HamburgerMenu
hirist

Security Operations Center Lead - Cyber Operations

Employee Forums
8 - 10 Years
rupee27-30 LPA
Mumbai

Posted on: 04/09/2026

Job Description

Role : Security Operations Center (SOC) Lead

Department : Cyber Operations & Engineering

Location : Mumbai

Experience Required : 8 - 10 Years

Reporting To : Head of Cybersecurity / CISO

Role Summary :

The SOC Lead oversees 24x7 security operations, advanced detection engineering, and high-severity incident response. This role combines technical leadership across SIEM, SOAR, and EDR platforms with operational governance - mentoring Tier-1 and Tier-2 analysts, optimizing runbooks, and ensuring swift threat containment across enterprise environments.

Key Responsibilities :

- Incident Response & Escalations : Serve as the final escalation point for critical (P1/P2) security incidents; direct end-to-end containment, eradication, forensics, and post-incident root cause analysis (RCA).

- Detection Engineering & Tuning : Oversee SIEM correlation rule creation, use-case mapping to the MITRE ATT&CK framework, and alert tuning to eliminate noise and reduce false positives.

- SOAR & Automation : Direct the development of automated incident response playbooks integrated with EDR, firewalls, IAM, and ITSM to consistently lower MTTR and MTTD.

- Threat Hunting & Intelligence : Integrate actionable threat intelligence (CTI) into monitoring workflows and guide proactive threat-hunting exercises across network, endpoint, and cloud assets.

- Operational Governance & Mentorship : Manage analyst shift rotations, define SOC SOPs and runbooks, conduct tabletop simulations, and mentor Tier-1 and Tier-2 engineers.

- Metrics & Executive Reporting : Track and report core operational KPIs (MTTD, MTTR, coverage gaps) and present threat summaries and security posture updates to executive leadership and audit teams.

Required Technical Skills & Qualifications :

- Experience : 8 - 10 years in cyber operations, with at least 3+ years in a senior, L3, or lead capacity within an enterprise SOC or MSSP.

- SIEM/SOAR Expertise : Deep architectural and operational mastery of modern SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, Google SecOps) and SOAR tools (e.g., Cortex XSOAR, Splunk SOAR).

- Threat Detection : Proven ability to map detections to MITRE ATT&CK, investigate complex lateral movement, and analyze advanced attack vectors (ransomware, living-off-the-land techniques).

- Scripting & Telemetry : Hands-on experience analyzing endpoint telemetry (CrowdStrike, Defender, SentinelOne), network logs, and identity systems; working knowledge of Python, PowerShell, or KQL for log query optimization and automation.

- Leadership : Strong track record in team coaching, crisis decision-making, and stakeholder communication.

Preferred Certifications :

- CISSP, CISM, or CCISO

- GIAC Certifications (GCIH, GCFA, GCED, or GNFA)

- Certified SIEM/SOAR Architect (e.g., Splunk Certified Enterprise Security Admin, Microsoft Sentinel SC-200)

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...