Security Operations SME (Mumbai)

Security Operations SME (Mumbai)

09 Oct
|
Persistent
|
Mumbai

09 Oct

Persistent

Mumbai

Job Description

About Persistent

We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what’s next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem.

Our disruptor’s mindset, commitment to client success, and agility to thrive in the dynamic environment have enabled us to sustain our growth momentum. Persistent has been recognized across top industry platforms for innovation, leadership, and inclusion. We reported $1,654.4M FY26 revenue with 17.4% Y-o-Y growth. We have delivered 24 sequential quarters of growth with $436.0M in Q4 FY26 revenue, up 3.2% Q-o-Q and 16.2% Y-o-Y growth. Our 27,500+ global team members, located in 18 countries, have been instrumental in helping the market leaders transform their industries. We have been recognized as the Fastest Growing IT Services Brand Globally in the 2026 Brand Finance IT Services 25 Report. We named a Leader in the Everest Group Private Equity (PE) Services PEAK Matrix® Assessment 2026 and Software Product Engineering PEAK Matrix® Assessment 2026.

About Position:

We are seeking a highly skilled Security Operations SME (L3) to serve as the senior technical escalation point for complex and high-severity cyber incidents. This role plays a critical part in leading advanced investigations, incident response, proactive threat hunting, and continuous improvement of detection and monitoring capabilities within the Security Operations Center (SOC). The ideal candidate will collaborate closely with Incident Response, Threat Intelligence, Infrastructure, Endpoint, Network, Cloud, and Application teams to strengthen the organization's overall security posture.

-
Role: Security Operations SME (L3)
- Location: Mumbai
- Experience: 8 to 12 Years
- Job Type: Full-Time Employment

What You'll Do:

- Act as the Level 3 escalation point for complex, high-severity, and multi-domain security incidents.
- Lead deep-dive investigations to determine attack scope, root cause, affected assets, business impact, and attacker tactics, techniques, and procedures.
- Drive incident containment, eradication, recovery, post-incident reviews, and corrective-action tracking with relevant technical teams.
- Conduct advanced analysis across SIEM events, endpoint telemetry, network traffic, identity activity, cloud logs, malware indicators, and threat intelligence sources.




- Perform proactive threat hunting and develop threat-hunting hypotheses aligned with MITRE ATT&CK; and emerging threat patterns.
- Design, tune, validate, and maintain correlation rules, detection use cases, alerts, dashboards, and investigation content.
- Reduce false positives, identify detection gaps, and improve monitoring coverage using lessons learned from incidents and threat intelligence.
- Develop and maintain incident response playbooks, SOPs, runbooks, escalation procedures, and knowledge articles.
- Optimize SIEM, EDR/XDR, SOAR, and related security tools while troubleshooting integration, monitoring, performance, and data quality issues.
- Provide technical guidance, mentoring, case reviews, and knowledge-sharing sessions for L1 and L2 analysts.
- Prepare incident reports, root-cause analyses, executive summaries, and technical recommendations.
- Support audits, tabletop exercises, service reviews, operational metrics, and continuous improvement initiatives.
- Participate in shift rotations and on-call support for critical security incidents as required.

Expertise You'll Bring:

- Extensive experience in Security Operations Center (SOC) operations, incident response, security monitoring, and cyber investigations.
- Advanced hands-on experience with SIEM platforms such as Splunk Enterprise Security, Microsoft Sentinel, IBM QRadar, or equivalent solutions.
- Experience with EDR/XDR technologies including Microsoft Defender for Endpoint, CrowdStrike Falcon, Carbon Black, or similar platforms.
- Strong log analysis expertise across endpoint, network, server, application, identity, and cloud data sources.
- Deep knowledge of threat hunting, IOC analysis, attack-chain reconstruction, malware triage, and digital forensic fundamentals.
- Strong understanding of MITRE ATT&CK;, common cyberattack techniques, threat actor methodologies, and incident response lifecycle management.
- Experience developing, tuning, and optimizing SIEM correlation rules, threat detection content, searches, alerts, dashboards, and reports.
- Exposure to SOAR platforms, automated workflows, orchestration playbooks, and security automation initiatives.
- Working knowledge of Windows, Linux, TCP/IP, DNS, HTTP/S, Active Directory, Entra ID, authentication technologies, and cloud environments.
- Scripting and automation experience using Python, PowerShell, Bash, or similar technologies.




- Excellent analytical, troubleshooting, documentation, stakeholder management, and communication skills.
- Experience working within enterprise SOC or Managed Security Service Provider (MSSP) environments.
- Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent professional experience.
- Relevant certifications such as CISSP, GCIH, GCIA, GCFA, Splunk, Microsoft Security, CrowdStrike, or equivalent security certifications.
- Experience presenting incident findings and security recommendations to both technical and non-technical audiences.
- Proven ability to manage high-severity incidents and drive effective incident response activities.
- Strong leadership and mentoring capabilities for guiding junior analysts and improving SOC maturity.
- Ability to collaborate effectively across multiple technical teams and business stakeholders.
- Strong focus on continuous improvement, detection engineering, threat intelligence integration, and operational excellence.
- Commitment to staying current with evolving cybersecurity threats, technologies, and industry best practices.

Benefits:

- Competitive salary and advantages package
- Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
- Opportunity to work with cutting-edge technologies
- Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
- Annual health check-ups
- Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents

Values-Driven, People-Centric & Inclusive Work Environment:

Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.

- We support hybrid work and flexible hours to fit diverse lifestyles.
- Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
- If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment

Let’s unleash your full potential at Persistent - persistent.com/careers

“Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.”

1

Open Positions

Identity and Access Management-Entra ID,Security testing

Skills Required

Mumbai

Location

Identity and Access Management-Entra ID,Security testing

Desirable Skills

188653

Job Code

📌 Security Operations SME (Mumbai)
🏢 Persistent
📍 Mumbai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security operations sme (mumbai) / mumbai