SOC LEAD - SIEM/EDR
Anveta Manpower Solutions•Hyderabad
Full-timeLead
👁️ 0 views•📝 0 applications•Posted 8/18/2026•Expires 9/28/2026
Get alerts for roles like this
More SOC LEAD - SIEM/EDR roles in Hyderabad — straight to your inbox. No account needed.
Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.
Job Description
Role : Security Operations Lead
Job Description :
We are looking for an experienced Security Operations Lead to provide functional leadership, technical direction, and operational oversight for our Security Operations Center (SOC). The role will focus on strengthening threat detection, incident response, investigation quality, and continuous improvement across cybersecurity operations.
Key Responsibilities :
- Provide functional leadership and operational coordination for 24x7 SOC shift activities.
- Lead and guide SOC analysts during security investigations and ensure investigation quality standards are maintained.
- Monitor, triage, investigate, and coordinate the response to security incidents from initial alert through documented closure.
- Perform hands-on investigation of security events using SentinelOne EDR, Mimecast, SIEM, and other security platforms.
- Investigate phishing, malware, endpoint compromise, suspicious authentication activity, and other security incidents.
- Develop, maintain, and improve SOC SOPs, runbooks, and playbooks covering alert triage, escalation, containment, and closure.
- Develop SIEM detection use cases, write queries, tune alert rules, and reduce false positives.
- Manage the SIEM use-case lifecycle from threat scenario identification through detection logic design, testing, implementation, and continuous tuning.
- Enrich alerts using threat intelligence and map observed indicators and attacker activity to the MITRE ATT&CK framework.
- Conduct alert quality reviews and ensure investigation findings are adequately documented before ticket closure.
- Support post-incident analysis, Root Cause Analysis (RCA), incident reporting, and continuous improvement initiatives.
- Build and maintain dashboards and reports for incident tracking, SLA visibility, and SOC performance.
- Use ServiceNow for incident management, ticket tracking, SLA monitoring, and reporting.
- Guide and coach L1/L2 SOC analysts on investigation techniques, documentation standards, and security tool usage.
- Support vulnerability management activities using Tenable or equivalent tools.
- Coordinate with Incident Response, Threat Management, IT, external MDR partners, and other stakeholders during security incidents.
- Participate in shift handovers, coverage planning, task allocation, and operational governance.
Required Technical Skills :
- Strong hands-on experience in 24x7 SOC operations, incident detection, triage, investigation, and response.
- Hands-on experience with SentinelOne EDR, Mimecast, and SIEM platforms (Microsoft Sentinel, Rapid7, IBM QRadar).
- Strong understanding of the MITRE ATT&CK framework, SOC SOPs, and ServiceNow.
- Knowledge of Windows/Linux, scripting (PowerShell/Bash/Python), Tenable, SOAR, and cloud security (Entra ID, AWS).
Experience Requirements :
- 7 to 10 years of experience in Information Security / Cybersecurity.
- Minimum 2+ years of experience as a Technical Lead, SOC Lead, Shift Lead, or Senior Analyst in a 24x7 SOC environment.
Education & Certifications :
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience preferred.
- Preferred Certifications : CompTIA Security+, CySA+, GSEC, SC-200, CISSP, SentinelOne, or Mimecast certifications.
Shift Requirement :
- This role requires participation in 24x7 rotational shift operations and support for APAC time zones.
Immediate joiners or candidates with a short notice period are preferred.
Required Skills
AWSDocumentationLeadershipLinuxPythonRoot Cause Analysis
Prepare to Win This Role
Everything you need to ace the interview and negotiate top-of-band compensation.