DM - Security

CorroHealth Infotech Private Limited

Chennai District

On-site

INR 2,800,000 - 3,800,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CorroHealth Infotech Private Limited is seeking an experienced Senior SOC Lead in Chennai. You will oversee end-to-end security operations, mentor analysts, and drive proactive threat hunting to identify sophisticated threats.

The role requires deep expertise in incident response, forensics, and SIEM/SOAR tuning, with a strong focus on reducing false positives and improving detection fidelity.

Qualifications

  • 10 years total experience with 7–8 years in cybersecurity
  • Minimum 5 years in a Security Operations Center (SOC) environment
  • Strong understanding of incident handling, forensics, and threat hunting

Responsibilities

  • Lead complex security incident investigations and deliver expert-level forensics and analysis
  • Manage end-to-end incident response including containment, eradication, and recovery
  • Mentor L1/L2 analysts and guide investigations
  • Conduct proactive threat hunting to identify advanced threats
  • Analyse multi-source security logs to detect attack patterns
  • Investigate zero-day vulnerabilities and CVEs
  • Develop and tune SIEM/SOAR use cases and playbooks
  • Oversee SIEM architecture enhancements and log onboarding

Skills

Cybersecurity
SOC operations
Incident response
Threat hunting
Log analysis
Forensics
Leadership

Tools

Splunk
QRadar
CrowdStrike Falcon
SOAR
JIRA
ServiceNow
Threat Intel

Job description

About Us:

Our purpose is to help clients exceed their financial health goals. Across the reimbursement cycle, our scalable solutions and clinical expertise help solve programmatic needs. Enabling our teams with leading technology allows analytics to guide our solutions and keeps us accountable achieving goals. We build long-term careers by investing in YOU. We seek to create an environment that cultivates your professional development and personal growth, as we believe your success is our success.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

Note: The essential duties and responsibilities below are intended to describe the general duties and responsibilities of this position and are not intended to be an exhaustive statement of duties. This position may perform all or most of the primary duties listed below. Specific tasks, responsibilities or competencies may be documented in the Team Member’s performance objectives as outlined by the Team Member’s immediate Leadership Team Member.

Experience
  • Overall 10 years of total experience, with 7–8 years of specialized expertise in Cybersecurity.
  • Minimum 5 years of hands‑on experience in a Security Operations Center (SOC) environment.
Core Responsibilities (L3 Level)
  • Lead complex security incident investigations and provide expert‑level forensics and technical analysis.
  • Perform end to end incident management, including containment, eradication, recovery, and root‑cause analysis.
  • Act as a senior escalation point for L1/L2 analysts and guide them through complex investigations.
  • Conduct proactive, intelligence‑driven threat hunting to identify advanced and stealthy threats.
  • Analyse multi‑source security logs, correlate events, and detect sophisticated attack patterns.
  • Investigate zero day vulnerabilities, newly reported CVEs, and emerging cyber threats.
SOC Operations & Enhancement
  • Develop, refine, and maintain detection use cases, correlation rules, event logic, and alert thresholds.
  • Provide SIEM & SOAR tuning and optimization to reduce false positives and improve detection fidelity.
  • Enhance automation workflows within SOAR platforms to improve incident response efficiency.
  • Maintain and continuously improve SOC playbooks, SOPs, and response templates.
  • Drive improvements across SOC processes, SLAs, shift workflows, and operational maturity.
  • Lead continuous improvement initiatives, focusing on detection gaps, tuning feedback loops, and new log onboarding.
Implementation & Projects
  • Lead technical implementation and onboarding of new security tools, log sources, and integrations.
  • Coordinate with platform teams to deploy, configure, and validate new security technologies.
  • Oversee SIEM architecture enhancements, parser development, log ingestion, and normalization.
  • Participate in deployment of EDR, UEBA, SOAR, Threat Intel, Network Security and other security platforms.
  • Ensure successful end‑to‑end implementation: requirement gathering → configuration → testing → go live.
  • Drive continuous platform upgrades, configuration finetuning, and operational improvements.
Technical Expertise
  • Strong understanding of cyberattacks, threat vectors, MITRE ATT&CK techniques, malware behaviour, and incident response frameworks.
  • Expertise across Windows, Linux, and Unix environments.
  • Strong knowledge of TCP/IP, DNS, DHCP, routing, packet analysis, and network security architecture.
  • Hands‑on experience with:
    • SIEM (Splunk, QRadar, crowdstrike etc.)
    • IDS/IPS, UEBA, EDR, SSL inspection, Packet analysis tools
    • CrowdStrike Falcon (deep experience in policies, detection tuning, RTR, investigation)
    • SOAR platforms (automation playbooks, workflow creation, integration)
    • Ticketing systems such as JIRA, ServiceNow
  • Strong expertise in Vulnerability Management, VAPT, and scanning activities (tools and remediation workflows).
Leadership & Collaboration
  • Mentor, guide, and train L1 and L2 analysts on incident handling, detection techniques, and SOC maturity.
  • Collaborate with cross‑functional teams (Infra, IT, Cloud, Network, Risk, Application teams).
  • Provide technical recommendations for remediation, risk reduction, and improved security posture.
  • Create and deliver clear, actionable incident reports, executive summaries, and technical documentation.
Additional Responsibilities
  • Monitor, assess, and respond to high severity alerts in a 24×7 SOC environment.
  • Perform ongoing threat analysis, vulnerability assessment, and incident trend analysis.
  • Participate in tabletop exercises, after‑action reviews, and cyber readiness activities.
  • Handle and support any additional SOC responsibilities as assigned.
PHYSICAL DEMANDS:

