Posted on: 07/09/2026
Role : SOC Lead - Security Operations
- Senior Role | SOC Operations, Detection Engineering, Incident Command & Team Leadership
Position : SOC Lead / Security Operations Lead
Department : Security Operations Centre (SOC)
Experience : 8+ years in security operations, with at least 2 years in a lead or senior analyst capacity
Location : Pune (Hybrid (2 days work from Home) - Shift role - not exceeding 11 PM IST
Employment Type : Full-time
Reports To : SOC Manager / Head of Security Services
Team Size : Leads a team of L1 and L2 analysts across a 24x7 roster
Education : B.E. / B.Tech / MCA / M.Sc. in Computer Science, IT or Cyber Security
Role Overview :
We are looking for a senior security professional to lead our Security Operations Centre. The SOC Lead owns detection quality, incident response outcomes and analyst capability.
Depth in SOC operations is non-negotiable, but this role also requires solid breadth - you should be able to read a VAPT report and judge which findings actually matter, discuss network and infrastructure design with the engineering teams, and translate all of it into detection coverage and risk conversations with senior stakeholders. This is a hands-on leadership role, not a purely managerial one.
Key Responsibilities - SOC Operations & Leadership :
- Own end-to-end 24x7 SOC operations - shift rostering, escalation matrix, workload distribution, quality review and SLA / SLO adherence across enterprise and multi-tenant client environments.
- Act as the final technical escalation point for L1 and L2, and take incident command during major or high-severity incidents.
- Own the incident response process - playbooks, containment and eradication decisions, root cause analysis, post-incident review and lessons-learned tracking.
- Define, track and report SOC KPIs and metrics : MTTD, MTTR, alert volume and disposition, false positive ratio, detection coverage, log source health and analyst productivity.
- Present incident, threat and performance briefings to senior management and client stakeholders; own monthly and quarterly governance reporting.
- Recruit, mentor, train and appraise analysts; define competency matrices, training paths and certification plans; run internal knowledge-sharing and tabletop exercises.
Key Responsibilities - Detection, Threat & Platform :
- Own the detection engineering roadmap and use-case lifecycle - requirement gathering, development, testing, tuning, versioning and retirement - across FortiSIEM, Elastic Security and other platforms.
- Review and approve parsers, correlation rules, Sigma rules and log source onboarding designs built by the L2 team.
- Lead the threat hunting programme and purple-team exercises; validate and continuously improve detection coverage against MITRE ATT&CK.
- Own SIEM platform architecture, sizing, EPS and licence management, upgrades, integrations and overall health.
- Drive SOAR adoption and automation to reduce manual analyst effort and shorten response times.
- Consume and operationalise threat intelligence - feeds, IOC management, sector-specific threat briefs and proactive advisories.
Key Responsibilities - VAPT, Network & Infrastructure Interface :
- Review VAPT and vulnerability assessment output; correlate findings with detection coverage, asset criticality and exploitability to prioritise real risk.
- Advise network and infrastructure teams on segmentation, hardening, logging requirements and control gaps identified during investigations.
- Contribute to security architecture reviews for new applications, infrastructure and cloud workloads.
- Own the vulnerability management governance loop - tracking, escalation, exception management and closure verification.
- Support audits and compliance programmes - ISO 27001, PCI-DSS, SOC 2, RBI / SEBI frameworks - including evidence, control mapping and auditor interaction.
Technical Skills & Tools Required :
- SIEM & Detection : FortiSIEM and Elastic Security in depth (mandatory); exposure to Splunk, IBM QRadar or Microsoft Sentinel is an advantage. Parser design, correlation logic, Sigma, detection-as-code.
- SOAR & Automation : FortiSOAR, Cortex XSOAR, TheHive / Cortex, Shuffle; Python, PowerShell and Bash automation, REST API integration.
- EDR / XDR & Endpoint : CrowdStrike Falcon, SentinelOne, Microsoft Defender for Endpoint, FortiEDR, Sysmon, YARA.
