Security Operations SME (L3)

Persistent Systems Limited

Mumbai

Hybrid

INR 2,800,000 - 4,200,000

Full time

17 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work options
Flexible work hours
Long service awards
Group term life insurance
Personal accident insurance
Mediclaim hospitalization for self, Sp

Job summary

Persistent Systems Limited seeks an experienced Security Operations SME (L3) to lead complex cyber investigations and incident response within the SOC. You will collaborate with cross-functional teams across endpoints, networks, cloud, and identity to strengthen defenses.

The role emphasizes threat hunting, detection engineering, and playbook development, with focus on continuous improvement and high-severity incident management in a hybrid work setup.

Qualifications

  • Bachelor's degree in CS, Cybersecurity, Information Security or equivalent.
  • 8–12 years of security operations, incident response, and investigations.
  • Experience in enterprise SOC or MSSP environments.

Responsibilities

  • Act as the Level 3 escalation point for complex, high-severity incidents.
  • Lead deep-dive investigations to determine scope, root cause, and business impact.
  • Drive containment, eradication, recovery and post-incident reviews.
  • Conduct advanced analysis across SIEM, endpoint, network, cloud logs, and threat intel.
  • Perform proactive threat hunting aligned with MITRE ATT&CK.
  • Design and tune SIEM detections, alerts, and dashboards.
  • Develop incident response playbooks and runbooks.
  • Mentor L1/L2 analysts and drive SOC maturity.

Skills

SOC operations
Incident response
Threat hunting
SIEM
EDR/XDR
Threat intelligence
Leadership
Communication
Python scripting

Education

Bachelor's degree in Computer Science/Cybersecurity

Tools

Splunk Enterprise Security
Microsoft Sentinel
IBM QRadar
Defender for Endpoint

Job description

We are an AI-led, platform-driven Digital Engineering and Enterprise Modernization partner, combining deep technical expertise and industry experience to help our clients anticipate what’s next. Our offerings and proven solutions create a unique competitive advantage for our clients by giving them the power to see beyond and rise above. We work with many industry-leading organizations across the world, including 20 Fortune 50 companies and 4 of the 5 top banks in both the US and India, and numerous innovators across the healthcare ecosystem.

We are seeking a highly skilled Security Operations SME (L3) to serve as the senior technical escalation point for complex and high-severity cyber incidents. This role plays a critical part in leading advanced investigations, incident response, proactive threat hunting, and continuous improvement of detection and monitoring capabilities within the Security Operations Center (SOC). The ideal candidate will collaborate closely with Incident Response, Threat Intelligence, Infrastructure, Endpoint, Network, Cloud, and Application teams to strengthen the organization's overall security posture.

