Manager, SOC Governance & Incident Oversight (India)

Manager, SOC Governance & Incident Oversight (India)

08 Oct
|
Talent Socio
|
India

08 Oct

Talent Socio

India

About our client:

Overview of the company: Our client is a top non-banking financial company in India focused on rural and semi-urban areas, offering vehicle loans, fixed deposits, and SME financing. It serves over 9 million customers through a large network of more than 1,380 offices across the country.

1. Role Purpose Responsible for governance and oversight of the outsourced Security Operations Centre (SOC) function, including independent validation of SOC performance, security incident closure, alert quality, service-level adherence and applicable regulatory requirements. The role will provide physical oversight of IBM SOC operations from Bengaluru, drive effective utilization of existing security investments, improve SOC processes and independently validate the quality and completeness of SOC deliverables and incident closures.

2. Key Responsibilities

A. SOC Governance & Service Oversight

Provide day-to-day governance and oversight of the outsourced IBM SOC function.

Operate from Bengaluru to facilitate physical oversight and effective coordination with the SOC.

Review SOC operations against agreed SLAs, KPIs, processes and security requirements.

Independently validate SOC reports, dashboards, metrics and operational deliverables submitted by IBM.

Identify service gaps, recurring issues and control weaknesses and track them to closure.

Coordinate with internal Information Security stakeholders and IBM SOC teams for operational governance.

B. Security Incident Oversight & Quality Assurance

Monitor security incidents handled by the SOC and ensure adherence to defined response and closure TATs.

Perform quality checks on incident categorization, severity assessment, investigation summary and closure justification.

Independently validate evidence supporting incident closure before acceptance.

Track overdue, recurring and high-risk security incidents and escalate deviations appropriately.

Review incident trends and identify opportunities to strengthen detection and response capabilities.

Ensure appropriate root-cause analysis and corrective actions are documented for significant incidents.

C. Regulatory Compliance & RBI Requirement Oversight

Monitor SOC processes and incident management activities against applicable regulatory requirements.

Track compliance with RBI Observations relating to timely closure of security incidents.





Maintain evidence and management reporting required to demonstrate adherence to incident closure TATs.

Track regulatory observations, audit findings and remediation actions relating to SOC operations.

Support internal, regulatory and audit reviews by providing validated SOC governance and incident management evidence.

D. Alert & Detection Governance

Review the quality and effectiveness of security alerts generated by the SOC.

Monitor false-positive trends and coordinate with SOC teams for appropriate rule tuning.

Review alert categorization, prioritization and escalation mechanisms.

Identify gaps in detection coverage and recommend improvements to monitoring use cases. Confidential Human Resources / Information Security

Ensure changes to detection rules and monitoring logic are appropriately documented and governed.

E. Threat Hunting & Incident Investigation Oversight

Coordinate and oversee threat-hunting activities for significant or suspicious security events.

Review incidents indicating potential malware, ransomware or advanced threat activity.

Ensure appropriate investigation and threat-hunting activities are performed following significant SIEM alerts.

Review investigation findings and ensure remediation and preventive actions are tracked.

Identify recurring attack patterns and recommend improvements to SOC detection capabilities.

F. SIEM & Log Governance

Review SIEM log sources and ensure appropriate security-relevant events are being monitored.

Drive optimization of log ingestion to focus on Events of Interest and improve monitoring effectiveness.

Review log correlation requirements and identify opportunities for improved detection through correlation.

Coordinate with infrastructure, application and security teams for relevant log-source onboarding and optimization.

Review SIEM use cases and identify opportunities for automation and improved detection efficiency.

G. Security Tool Utilization & Automation

Identify opportunities to maximize existing Information Security investments including DLP, DAM, Security.AI, IS GRC, Palo Alto security products and SIEM capabilities.





Identify repetitive SOC governance and monitoring activities that can be automated.

Coordinate with technical teams and vendors for integration and automation initiatives.

Track implementation and effectiveness of agreed automation initiatives.

H. Reporting, Metrics & Management Governance

Prepare and review periodic SOC governance dashboards and management reports.

Track incident volumes and severity, closure TAT, SLA adherence, false-positive trends, alert quality, recurring incidents, threat-hunting activities, open incidents and regulatory/audit observations.

Provide management with meaningful insights on SOC effectiveness and areas requiring improvement.

Ensure accuracy and completeness of reports received from the outsourced SOC.

3. Key Deliverables

Effective governance and oversight of outsourced SOC operations.

Independent validation of SOC reports and deliverables.

Timely closure and quality assurance of security incidents.

Compliance tracking for regulatory and audit observations, including RBI requirements.

Improved alert quality and reduction of unnecessary false positives.

Improved SIEM log optimization and correlation.

Effective oversight of threat-hunting activities.

Increased utilization and automation of existing security tools.

Accurate and timely SOC management reporting.

Continuous improvement of SOC processes, controls and service quality.

4. Key Interfaces Internal Stakeholders

Information Security / Cyber Security Leadership

Infrastructure & Network teams

Application / Technology teams Confidential Human Resources / Information Security

Risk & Compliance

Internal Audit

Regulatory Compliance teams External Stakeholders

IBM SOC / MSSP

Security technology vendors

Managed security service providers

Auditors and assessment teams

5. Candidate Profile Education: Bachelor's degree in Computer Science, Information Technology, Cyber Security or a related discipline. Relevant certifications such as CISSP, CISM, CRISC, CEH, Security+ or equivalent are advantageous. Experience: Relevant experience in SOC governance, security operations oversight, incident management, cyber security governance or MSSP management, preferably in an outsourced SOC setting. Experience with SIEM, security monitoring, incident lifecycle management, SLA/TAT monitoring and regulatory/audit requirements is desirable.

📌 Manager, SOC Governance & Incident Oversight (India)
🏢 Talent Socio
📍 India

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager, soc governance & incident oversight (india) / india

Subscribe to this job alert:

Get the latest job offers by email for: manager, soc governance & incident oversight (india) / india