- Network & Perimeter Security : NGFW (FortiGate, Palo Alto, Cisco), IDS/IPS (Suricata, Snort), WAF, proxy, NDR, DDoS protection, VPN, NAC.
- Vulnerability & Offensive Tooling : Nessus, Qualys, Rapid7, OpenVAS; working familiarity with Nmap, Burp Suite, Metasploit, BloodHound and Impacket to assess VAPT findings credibly.
- Adversary Emulation : MITRE Caldera, Atomic Red Team, Prelude; purple team exercise design.
- Threat Intelligence : MISP, Cyble Vision, Recorded Future, OpenCTI, VirusTotal, OSINT and dark web intelligence sources.
- Cloud & Identity Security : AWS CloudTrail / GuardDuty / Security Hub, Azure Defender and Entra ID, Microsoft 365 security, CSPM concepts, Kubernetes and container logging.
- Forensics & Analysis : Wireshark, Zeek, Volatility, FTK Imager, Autopsy, KAPE, log and memory triage.
- Governance & Reporting : ServiceNow, Jira, Confluence, Grafana, Power BI / Excel for metrics; risk registers and RACI models.
Core Concepts You Must Know :
- SOC operating models - in-house, MSSP, hybrid and co-managed; tiering, shift design, follow-the-sun, and SLA / OLA definition.
- Detection engineering discipline - hypothesis-driven use cases, detection-as-code, testing and coverage measurement.
- MITRE ATT&CK, D3FEND, ATT&CK Navigator, Cyber Kill Chain, Diamond Model and the Pyramid of Pain.
- Incident response and management frameworks - NIST SP 800-61, ISO/IEC 27035, SANS IR process, crisis communication and regulatory breach notification timelines (including CERT-In reporting requirements).
- Digital forensics fundamentals - evidence acquisition, disk and memory analysis, timeline reconstruction, chain of custody.
- Threat intelligence lifecycle and intelligence-driven defence; strategic, operational and tactical intel.
- Log architecture and engineering - ingestion sizing, EPS forecasting, normalisation and taxonomy, ECS/CIM, retention, ILM and cost control.
- Network and security architecture - segmentation, DMZ design, zero trust, east-west visibility, identity-centric controls.
- Vulnerability and risk management - CVSS, EPSS, CISA KEV, asset criticality, risk acceptance and compensating controls.
- Penetration testing methodology and how offensive findings translate into detections and hardening actions.
- Governance and compliance - ISO 27001, NIST CSF, PCI-DSS, SOC 2, RBI Cyber Security Framework, SEBI CSCRF, DPDP Act.
- People leadership - hiring, coaching, performance management, burnout prevention and retention in a 24x7 environment.
Qualifications & Certifications :
- 8+ years in security operations with demonstrable ownership of detection content, incident response and team leadership.
- Prior experience leading a SOC shift or pod, or running SOC operations for a client / MSSP engagement.
- Preferred certifications : CISSP, CISM, GCIA / GCIH / GCFA, CEH, Fortinet NSE 5 / NSE 7, Elastic Certified Engineer, ISO 27001 Lead Auditor; OSCP is a strong differentiator.
- Excellent communication - able to write a board-level incident summary and a technical RCA with equal confidence.
Good To Have :
- Experience building or maturing a SOC from the ground up, or migrating between SIEM platforms.
- BFSI, fintech or critical infrastructure client experience with regulatory audit exposure.
- Threat research, detection publication, conference speaking or community contribution.
- Exposure to OT / ICS security monitoring and cloud-native security operations.
What We Offer :
- Exposure to enterprise and BFSI-grade security environments and real-world adversary activity.
- Access to company's threat intelligence platform and a strong internal knowledge-sharing culture.
- Sponsored certifications, training and structured career progression within the security practice.
- Competitive compensation, medical coverage and a collaborative, growth-oriented team.
The job is for:
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
Cyber Security
Job Code
1669042