Security Operations Center Lead - Cyber Operations
Employee Forums•Mumbai
Full-timeLead
₹27L - ₹30L
per year
👁️ 0 views•📝 0 applications•Posted 9/4/2026•Expires 10/4/2026
Get alerts for roles like this
More Security Operations Center Lead - Cyber Operations roles in Mumbai — straight to your inbox. No account needed.
Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.
Job Description
Role : Security Operations Center (SOC) Lead
Department : Cyber Operations & Engineering
Location : Mumbai
Experience Required : 8 - 10 Years
Reporting To : Head of Cybersecurity / CISO
Role Summary :
The SOC Lead oversees 24x7 security operations, advanced detection engineering, and high-severity incident response. This role combines technical leadership across SIEM, SOAR, and EDR platforms with operational governance - mentoring Tier-1 and Tier-2 analysts, optimizing runbooks, and ensuring swift threat containment across enterprise environments.
Key Responsibilities :
- Incident Response & Escalations : Serve as the final escalation point for critical (P1/P2) security incidents; direct end-to-end containment, eradication, forensics, and post-incident root cause analysis (RCA).
- Detection Engineering & Tuning : Oversee SIEM correlation rule creation, use-case mapping to the MITRE ATT&CK framework, and alert tuning to eliminate noise and reduce false positives.
- SOAR & Automation : Direct the development of automated incident response playbooks integrated with EDR, firewalls, IAM, and ITSM to consistently lower MTTR and MTTD.
- Threat Hunting & Intelligence : Integrate actionable threat intelligence (CTI) into monitoring workflows and guide proactive threat-hunting exercises across network, endpoint, and cloud assets.
- Operational Governance & Mentorship : Manage analyst shift rotations, define SOC SOPs and runbooks, conduct tabletop simulations, and mentor Tier-1 and Tier-2 engineers.
- Metrics & Executive Reporting : Track and report core operational KPIs (MTTD, MTTR, coverage gaps) and present threat summaries and security posture updates to executive leadership and audit teams.
Required Technical Skills & Qualifications :
- Experience : 8 - 10 years in cyber operations, with at least 3+ years in a senior, L3, or lead capacity within an enterprise SOC or MSSP.
- SIEM/SOAR Expertise : Deep architectural and operational mastery of modern SIEM platforms (e.g., Microsoft Sentinel, Splunk, QRadar, Google SecOps) and SOAR tools (e.g., Cortex XSOAR, Splunk SOAR).
- Threat Detection : Proven ability to map detections to MITRE ATT&CK, investigate complex lateral movement, and analyze advanced attack vectors (ransomware, living-off-the-land techniques).
- Scripting & Telemetry : Hands-on experience analyzing endpoint telemetry (CrowdStrike, Defender, SentinelOne), network logs, and identity systems; working knowledge of Python, PowerShell, or KQL for log query optimization and automation.
- Leadership : Strong track record in team coaching, crisis decision-making, and stakeholder communication.
Preferred Certifications :
- CISSP, CISM, or CCISO
- GIAC Certifications (GCIH, GCFA, GCED, or GNFA)
- Certified SIEM/SOAR Architect (e.g., Splunk Certified Enterprise Security Admin, Microsoft Sentinel SC-200)
Required Skills
AuditCybersecurityKPI ManagementLeadershipPythonRoot Cause AnalysisStakeholder ManagementSwift
Prepare to Win This Role
Everything you need to ace the interview and negotiate top-of-band compensation.