Skip to main content
← Back to Jobs

Security Operations Center Lead - Cyber Operations

Employee ForumsMumbai
Full-timeLead
₹27L - ₹30L
per year
👁️ 0 views📝 0 applicationsPosted 9/4/2026Expires 10/4/2026
Tailor Resume for This JobCheck ATS Score

Get alerts for roles like this

More Security Operations Center Lead - Cyber Operations roles in Mumbai — straight to your inbox. No account needed.

Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.

Job Description

Role : Security Operations Center (SOC) Lead Department : Cyber Operations & Engineering Location : Mumbai Experience Required : 8 - 10 Years Reporting To : Head of Cybersecurity / CISO Role Summary : The SOC Lead oversees 24x7 security operations, advanced detection engineering, and high-severity incident response. This role combines technical leadership across SIEM, SOAR, and EDR platforms with operational governance - mentoring Tier-1 and Tier-2 analysts, optimizing runbooks, and ensuring swift threat containment across enterprise environments. Key Responsibilities : - Incident Response & Escalations : Serve as the final escalation point for critical (P1/P2) security incidents; direct end-to-end containment, eradication, forensics, and post-incident root cause analysis (RCA). - Detection Engineering & Tuning : Oversee SIEM correlation rule creation, use-case mapping to the MITRE ATT&CK framework, and alert tuning to eliminate noise and reduce false positives. - SOAR & Automation : Direct the development of automated incident response playbooks integrated with EDR, firewalls, IAM, and ITSM to consistently lower MTTR and MTTD. - Threat Hunting & Intelligence : Integrate actionable threat intelligence (CTI) into monitoring workflows and guide proactive threat-hunting exercises across network, endpoint, and cloud assets. - Operational Governance & Mentorship : Manage analyst shift rotations, define SOC SOPs and runbooks, conduct tabletop simulations, and mentor Tier-1 and Tier-2 engineers. - Metrics & Executive Reporting : Track and report core operational KPIs (MTTD, MTTR, coverage gaps) and present threat summaries and security posture updates to executive leadership and audit teams. Required Technical Skills & Qualifications : - Experience : 8 - 10 years in cyber operations, with at least 3+ years in a senior, L3, or lead capacity within an enterprise SOC or MSSP. - SIEM/SOAR Expertise : Deep architectural and operational mastery of modern SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, Google SecOps) and SOAR tools (e.g., Cortex XSOAR, Splunk SOAR). - Threat Detection : Proven ability to map detections to MITRE ATT&CK, investigate complex lateral movement, and analyze advanced attack vectors (ransomware, living-off-the-land techniques). - Scripting & Telemetry : Hands-on experience analyzing endpoint telemetry (CrowdStrike, Defender, SentinelOne), network logs, and identity systems; working knowledge of Python, PowerShell, or KQL for log query optimization and automation. - Leadership : Strong track record in team coaching, crisis decision-making, and stakeholder communication. Preferred Certifications : - CISSP, CISM, or CCISO - GIAC Certifications (GCIH, GCFA, GCED, or GNFA) - Certified SIEM/SOAR Architect (e.g., Splunk Certified Enterprise Security Admin, Microsoft Sentinel SC-200)

Required Skills

AuditCybersecurityKPI ManagementLeadershipPythonRoot Cause AnalysisStakeholder ManagementSwift

The best-paying roles in your field. Every week. Free.

Join 10,000+ professionals getting job alerts and salary insights in their inbox

We respect your privacy. Unsubscribe anytime with one click.