AI SOC Lead

Ethicalhat

India

On-site

INR 2,500,000 - 4,200,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Ethicalhat is seeking an AI SOC Lead to drive 24x7 security monitoring, detection, investigation and incident response. You will provide technical leadership to SOC analysts, handle escalations and oversee detection enhancements and playbooks.

You will champion AI-assisted operations, automate alert triage and investigations, and maintain controls while engaging with clients on incident findings and recommendations.

Qualifications

  • 5+ years of SOC operations, security monitoring, incident detection and response.
  • Experience providing technical guidance or leading SOC activities.
  • Hands-on with enterprise SIEM platforms (Securonix, Splunk, Sentinel, QRadar).
  • Knowledge of EDR/XDR, IDS/IPS, DLP and vulnerability management.

Responsibilities

  • Lead security event monitoring, investigation and incident response across the SOC.
  • Manage SIEM tuning, detection logic, alerts and use cases.
  • Perform deep-dive investigations, threat hunting and root-cause analysis.
  • Lead SOC shifts and allocate work across analysts to ensure timely closure.
  • Review investigations and incident documentation to maintain quality and SLAs.
  • Identify gaps and propose improvements across security controls.

Skills

SOC operations
Security monitoring
Incident response
Threat hunting
SIEM tuning
AI-assisted security
SOAR scripting
Client/stakeholder management

Education

Bachelor's degree in a relevant field

Tools

Securonix
Splunk
Microsoft Sentinel
IBM QRadar

Job description

The AI SOC Lead will be responsible for leading day-to-day security monitoring, detection, investigation and incident response activities within a 24×7 Security Operations Centre. The role will provide technical leadership to SOC analysts, handle complex escalations, improve detection capabilities and ensure consistent quality of incident analysis and response.

The role will also drive the practical adoption of AI-assisted security operations and automation to improve alert triage, investigation, threat hunting and analyst productivity. This includes evaluating AI-enabled capabilities within security platforms and identifying appropriate opportunities for automation while maintaining analyst validation and operational controls.

Key Responsibilities
  • Lead security event monitoring, investigation and incident response activities across the SOC, acting as the technical escalation point for complex or high-severity incidents.
  • Manage, tune and optimise SIEM capabilities, including correlation rules, detection logic, filters, alerts and use cases based on evolving threats and business requirements.
  • Perform and guide deep-dive investigations, threat hunting, malware analysis and root-cause analysis for escalated security incidents.
  • Lead SOC shifts and allocate work across analysts while ensuring timely investigation, escalation and closure of security incidents.
  • Review analyst investigations, incident documentation and response actions to maintain investigation quality and adherence to established processes and SLAs.
  • Identify gaps and recommend improvements across security controls such as EDR/XDR, IDS/IPS, DLP, vulnerability management and other security monitoring technologies.
  • Apply AI-assisted investigation, alert enrichment and summarisation capabilities where they can improve SOC efficiency without compromising investigation accuracy or security controls.
  • Identify opportunities to automate repetitive SOC workflows using SOAR, scripting and platform-native automation, including enrichment, triage and response activities.
  • Work with SOC management to develop and improve operational procedures, playbooks, detection use cases and incident response processes.
  • Serve as a key operational and technical contact for clients/stakeholders, providing incident updates, investigation findings and recommendations.
Skills & Experience
  • 5+ years of relevant experience in SOC operations, security monitoring, incident detection and response, with experience providing technical guidance or leading SOC activities.
  • Strong understanding of security event analysis, incident investigation, threat hunting and common attacker techniques.
  • Hands-on experience with enterprise SIEM platforms; Securonix, Splunk, Microsoft Sentinel, IBM QRadar
  • Working knowledge of EDR/XDR, IDS/IPS, firewalls, DLP, vulnerability management and other security monitoring/control technologies.
  • Experience developing and tuning SIEM correlation rules, detection logic, alerts and security use cases.
  • Understanding of network, endpoint, identity and authentication logs and their use during security investigations.
  • Familiarity with threat intelligence, IOC analysis and frameworks such as MITRE ATT&CK for investigation and detection engineering.
  • Practical understanding of SOAR, security workflow automation and scripting for repetitive investigation or response activities.
  • Familiarity with AI-assisted capabilities in modern security operations platforms, including their appropriate use and limitations in investigation and triage.
  • Strong incident documentation, analytical, communication and client/stakeholder management skills.
Preferred Qualifications
  • Certifications such as CISSP, CISM, GIAC, CEH, Security+ or relevant vendor‑specific SIEM/SOC certifications are preferred.
  • Experience working in an MSSP, managed SOC or large enterprise SOC environment.
  • Exposure to SOAR platforms, security automation, detection engineering or AI-enabled SOC capabilities will be an advantage.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI SOC Manager
AI SOC Manager

Ethicalhat • India

On-site
INR 4,000,000 - 7,000,000
Senior Security Analyst – AI SOC
Senior Security Analyst – AI SOC

Ethicalhat • India

On-site
INR 1,400,000 - 2,400,000
SOC Principal
SOC Principal

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,500,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000
Manager - AI Detection & Response
Manager - AI Detection & Response

EY • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Senior AI Detection & Response Consultant
Senior AI Detection & Response Consultant

EY • Bengaluru

On-site
INR 4,000,000 - 7,000,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000