Cybersecurity SOC Incident Response and Threat Intelligence Manager (Kochi)

Cybersecurity SOC Incident Response and Threat Intelligence Manager (Kochi)

02 Oct
|
EY
|
Kochi

02 Oct

EY

Kochi

Job Summary

As a Manager in EY s Cybersecurity practice, you will play a pivotal role in delivering advanced Security Operations, Incident Response, Security Orchestration, and Threat Intelligence services across diverse client environments. We are seeking a Security Operations Manager to support MSSP and multi-tenant Security Operations Centers (SOC), administering, deploying, and overseeing IBM QRadar SIEM, Splunk Enterprise, ELK Stack, IBM SOAR Resilient, and CTM360 Threat Management Platform. The role supports multiple client environments across IT and OT ecosystems, ensuring effective threat detection, incident response, security orchestration, and threat intelligence operations. Candidates may have expertise in one or more platforms, with opportunities for cross-training and growth across the security operations technology stack.

The Opportunity

We are seeking cybersecurity professionals with 12+ years of experience in Security Operations, Incident Response, Threat Intelligence, Cyber Defence, or cybersecurity consulting. The ideal candidate will possess deep expertise in SIEM, SOAR, and Threat Intelligence platforms while demonstrating the ability to lead client engagements, manage security operations teams, and contribute to the growth of EYs managed security services capabilities. High-performing individuals who demonstrate leadership, innovation, and alignment with EYs values and talent policies may be considered for accelerated career progression and leadership opportunities within the cybersecurity practice.

Key Responsibilities

SIEM Administration - IBM QRadar, Splunk ELK Stack (IT OT Security Monitoring)

- Deploy, configure, and administer IBM QRadar, Splunk, and ELK Stack SIEM platforms across multiple client environments.
- Design and implement SIEM use cases, correlation rules, dashboards, and reporting mechanisms.
- Integrate log sources from network, endpoint, cloud, application, and OT environments.
- Monitor and optimize SIEM performance, health, and event processing capabilities.
- Perform tuning of offense rules to minimize false positives and improve detection efficiency.
- Support onboarding of recent customers,



assets, and log sources into the managed SOC environment.
- Lead investigations of security alerts, incidents, and suspicious activities identified through IBM QRadar, Splunk, and ELK Stack.
- Develop and maintain detection content aligned to evolving threat landscapes and industry best practices.
- Support incident response activities, forensic investigations, and root cause analysis.
- Collaborate with stakeholders to improve security visibility across IT and OT environments.
- Communicate complex technical concepts to senior stakeholders and business leaders.
- Mentor junior consultants and SOC analysts, fostering a culture of continuous learning and operational excellence.

SOAR Engineering Security Automation

- Deploy and configure SOAR platforms such as Phantom, XSOAR, Resilient supporting multi-tenant MSSP operations.
- Design and implement automated incident response workflows and response playbooks.
- Develop integrations between SOAR, SIEM, endpoint security, ticketing systems, and threat intelligence platforms.
- Configure incident types, workflows, tasks, and escalation processes for client environments.
- Maintain and enhance security orchestration workflows to improve SOC efficiency and response times.
- Troubleshoot integration, automation, and workflow performance issues.
- Collaborate with SOC teams to identify automation opportunities across incident handling processes.
- Lead customer onboarding, migration, and expansion activities within SOAR platforms.
- Develop custom scripts and automation use cases using supported APIs and integration frameworks.
- Ensure governance, auditability, and operational effectiveness of automated response actions.




- Support SOC analysts during complex incident investigations and escalations.
- Mentor junior consultants and engineers in automation best practices.

Threat Intelligence Operations

- Deploy, configure, and manage Threat Management Platform such as CTM360, CyberArk, BitSight, RecordedFuture capabilities across client environments.
- Monitor external threat exposure and digital attack surfaces for multiple clients.
- Perform threat intelligence analysis to identify emerging threats, adversary activities, and indicators of compromise (IOCs).
- Correlate threat intelligence findings with SIEM and SOAR platforms to enhance detection capabilities.
- Develop threat intelligence reports, executive briefings, and strategic risk assessments.
- Monitor brand exposure, domain threats, credential leaks, phishing campaigns, and digital risks.
- Support proactive threat hunting activities using intelligence-driven methodologies.
- Create and maintain threat detection use cases based on intelligence findings.
- Collaborate with incident response teams during active cyber incidents.
- Provide actionable recommendations to clients for risk mitigation and exposure reduction.
- Support intelligence sharing and threat-informed defines initiatives.

Security Operations Incident Response Leadership

- Lead security monitoring, threat detection, incident response, and threat intelligence activities across multiple client environments.
- Manage MSSP service delivery, ensuring adherence to SLAs, KPIs, and operational objectives.
- Support major incident management, cyber crisis response, and post-incident reviews.
- Coordinate across security, infrastructure, cloud, and application teams during investigations.
- Conduct regular service reviews and provide recommendations for security posture improvement.
- Drive operational excellence through process improvement, automation, and innovation.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Cybersecurity SOC Incident Response and Threat Intelligence Manager (Kochi)
🏢 EY
📍 Kochi

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity soc incident response and threat intelligence manager (kochi) / kochi

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity soc incident response and threat intelligence manager (kochi) / kochi