AI SOC Manager

Ethicalhat

India

On-site

INR 4,000,000 - 7,000,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Ethicalhat is seeking an AI SOC Manager to lead the Security Operations Centre, driving 24x7 monitoring, detection and incident response. You will oversee SOC teams, manage high-severity incidents and ensure service levels align with client requirements.

You will champion AI-assisted security workflows, automation and threat hunting, collaborating with clients and technical teams to strengthen detection capabilities and governance across SOC processes.

Qualifications

  • 8–12 years of cybersecurity experience with hands-on SOC operations and leadership.
  • Strong understanding of SIEM architecture, detection engineering and incident response.
  • Experience with enterprise SIEM platforms and security analytics.
  • Familiarity with MITRE ATT&CK framework and threat intel.

Responsibilities

  • Manage end-to-end SOC operations in a 24×7 environment including monitoring, detection and incident response.
  • Lead SOC Leads and Analysts, provide guidance, performance oversight and mentoring.
  • Oversee critical incident escalations and stakeholder communications.
  • Govern SIEM operations, detection use cases, alert tuning and coverage.
  • Drive threat hunting, detection engineering and AI-assisted SOC workflows.
  • Oversee SOAR playbooks and automation to improve response times.
  • Review performance metrics, SLA/KPI adherence and drive improvements.
  • Engage with clients and internal teams to review security controls and incidents.
  • Develop and maintain SOC processes, escalation procedures and playbooks.

Skills

SOC operations
Incident detection
Team leadership
SIEM architecture
Threat hunting
AI-assisted security
SOAR playbooks
Client management
Communication

Tools

Microsoft Sentinel
Splunk
QRadar
LogRhythm
EDR/XDR
SOAR

Job description

The AI SOC Manager will be responsible for the overall delivery and operational effectiveness of Security Operations Centre (SOC) services, including security monitoring, detection, incident response, threat hunting and continuous improvement. The role will lead SOC teams, oversee critical incident escalations and ensure that security operations meet agreed service levels, quality standards and client requirements.

The role will also drive practical adoption of AI-assisted security operations and automation to improve detection, triage, investigation and response workflows. The SOC Manager will work closely with clients, SOC leadership and technical teams to strengthen detection capabilities, improve operational processes and ensure appropriate governance of AI-enabled and automated SOC workflows.

Key Responsibilities
  • Manage end-to-end SOC operations, including monitoring, detection, investigation, incident response, escalation management and service delivery across a 24×7 environment.
  • Lead SOC Leads and Analysts, including work allocation, technical guidance, performance oversight, mentoring and capability development.
  • Provide oversight and decision support for critical and high-severity security incidents, ensuring appropriate investigation, containment, escalation and stakeholder communication.
  • Govern SIEM operations, including detection use cases, correlation rules, alert tuning, log-source coverage and continuous improvement of detection effectiveness.
  • Drive threat hunting and detection engineering initiatives based on emerging threats, threat intelligence and frameworks such as MITRE ATT&CK.
  • Identify and implement appropriate AI-assisted and automated SOC workflows for alert enrichment, triage, investigation, correlation and response, with suitable analyst validation and governance.
  • Oversee SOAR playbooks and security automation initiatives to reduce repetitive analyst effort and improve consistency and response times.
  • Review SOC performance through operational metrics, incident trends, SLA/KPI adherence, detection coverage and investigation quality; drive corrective and preventive actions where required.
  • Act as a senior operational and technical point of contact for clients and internal stakeholders, leading service reviews, incident discussions and recommendations for security control improvements.
  • Develop and maintain SOC processes, escalation procedures, incident response playbooks, operating guidelines and quality standards.
Skills & Experience
  • 8–12 years of cybersecurity experience, with significant hands‑on experience in SOC operations, incident detection and response, and experience leading SOC teams or managed security services.
  • Strong understanding of SIEM architecture and operations, security monitoring, detection engineering, incident investigation, threat hunting and security analytics.
  • Experience with enterprise SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, LogRhythm or equivalent technologies.
  • Good working knowledge of EDR/XDR, SOAR, IDS/IPS, firewalls, DLP, vulnerability management, identity security and related security controls.
  • Strong understanding of attacker techniques, IOCs, behavioural detection and MITRE ATT&CK.
  • Experience managing major security incidents and coordinating technical investigation and response across multiple teams and stakeholders.
  • Practical understanding of SOC automation, SOAR playbooks and AI-assisted security capabilities, including the risks and limitations associated with automated analysis and response.
  • Experience defining and reviewing SOC metrics, SLAs/KPIs, detection coverage, incident trends and operational performance.
  • Strong people management, mentoring and technical review capabilities, with the ability to develop SOC analysts and leads.
  • Strong client-facing communication, reporting and stakeholder management skills, including the ability to communicate technical incidents and security risks to management audiences.
Preferred Qualifications
  • Certifications such as CISSP, CISM, GIAC, CEH or relevant SIEM/SOC vendor certifications are preferred.
  • Experience managing SOC operations within an MSSP, managed SOC or large enterprise security environment.
  • Experience with detection engineering, SOAR implementation, security automation or AI-enabled capabilities within modern SIEM/XDR platforms will be an advantage.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI SOC Lead
AI SOC Lead

Ethicalhat • India

On-site
INR 2,500,000 - 4,200,000
Senior Security Analyst – AI SOC
Senior Security Analyst – AI SOC

Ethicalhat • India

On-site
INR 1,400,000 - 2,400,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Manager - AI Detection & Response
Manager - AI Detection & Response

EY • Bengaluru

On-site
INR 3,500,000 - 5,500,000
SOC Principal
SOC Principal

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,500,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Senior AI Detection & Response Consultant
Senior AI Detection & Response Consultant

EY • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000