  • Role: Security Operations SME (L3)
  • Experience: 8 to 12 Years
  • Job Type: Full-Time Employment
What You'll Do:
  • Act as the Level 3 escalation point for complex, high-severity, and multi-domain security incidents.
  • Lead deep-dive investigations to determine attack scope, root cause, affected assets, business impact, and attacker tactics, techniques, and procedures.
  • Drive incident containment, eradication, recovery, post-incident reviews, and corrective-action tracking with relevant technical teams.
  • Conduct advanced analysis across SIEM events, endpoint telemetry, network traffic, identity activity, cloud logs, malware indicators, and threat intelligence sources.
  • Perform proactive threat hunting and develop threat-hunting hypotheses aligned with MITRE ATT&CK and emerging threat patterns.
  • Design, tune, validate, and maintain correlation rules, detection use cases, alerts, dashboards, and investigation content.
  • Reduce false positives, identify detection gaps, and improve monitoring coverage using lessons learned from incidents and threat intelligence.
  • Develop and maintain incident response playbooks, SOPs, runbooks, escalation procedures, and knowledge articles.
  • Optimize SIEM, EDR/XDR, SOAR, and related security tools while troubleshooting integration, monitoring, performance, and data quality issues.
  • Provide technical guidance, mentoring, case reviews, and knowledge-sharing sessions for L1 and L2 analysts.
  • Prepare incident reports, root-cause analyses, executive summaries, and technical recommendations.
  • Support audits, tabletop exercises, service reviews, operational metrics, and continuous improvement initiatives.
  • Participate in shift rotations and on-call support for critical security incidents as required.
Expertise You'll Bring:
  • Extensive experience in Security Operations Center (SOC) operations, incident response, security monitoring, and cyber investigations.
  • Advanced hands-on experience with SIEM platforms such as Splunk Enterprise Security, Microsoft Sentinel, IBM QRadar, or equivalent solutions.
  • Experience with EDR/XDR technologies including Microsoft Defender for Endpoint, CrowdStrike Falcon, Carbon Black, or similar platforms.
  • Strong log analysis expertise across endpoint, network, server, application, identity, and cloud data sources.
  • Deep knowledge of threat hunting, IOC analysis, attack-chain reconstruction, malware triage, and digital forensic fundamentals.
  • Strong understanding of MITRE ATT&CK, common cyberattack techniques, threat actor methodologies, and incident response lifecycle management.
  • Experience developing, tuning, and optimizing SIEM correlation rules, threat detection content, searches, alerts, dashboards, and reports.
  • Exposure to SOAR platforms, automated workflows, orchestration playbooks, and security automation initiatives.
  • Working knowledge of Windows, Linux, TCP/IP, DNS, HTTP/S, Active Directory, Entra ID, authentication technologies, and cloud environments.
  • Scripting and automation experience using Python, PowerShell, Bash, or similar technologies.
  • Excellent analytical, troubleshooting, documentation, stakeholder management, and communication skills.
  • Experience working within enterprise SOC or Managed Security Service Provider (MSSP) environments.
  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent professional experience.
  • Relevant certifications such as CISSP, GCIH, GCIA, GCFA, Splunk, Microsoft Security, CrowdStrike, or equivalent security certifications.
  • Experience presenting incident findings and security recommendations to both technical and non-technical audiences.
  • Proven ability to manage high-severity incidents and drive effective incident response activities.
  • Strong leadership and mentoring capabilities for guiding junior analysts and improving SOC maturity.
  • Ability to collaborate effectively across multiple technical teams and business stakeholders.
  • Strong focus on continuous improvement, detection engineering, threat intelligence integration, and operational excellence.
  • Commitment to staying current with evolving cybersecurity threats, technologies, and industry best practices.
  • Competitive salary and benefits package
  • Culture focused on talent development with quarterly growth opportunities and company-sponsored higher education and certifications
  • Opportunity to work with cutting-edge technologies
  • Employee engagement initiatives such as project parties, flexible work hours, and Long Service awards
  • Insurance coverage: group term life, personal accident, and Mediclaim hospitalization for self, spouse, two children, and parents
Values-Driven, People-Centric & Inclusive Work Environment:

Persistent is dedicated to fostering diversity and inclusion in the workplace. We invite applications from all qualified individuals, including those with disabilities, and regardless of gender or gender preference. We welcome diverse candidates from all backgrounds.

  • We support hybrid work and flexible hours to fit diverse lifestyles.
  • Our office is accessibility-friendly, with ergonomic setups and assistive technologies to support employees with physical disabilities.
  • If you are a person with disabilities and have specific requirements, please inform us during the application process or at any time during your employment

Persistent is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Threat Intelligence & Threat Hunting Specialist
Threat Intelligence & Threat Hunting Specialist

Persistent Systems Limited • Chennai District

Hybrid
INR 3,500,000 - 7,000,000
Hybrid work arrangement
Career development support
Higher education & certifications
Security Engineer
Security Engineer

Persistent Systems • Bengaluru

On-site
INR 2,800,000 - 4,800,000
Insurance coverage
Hybrid work model
Quarterly growth opportunities with教育/
+1
Threat Intelligence & Threat Hunting Specialist
Threat Intelligence & Threat Hunting Specialist

Persistent Systems Limited • Mumbai

Hybrid
INR 3,000,000 - 4,200,000
Hybrid work
Education support
Cutting-edge technologies
+2
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000
Security Analyst, CSOC
Security Analyst, CSOC

Lever, Inc. • India

Remote
INR 900,000 - 1,500,000
Medical, dental, and vision insurance
Provident Fund
Remote work within India
+1
Security Analyst New India
Security Analyst New India

Litmos Limited • