AI SOC Lead

black.ai

Bengaluru

On-site

INR 2,200,000 - 4,800,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

CYBLE in Bengaluru is seeking a seasoned SOC Lead to blend cybersecurity expertise with AI-driven detection and response. You will bridge frontline analysts and executives, drive operational excellence, and champion AI/ML tooling, including Cyble's intelligence platform, ensuring threats are detected, triaged, and contained swiftly.

You will lead 24x7 SOC operations, elevate capabilities through automation, threat intel, and a culture of continuous improvement, while partnering with legal,

Qualifications

  • 4–6 years of progressive cybersecurity experience with leadership exposure.
  • Hands-on with SIEM/SOAR platforms and incident response.
  • Experience integrating or operating AI-powered security tools is a plus.

Responsibilities

  • Lead, mentor, and develop a SOC team (Tier 1–3) for high performance.
  • Oversee 24x7 SOC operations with SLA adherence and escalation.
  • Act as escalation point for complex or high-severity incidents.
  • Develop AI-assisted playbooks for automated triage and response.
  • Coordinate with legal, compliance, and risk stakeholders on major breaches.

Skills

Leadership
SOC Leadership
Communication
Threat hunting
Automation

Tools

Splunk
Microsoft Sentinel
IBM QRadar
XSOAR
PowerShell
Python
KQL

Job description

About The Role

We are looking for a seasoned SOC Lead who can blend deep cybersecurity expertise with a forward-thinking approach to AI-driven detection and response. In this leadership role, you will be the linchpin between frontline analysts and executive stakeholders — driving operational excellence, championing AI/ML tooling, including Cyble's own intelligence platform, and ensuring threats are detected, triaged, and contained with speed and precision.

You will own the SOC's day-to-day operations while continuously elevating the team's capabilities through automation, threat intelligence, and a culture of continuous improvement.

What You’ll Do At CYBLE
Leadership & Operations
  • Lead, mentor, and develop a team of SOC analysts (Tier 1–3), fostering a high-performance security culture.
  • Oversee 24×7 SOC operations, ensuring coverage, SLA adherence, and escalation procedures are consistently followed.
  • Act as the primary point of escalation for complex or high-severity incidents.
  • Conduct regular team reviews, shift handovers, and post-incident retrospectives.
AI-Augmented Detection & Response
  • Champion the adoption of AI/ML tools for behavioural analytics, anomaly detection, and threat correlation — including Cyble's AI-powered threat intelligence platform.
  • Leverage Cyble Vision and Cyble's dark web intelligence feeds to enrich detection use cases and proactively identify emerging threats.
  • Integrate and tune AI-powered SIEM, SOAR, and EDR platforms to reduce false positives and improve detection fidelity.
  • Develop and maintain AI-assisted playbooks for automated triage and initial response actions.
  • Evaluate emerging AI security products and recommend adoptions aligned to the threat landscape.
  • Monitor AI model performance and ensure explainability and auditability of automated decisions.
Threat Detection & Triage
  • Oversee alert triage workflows, ensuring timely and accurate classification of security events.
  • Develop and maintain detection rules, correlation logic, and use cases across SIEM and XDR platforms.
  • Establish triage SLAs and quality benchmarks; regularly audit analyst triage accuracy.
  • Leverage threat intelligence feeds to continuously refine detection coverage and reduce dwell time.
Incident Response
  • Lead end-to-end incident response for critical and high-severity security incidents.
  • Coordinate containment, eradication, and recovery activities in line with the IR framework.
  • Produce clear, executive-level incident reports and root cause analyses (RCAs).
  • Conduct post-incident reviews and drive lessons‑learned into process and detection improvements.
  • Liaise with legal, compliance, and external stakeholders during significant breaches.
Process Improvement & Reporting
  • Define and track key SOC metrics (MTTD, MTTR, false positive rates, coverage gaps).
  • Continuously refine and document SOC runbooks, playbooks, and standard operating procedures.
  • Prepare regular reporting for CISO and board-level audiences on SOC posture and key incidents.
  • Drive automation initiatives to improve analyst efficiency and reduce manual workload.
Experience
What You’ll Need
  • 4–6 years of progressive cybersecurity experience, with at least 2 years in a SOC leadership or senior analyst role.
  • Proven hands‑on experience with SIEM platforms (e.g., Splunk, Microsoft Sentinel, IBM QRadar).
  • Strong background in incident response, digital forensics, and threat hunting.
  • Experience integrating or operating AI/ML-powered security tools (UEBA, NDR, AI-assisted SOAR).
Technical Skills
  • Deep understanding of attack frameworks: MITRE ATT&CK, Cyber Kill Chain, Diamond Model.
  • Proficiency in network forensics, log analysis, and endpoint investigation techniques.
  • Hands‑on experience with SOAR platforms (e.g., Palo Alto XSOAR, Splunk SOAR, Microsoft Sentinel Playbooks).
  • Working knowledge of cloud security monitoring (AWS, Azure, GCP) and cloud-native threat detection.
  • Scripting ability in Python, PowerShell, or KQL for automation and detection rule development.
  • Familiarity with threat intelligence platforms.
Soft Skills & Leadership
  • Exceptional communication skills — able to translate technical findings to non‑technical executives.
  • Strong analytical thinking and ability to make sound decisions under pressure.
  • Proven ability to build, coach, and retain high‑performing security teams.
  • Collaborative mindset with cross‑functional stakeholders, including IT, Legal, and Risk.
Bonus Points If You Have
  • Industry certifications: CISSP, CISM, GCIA, GCIH, GDAT, CEH, Microsoft SC-200, or equivalent.
  • Hands‑on experience with Cyble Vision, Cyble CSPM, or equivalent AI-driven threat intelligence and attack surface management platforms.
  • Prior experience in a regulated industry (BFSI, healthcare, critical infrastructure).
  • Familiarity with compliance frameworks: ISO 27001, NIST CSF, SOC 2, PCI-DSS.
  • Exposure to red team / purple team engagements and adversary simulation exercises.
  • Experience with deception technologies, honeypots, or active defence strategies.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI SOC Lead
AI SOC Lead

Cyble • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Senior Software Engineer – AI
Senior Software Engineer – AI

Cyble • Bengaluru

On-site
INR 2,000,000 - 3,000,000
Impactful Work
Modern Stack
Growth & Learning
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Director Cyber Security
Director Cyber Security

HCLTech • Dadri, Mhalunge, Jigani

Hybrid
INR 4,000,000 - 7,000,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Intrusion Analyst III
Intrusion Analyst III

Jobtailor • Bengaluru

Hybrid
INR 1,800,000 - 2,800,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Lead Cyber Defence Analyst
Lead Cyber Defence Analyst

Remotestar • Bengaluru

Hybrid
INR 1,200,000 - 1,800,000
AVP Cybersecurity
AVP Cybersecurity

Ares Management • Mumbai

On-site
INR 4,500,000 - 7,500,000