Security Operations Center Manager

CMS It Services

Dadri

On-site

INR 1,400,000 - 2,100,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

CMS It Services in Noida is seeking an experienced SOC L3 Analyst or Team Lead to oversee L1/L2/L3 operations, drive incident response, and mentor the security operations center staff in real time.

You will lead deep-dive investigations across endpoint, network, and cloud telemetry, perform root cause analysis, coordinate containment actions, and author clear post-incident reports. This role requires 10+ years in SOC with hands-on SIEM and EDR experience.

Qualifications

  • 10+ years in a SOC/security operations environment, with at least 3+ years performing L2/L3-level investigation or incident response.
  • Strong hands-on experience with a SIEM platform including query authoring and correlation rule tuning.
  • Solid understanding of endpoint (EDR) and network security telemetry.
  • Working knowledge of the MITRE ATT&CK framework and structured investigation methodology.
  • Experience with incident documentation, RCA, and post-incident reporting.
  • Strong ability to review and coach junior analysts’ work without owning every ticket.

Responsibilities

  • Oversee L1 Operations: review/validate L1 triage decisions, audit sampling, and SLA adherence.
  • Coach L1 analysts in investigation technique, tooling, and escalation judgment.
  • Own the L1L2/L3 escalation queue and ensure timely handling of escalated cases.
  • Identify recurring L1 errors and feed improvements to training plans and playbooks.
  • Lead deep-dive investigations for high-severity alerts across endpoint, network, identity, and cloud telemetry.
  • Perform root cause analysis, timeline reconstruction, and scope incidents.
  • Drive containment and remediation actions in coordination with IR/IT and asset owners.
  • Author clear, defensible incident reports and post-incident reviews.
  • Identify false-positive patterns and tune detections with SIEM (Splunk, Chronicle, Devo).
  • Partner with detection engineering for new use cases.
  • Maintain SOPs, runbooks, and playbooks used by L1.
  • Conduct periodic quality audits of closed tickets against SOC standards.
  • Track quality metrics and improve mean times to triage/escalate.
  • Ensure chain-of-custody and evidence handling compliance.
  • Support shift handover quality with complete notes.
  • Act as senior technical mentor for L1 team; run knowledge-sharing sessions.
  • Contribute to onboarding and skills-development curriculum.
  • Be the go-to escalation point for ambiguous/high-pressure alerts.

Skills

SOC operations
L2/L3 investigation
Incident response
Mentoring junior analysts
Quality audits
Training & playbooks

Tools

Splunk
Google SecOps/Chronicle
Devo
SentinelOne
CrowdStrike
Palo Alto

Job description

Job Description SOC L3 Analyst or Team Lead

Location : Noida

Rotational shift

Experience : 10 -16 years

Key Responsibilities
Oversight of L1 Operations
  • Review and validate L1 alert triage and closure decisions on a sampling/audit basis to ensure accuracy and consistency
  • Coach L1 analysts in real time on investigation technique, tooling, and escalation judgment
  • Own the L1L2/L3 escalation queue; ensure escalated cases are picked up and worked within SLA
  • Identify recurring L1 errors or knowledge gaps and feed them into training plans and playbook updates
Investigation & Response
  • Lead deep-dive investigations for escalated and high-severity alerts across endpoint, network, identity, and cloud telemetry
  • Perform root cause analysis, timeline reconstruction, and scoping of confirmed incidents
  • Drive containment and remediation actions in coordination with IR, IT, and asset owners
  • Author clear, defensible incident reports and post-incident reviews
Detection Engineering & Tuning
  • Identify false-positive patterns and detection gaps from L1/L3 casework; write or tune correlation rules and detections (SIEM: Google SecOps/Chronicle, Splunk, or Devo or Any other)
  • Partner with detection engineering/content team on new use cases derived from investigation findings
  • Maintain and improve SOPs, runbooks, and playbooks used by L1
Process & Quality Assurance
  • Conduct periodic quality audits of closed tickets against SOC investigation standards
  • Track and report on quality metrics (mean time to triage/escalate, false-positive rate, reopened-ticket rate)
  • Ensure chain-of-custody and evidence-handling standards are followed on all investigations
  • Support shift handover quality verify handover notes are complete and actionable
Mentorship & Enablement
  • Act as the senior technical mentor for the L1 team; run knowledge-sharing sessions
  • Contribute to onboarding and skills-development curriculum
  • Be the go-to escalation point during shift for ambiguous or high-pressure alerts
Required Qualifications
  • 10+ relevant years in a SOC/security operations environment, with at least 3+ years performing L2/L3-level investigation or incident response
  • Strong hands-on experience with a SIEM platform (Splunk, Google SecOps/Chronicle, Devo, or equivalent) including query authoring and correlation rule tuning
  • Solid understanding of endpoint (EDR — e.g., SentinelOne, CrowdStrike), network security (e.g., Palo Alto), and identity/access telemetry
  • Working knowledge of the MITRE ATT&CK framework and structured investigation methodology
  • Experience with incident documentation, RCA, and post-incident reporting
  • Strong ability to review and coach junior analysts’ work without owning every ticket personally
Preferred Qualifications
  • Prior team lead / shift lead experience in a SOC
  • Familiarity with SOAR platforms and automation/playbook design
  • Exposure to cloud security monitoring (AWS/Azure/GCP)
  • Experience operating in a global/24x7 SOC model with shift handovers
Success Metrics for the Role
  • Improvement in mean time to detect/escalate/contain
  • Audit pass rate on investigation quality reviews
  • Measurable uplift in L1 team capability (fewer repeat coaching items quarter over quarter)

Thanks

Salma Saifi

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
L2 SOC Analyst
L2 SOC Analyst

UST • Thiruvananthapuram

Hybrid
INR 600,000 - 900,000
Security Operations Center Analyst- L2
Security Operations Center Analyst- L2

Incedo Inc. • Gurugram District

On-site
INR 900,000 - 1,500,000
Soc Analyst
Soc Analyst

Incedo • Gurugram District

On-site
INR 1,800,000 - 2,400,000
24x7 Rotational Shift
Willingness to work on weekends/holid-
Lead Cyber Defence Analyst
Lead Cyber Defence Analyst

IG Infotech • Bengaluru

On-site
INR 1,200,000 - 1,800,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Security Operations Center Lead
Security Operations Center Lead

Tekskills • Bengaluru

On-site
INR 2,500,000 - 4,000,000
SOC-Associate Director
SOC-Associate Director

SISA • Bengaluru

On-site
INR 1,000,000 - 1,500,000