Live opening · Posted 12 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Role Overview:
The Technical SOC Lead is a hands-on, deep technical authority responsible for defending complex, multi-tenant enterprise and financial customer environments. This role is not a passive managerial or people-coordination position.
We are seeking a candidate similar to senior technical leads in tier-one product/IT consulting firms who actively manages multiple high-complexity enterprise and global client accounts simultaneously, remaining deeply involved in the CLI/console, log engineering, high-severity incident containment, and correlation logic design.
The candidate must balance hands-on technical mastery across SIEM, SOAR, EDR, and UEBA with client-facing technical leadership—serving as the direct technical SPOC for client CISOs, incident handlers, and SOC engineering teams.
Primary Responsibilities:
Hands-On L3 Incident Response & Forensic Containment
Direct end-to-end incident investigations for critical P1/P2 security incidents, APT intrusions, ransomware execution, credential stuffing, and data breaches across diverse client environments.
Act as the final technical escalation point for L1/L2 analysts. Take command of active attacks, determine infection vectors, execute remote containment (host isolation, network segmentation, process termination), and drive Root Cause Analysis (RCA).
Perform deep-dive network traffic analysis (PCAP), memory/disk forensics, and binary/script reverse analysis to counter evasion techniques.
2. Multi-Client Technical Ownership & Delivery
Serve as the Lead Technical SPOC across multiple large-scale enterprise, banking, and critical infrastructure accounts.
Lead technical triage bridges and incident war rooms directly with client CISOs, Threat Leads, and Enterprise IT Directors.
Present technical threat trends, architectural detection gaps, and forensic RCA summaries directly to client leadership
3. Advanced Detection Engineering & SIEM Architecture
Hands-on ownership of detection logic across modern enterprise SIEMs (e.g., Google SecOps/Chronicle, Splunk ES, IBM QRadar, Microsoft Sentinel, ArcSight).
Build, parse, and optimize complex correlation rules and analytics queries (KQL, YARA-L, SPL, AQL) mapped strictly to the MITRE ATT&CK matrix.
Execute aggressive false-positive suppression, baseline profiling, and threshold tuning to maximize SOC alert fidelity.
4. SOAR Playbook Engineering & Automation
Design, build, and deploy automated and semi-automated incident response playbooks on enterprise SOAR platforms (e.g., Cortex XSOAR, Secura, Splunk SOAR).
Develop custom automation scripts (Python, PowerShell, APIs) to integrate SIEM/SOAR with EDR platforms (CrowdStrike Falcon, SentinelOne, Carbon Black), next-gen firewalls, IAM, and ticketing platforms.
5. Proactive Threat Hunting & UEBA Modeling
Execute continuous, hypothesis-driven threat hunts across cloud (AWS/GCP/Azure), on-premises telemetry, and identity providers to uncover hidden adversary persistence.
Tune UEBA risk models to pinpoint lateral movement, insider threat activity, anomalous privilege escalation, and account takeover.
Required Technical Profile:
8–10+ years of core, hands-on SOC and incident handling experience, with at least 3+ years operating in an L3 Senior Technical / Lead capacity.
Mandatory Multi-Client / MSSP Experience: Demonstrated track record managing threat defense and security operations for multiple concurrent enterprise clients.
Active Technical Involvement: Must currently spend significant working time in consoles, query editors (KQL, SPL, YARA-L), and incident bridges rather than purely administrative/managerial tasks.
Multi-SIEM Fluency: Deep administrative and engineering competence in at least two major SIEM solutions (e.g., Google Chronicle/SecOps, Microsoft Sentinel, Splunk ES, QRadar, ArcSight).
EDR/XDR Mastery: Live containment and hunting expertise across CrowdStrike Falcon, SentinelOne, Cortex XDR, or Microsoft Defender XDR.
Scripting Competence: Practical capability to write automation scripts and custom parsers (Python, PowerShell, Bash, Regex).
Preferred Certifications:
Management/Governance: CISM, CISSP
Incident Response & Operations: GCIH, GCIA, GCED, or ECSA/CEH
Platform Specializations: Google Cloud SecOps Credential, Microsoft SC-200, Splunk Certified Architect, or Cortex XSOAR Certified
Location:
Andheri East, Mumbai
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.