Posted on: 04/09/2026
Role : Security Operations Center (SOC) Lead
Department : Cyber Operations & Engineering
Location : Mumbai
Experience Required : 8 - 10 Years
Reporting To : Head of Cybersecurity / CISO
Role Summary :
The SOC Lead oversees 24x7 security operations, advanced detection engineering, and high-severity incident response. This role combines technical leadership across SIEM, SOAR, and EDR platforms with operational governance - mentoring Tier-1 and Tier-2 analysts, optimizing runbooks, and ensuring swift threat containment across enterprise environments.
Key Responsibilities :
- Incident Response & Escalations : Serve as the final escalation point for critical (P1/P2) security incidents; direct end-to-end containment, eradication, forensics, and post-incident root cause analysis (RCA).
- Detection Engineering & Tuning : Oversee SIEM correlation rule creation, use-case mapping to the MITRE ATT&CK framework, and alert tuning to eliminate noise and reduce false positives.
- SOAR & Automation : Direct the development of automated incident response playbooks integrated with EDR, firewalls, IAM, and ITSM to consistently lower MTTR and MTTD.
- Threat Hunting & Intelligence : Integrate actionable threat intelligence (CTI) into monitoring workflows and guide proactive threat-hunting exercises across network, endpoint, and cloud assets.
- Operational Governance & Mentorship : Manage analyst shift rotations, define SOC SOPs and runbooks, conduct tabletop simulations, and mentor Tier-1 and Tier-2 engineers.
- Metrics & Executive Reporting : Track and report core operational KPIs (MTTD, MTTR, coverage gaps) and present threat summaries and security posture updates to executive leadership and audit teams.
Required Technical Skills & Qualifications :
- Experience : 8 - 10 years in cyber operations, with at least 3+ years in a senior, L3, or lead capacity within an enterprise SOC or MSSP.
- SIEM/SOAR Expertise : Deep architectural and operational mastery of modern SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, Google SecOps) and SOAR tools (e.g., Cortex XSOAR, Splunk SOAR).
- Threat Detection : Proven ability to map detections to MITRE ATT&CK, investigate complex lateral movement, and analyze advanced attack vectors (ransomware, living-off-the-land techniques).
- Scripting & Telemetry : Hands-on experience analyzing endpoint telemetry (CrowdStrike, Defender, SentinelOne), network logs, and identity systems; working knowledge of Python, PowerShell, or KQL for log query optimization and automation.
- Leadership : Strong track record in team coaching, crisis decision-making, and stakeholder communication.
Preferred Certifications :
- CISSP, CISM, or CCISO
- GIAC Certifications (GCIH, GCFA, GCED, or GNFA)
- Certified SIEM/SOAR Architect (e.g., Splunk Certified Enterprise Security Admin, Microsoft Sentinel SC-200)
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1668608