Note: Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions as described. Regular eye‑hand coordination and manual dexterity is required to operate office equipment. The ability to perform work at a computer terminal for 6-8 hours a day and function in an environment with constant interruptions is required. At times, Team Members are subject to sitting for prolonged periods. Infrequently, Team Member must be able to lift and move material weighing up to 20 lbs. Team Member may experience elevated levels of stress during periods of increased activity and with work entailing multiple deadlines. A job description is only intended as a guideline and is only part of the Team Member’s function. The company has reviewed this job description to ensure that the essential functions and basic duties have been included. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate.

CorroHealth sits at the center of the revenue cycle revolution. Fundamental operations of the revenue cycle are supported through our expert teams while we recast the role of clinicians through automation. This shift to a true clinical revenue cycle helps us achieve our core purpose – exceed client financial health goals. For each patient population, CorroHealth automates key clinical aspects of the cycle. Our platforms focus on capture and application of clinical documentation while easing the burden on physicians. Scalability is prioritized in the support of client program operations. As with most revenue cycle partners, our skilled and enthusiastic team is available to outsource any portion of the cycle. However, we can also complement client programs with additional expert support or upskill existing client teams to meet program demands. Whether our team is deployed directly, or automation is incorporated for a more programmatic solution, CorroHealth delivers. CorroHealth has acquired Xtend Healthcare! For more information, please visit https://corrohealth.com. Applicants will only receive job‑related emails from the domain @corrohealth.com. Additionally, it is important to emphasize that CorroHealth will never ask for money in return for a job offer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Site Reliability Engineer - Level - 3
Site Reliability Engineer - Level - 3

CorroHealth Infotech Private Limited • Dadri

On-site
INR 1,500,000 - 2,200,000
Director – Security & Government affairs
Director – Security & Government affairs

CorroHealth Infotech Private Limited • Dadri

On-site
INR 3,000,000 - 6,000,000
System Analyst - IT
System Analyst - IT

CorroHealth Infotech Private Limited • Dadri

On-site
INR 300,000 - 420,000
QA - RCM Services
QA - RCM Services

CorroHealth Infotech Private Limited • Dadri

On-site
INR 400,000 - 600,000
AM - RCM Services
AM - RCM Services

CorroHealth Infotech Private Limited • Hyderabad

On-site
INR 600,000 - 900,000
AVP - L&D
AVP - L&D

CorroHealth Infotech Private Limited • Bengaluru

On-site
INR 3,500,000 - 6,500,000
Leadership HIM/RCM
Leadership HIM/RCM

CorroHealth Inc • Dadri

On-site
INR 1,800,000 - 2,400,000
DGM - RCM Services
DGM - RCM Services

CorroHealth Infotech Private Limited • Dadri

On-site
INR 3,500,000 - 5,500,000
Jr Executive - HIM Services
Jr Executive - HIM Services

CorroHealth Infotech Private Limited • Dadri

On-site
INR 250,000 - 450,000
AI - Engineer
AI - Engineer

CorroHealth Infotech Private Limited • Dadri

On-site
INR 1,000,000 - 2,100,000