Security Operations Center Lead

Altera

Bengaluru

On-site

INR 1,800,000 - 3,200,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Altera is seeking an experienced Security Operations Center (SOC) lead to manage daily SOC operations across global time zones, drive detection engineering, and coordinate incident response. You will enhance playbooks, oversee analysts, and ensure governance-aligned processes.

The role requires 5+ years in security operations, strong SIEM/EDR skills, and leadership experience, with excellent communication to technical and executive stakeholders.

Qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, or a related field, or equivalent practical experience.
  • 5+ years of progressive cybersecurity experience, including hands-on experience in security operations, incident response, threat detection, or SOC leadership.
  • 3+ years of experience leading SOC analysts, incident response teams, managed security operations, or cross-functional cyber defense workflows.
  • Strong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and incident response processes.
  • Demonstrated experience building or improving detection use cases, alert triage workflows, response playbooks, escalation procedures, and SOC metrics.
  • Experience coordinating investigations involving phishing, malware, endpoint compromise, suspicious authentication, privileged access misuse, data exposure, and cloud security events.
  • Familiarity with frameworks and standards such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls, or equivalent cyber defense frameworks.
  • Ability to communicate clearly with technical teams, business stakeholders, senior leadership, and external partners during security incidents.
  • CISSP, Security+, or equivalent industry certification.

Responsibilities

  • Lead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.
  • Own and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.
  • Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.
  • Build, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.
  • Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.
  • Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.
  • Establish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.
  • Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.
  • Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.
  • Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.
  • Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.
  • Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.
  • Serve as a security operations lead for global SOC coverage and cross-functional collaboration.

Skills

Cybersecurity experience
SOC leadership
SIEM/SOAR/EDR
MITRE ATT&CK
NIST CSF
ISO 27001
Communication skills
CISSP/Security+
Bachelor's degree

Education

Bachelor’s degree in Computer Science/Engineering

Job description

  • Lead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.
  • Own and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.
  • Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.
  • Build, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.
  • Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.
  • Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.
  • Establish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.
  • Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.
  • Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.
  • Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.
  • Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.
  • Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.
  • Serve as a security operations lead for global SOC coverage and cross-functional collaboration.
Job Details
Job Description
  • Lead daily SOC operations across monitoring, alert triage, investigation, escalation, incident response coordination, and operational handoff across global time zones.
  • Own and mature SOC operating procedures, including incident intake, severity classification, escalation paths, response playbooks, major incident communications, and post-incident reviews.
  • Manage and improve security monitoring across SIEM, SOAR, EDR/XDR, email security, cloud security, identity security, vulnerability signals, network telemetry, and threat intelligence sources.
  • Build, tune, and continuously improve detection use cases aligned to enterprise risks, MITRE ATT&CK techniques, threat intelligence, audit findings, and business-critical assets.
  • Partner with security engineering teams to improve log onboarding, data quality, telemetry coverage, alert fidelity, automation, and response integrations.
  • Lead incident response coordination for security events involving endpoint compromise, identity misuse, phishing, malware, data loss indicators, cloud misconfigurations, suspicious network activity, and unauthorized access attempts.
  • Establish SOC performance metrics and reporting, including alert volumes, false-positive rates, SLA adherence, escalation quality, mean time to detect, mean time to acknowledge, mean time to contain, and incident trends.
  • Oversee SOC analyst workflows, shift handoffs, case documentation, evidence handling, and quality assurance reviews.
  • Coordinate with managed security service providers, internal IT teams, and business stakeholders to ensure timely response and clear ownership of remediation actions.
  • Support implementation and operationalization of SOAR playbooks, automation workflows, enrichment logic, and incident response runbooks.
  • Drive continuous improvement through tabletop exercises, incident retrospectives, purple-team findings, threat hunting outputs, and lessons learned.
  • Maintain alignment with security governance, regulatory, privacy, and audit requirements by ensuring SOC processes are documented, repeatable, measurable, and evidence-ready.
  • Serve as a security operations lead for global SOC coverage and cross-functional collaboration.
Qualifications
Minimum Qualifications
  • Bachelor’s degree in Computer Science, Computer Engineering, Information Security, Cybersecurity, or a related field, or equivalent practical experience.
  • 5+ years of progressive cybersecurity experience, including significant hands‑on experience in security operations, incident response, threat detection, or SOC leadership.
  • 3+ years of experience leading SOC analysts, incident response teams, managed security operations, or cross‑functional cyber defense workflows.
  • Strong working knowledge of SIEM, SOAR, EDR/XDR, cloud security monitoring, identity security, email security, network security, and incident response processes.
  • Demonstrated experience building or improving detection use cases, alert triage workflows, response playbooks, escalation procedures, and SOC metrics.
  • Experience coordinating investigations involving phishing, malware, endpoint compromise, suspicious authentication, privileged access misuse, data exposure, and cloud security events.
  • Familiarity with frameworks and standards such as MITRE ATT&CK, NIST CSF, NIST SP 800-61, ISO 27001, CIS Controls, or equivalent cyber defense frameworks.
  • Ability to communicate clearly with technical teams, business stakeholders, senior leadership, and external partners during security incidents.
  • Strong analytical, documentation, prioritization, and decision‑making skills in high‑pressure operational environments.
  • CISSP, Security+, or equivalent industry certification.
Preferred Qualifications
  • Experience operating or transforming a global SOC in an enterprise environment.
  • Experience working as an Incident Commander, leading IR execution for the company.
  • Experience working with Microsoft Sentinel, Microsoft Defender XDR, KQLs, UEBA, or comparable security operations platforms.
  • Experience with cloud security monitoring across Azure, AWS, GCP, or hybrid cloud environments.
  • Experience with threat hunting, purple‑team collaboration, adversary emulation, or detection engineering.
  • Experience managing managed detection and response providers or outsourced SOC services.
  • Experience in semiconductor, technology, manufacturing, or intellectual property‑intensive environments.
  • Familiarity with GenAI‑assisted SOC workflows, including alert enrichment, analyst productivity, incident summarization, and security automation.
  • Additional certifications such as CEH, or similar.
Job Type

Regular

Shift

Shift 1 (Malaysia)

Primary Location

Penang 15, Penang, Malaysia

Additional Locations

Bengaluru, Karnataka, India

Posting Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000
SOC Manager
SOC Manager

Sisainfosec • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Associate SOC
Associate SOC

Epsilon Data Management • Bengaluru

On-site
INR 900,000 - 1,500,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
SOC Manager
SOC Manager

Angel One • Bengaluru

Hybrid
INR 1,800,000 - 3,200,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
SOC / Security Operations Lead
SOC / Security Operations Lead

One97 Communications Limited • Dadri

On-site
INR 3,000,000 - 6,000,000
SOC Manager
SOC Manager

Keka Technologies • Bengaluru

On-site
INR 350,000 - 600,000
SOC Specialist
SOC Specialist

METRO/MAKRO • Pune District

On-site
INR 4,000,000 - 7,000,000
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000