Cyber Security Specialist

Terralogic

Bengaluru

On-site

INR 2,500,000 - 4,200,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Terralogic is hiring a SOC L3 Lead / SME (Cybersecurity Operations) for our Bangalore office to spearhead advanced threat detection, incident response, and security automation.

The role requires 7+ years of core cybersecurity operations experience with hands-on expertise in Microsoft Sentinel, Defender, and Azure Logic Apps, plus strong RCA and leadership capabilities.

Qualifications

  • 7+ years in core cybersecurity operations.
  • Hands-on with Microsoft Sentinel, Defender suite and Logic Apps.
  • Proficient in writing and tuning KQL queries.
  • Experience leading investigations and incident response.
  • Ability to design automated playbooks and integrations.

Responsibilities

  • Lead deep-dive investigations and RCA for complex incidents.
  • Architect and optimize Microsoft Sentinel SIEM/XDR environments.
  • Develop KQL rules, threat hunting queries, and watchlists.
  • Build automated playbooks to reduce MTTR and improve SOC efficiency.
  • Provide transition plans for migrating to automated frameworks.
  • Mentor L1/L2 analysts and coordinate with clients during incidents.

Skills

Microsoft Sentinel
Azure Logic Apps
Microsoft Defender suite
KQL queries
SOAR automation

Tools

Azure DevOps
Logic Apps

Job description

Terralogic is hiring a SOC L3 Lead/SME (Cybersecurity Operations) for our Bangalore office to spearhead advanced threat detection, incident response, and security automation.

Position Overview
  • Position: SOC L3 Lead / Subject Matter Expert (SME)
  • Experience: 7+ years of core cybersecurity operations experience
  • Location: Bangalore, Karnataka
  • Core Focus: Hands-on Microsoft Security stack management, root-cause analysis, advanced threat investigation, and remediation orchestration.
Key Responsibilities
Advanced Threat Investigation & RCA
  • Lead deep-dive investigations into complex, multi-stage security incidents escalated by L1/L2 analysts.
  • Perform comprehensive Root Cause Analysis (RCA) to identify underlying vulnerabilities and system gaps.
  • Track adversary behavior across the network using cyber threat intelligence frameworks (e.g., MITRE ATT&CK).
Microsoft Security Stack Execution
  • Architect, configure, and optimize Microsoft Sentinel SIEM/XDR environments.
  • Develop advanced KQL (Kusto Query Language) queries for custom analytic rules, threat hunting, and watchlists.
  • Build automated playbooks within Microsoft Sentinel and Azure Logic Apps to optimize SOAR capabilities and reduce Mean Time to Respond (MTTR).
Remediation & Transition Planning
  • Design strategic transition plans to migrate legacy SOC operations into modern, automated frameworks.
  • Formulate containment and remediation strategies during active high-priority incidents.
  • Provide actionable blueprints to engineering teams for long-term threat neutralization and system hardening.
Leadership & Stakeholder Management
  • Act as the technical SME and point of contact for enterprise customers, handling on-site deployments and crisis communication when required.
  • Mentor and upscale L1 and L2 security analysts through technical workshops and incident simulations.
  • Maintain rigorous documentation for incident playbooks, post-mortem reports, and compliance audits.
Qualifications
Technical Expertise
  • Expertise: Hands-on mastery of Microsoft Sentinel, Azure Logic Apps, and Microsoft Defender suite.
  • Query Languages: Exceptional proficiency in writing and tuning KQL queries.
  • Automation: Proven experience building complex conditional workflows and integrations in Azure DevOps or Logic Apps.
  • Incident Response: Deep knowledge of network protocols, operating system forensics (Windows/Linux), and cloud security vectors.
Professional Attributes
  • Problem Solving: Exceptional analytical mind capable of connecting disparate security events.
  • Flexibility: Willingness to work dynamically between the Terralogic corporate office and client sites.
  • Communication: Clear verbal and written skills to translate technical cyber risks to non-technical client stakeholders.
Preferred Skills but not mandatory
  • Microsoft Certified: Security Operations Analyst Associate (SC-200)
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • GIAC Certified Incident Handler (GCIH) or Certified Information Systems Security Professional (CISSP)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Lead
SOC Lead

Terralogic • Bengaluru

On-site
INR 2,500,000 - 4,000,000
T&T | Cyber: D&R I Manager | Incident Response & Handling | Bengaluru
T&T | Cyber: D&R I Manager | Incident Response & Handling | Bengaluru

Deloitte & Touche GmbH Wirtschaftsprüfungsgesellschaft • Bengaluru

On-site
INR 2,400,000 - 4,000,000
SOC Analyst
SOC Analyst

Resillion • Bengaluru

Hybrid
INR 600,000 - 900,000
Senior Cybersecurity Analyst L3 – Threat Detection & SIEM
Senior Cybersecurity Analyst L3 – Threat Detection & SIEM

YO IT Consulting • Maharashtra

On-site
INR 1,500,000 - 2,500,000
Cyber Security Analyst
Cyber Security Analyst

Genpact • Dadri, Hyderabad, Bangalore Rural

Hybrid
INR 900,000 - 1,500,000
Senior Consultant-SOC L3-Incident Response | Experience: 5+ Years
Senior Consultant-SOC L3-Incident Response | Experience: 5+ Years

Aujas Networks Pvt. Ltd. • Mumbai, Bengaluru

On-site
INR 1,200,000 - 1,800,000
SOC L3 Analyst
SOC L3 Analyst

Robert Bosch Group • Bengaluru

On-site
INR 3,500,000 - 5,500,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)
Hiring: SOC L3 Engineer (Elastic SIEM & SOAR)

IT MNC • Karnataka

On-site
INR 1,500,000 - 2,000,000
Senior Cyber Threat Engineer
Senior Cyber Threat Engineer

YO IT Consulting • Maharashtra

On-site
INR 1,200,000 - 2,000,000