environments.
- Experience with SIEM, EDR, vulnerability management and incident response.
- Solid troubleshooting and investigation skills.
- Experience leading a SecOps/SOC team.
- Good scripting/automation skills.
- Robust communication and stakeholder-management skills.
Preferred Certifications: CISSP, CCSP, AWS Security Specialty, GCIH, CISM or equivalent.
📌 SecOps Lead (Bengaluru)
🏢 Relevance Labs
📍 Bengaluru