A leading business innovation hub in Chennai is looking for a SOC Operations Lead to oversee security operations and incident responses globally. The ideal candidate will have over 7 years of cybersecurity experience, with at least 3 years in SOC management, alongside hands-on experience with major SIEM platforms. Responsibilities include leading SOC, ensuring adherence to processes, and mentoring analysts. This role emphasizes a collaborative approach with cross-functional teams and continuous improvement of security practices.
Qualifications
At least 7 years of experience in cybersecurity, 3 years in SOC management.
Hands-on experience with major SIEM platforms.
Strong understanding of network and endpoint security.
Responsibilities
Lead and manage SOC operations across environments.
Guide team on handling detections and incident response.
Collaborate with US teams for incidents and process improvement.
Skills
Cybersecurity
Incident response
Log analysis
Mentorship
Security awareness
Tools
Microsoft Sentinel
Splunk
QRadar
LogRhythm
Microsoft Defender
Crowdstrike
Job description
Staples India Business Innovation Hub Private Limited | Permanent
Lead and manage SOC operations, ensuring effective monitoring and response to security events across global environments.
Guide the team in handling detections, alerts, incident response, and remediation.
Collaborate with US‑based teams for incident escalation, knowledge sharing, and process>
Ensure adherence to SOPs, Playbooks, and Runbooks; contribute to their development and refinement.
Provide feedback to engineering teams for platform improvements and detection logic enhancements.
Maintain expertise in log analysis and threat detection using SIEM platforms (Microsoft Sentinel, Splunk, QRadar, LogRhythm).
Ensure effective use of security controls (Microsoft Defender, Crowdstrike, etc.) and integration with SOC workflows.
Champion continuous improvement, maturity, and growth of SOC capabilities and detection platforms.
Mentor and develop SOC Analysts, fostering a culture of security awareness and operational excellence.
Requirements
Basic Qualifications
7+ years of progressively complex experience in cybersecurity, including at least 3 years in SOC or security operations management.
Hands‑on experience with SIEM platforms (Microsoft Sentinel, Splunk, QRadar, LogRhythm) and familiarity with SOAR and EDR technologies.
Deep understanding of network architectures, firewalls, IDS/IPS, VPNs, and endpoint security tools.
Experience developing and maintaining SOPs, Playbooks, and Runbooks.
Proven ability to troubleshoot complex security incidents and platform issues.
Familiarity with security controls (Microsoft Defender, Crowdstrike, etc.).
Proficiency in analyzing attacker tactics, techniques, and procedures (TTPs) and integrating threat intelligence feeds.
Strong knowledge of compliance and regulatory frameworks such as NIST, ISO 27001, GDPR, HIPAA, and PCI‑DSS.
Expertise in securing multi‑cloud environments and managing cloud‑native security tools.
Experience working in a global, cross‑functional environment.
Preferred Qualifications
Experience in large‑scale SOC operations or transformations.
Familiarity with security standards and compliance frameworks (e.g., NIST, ISO).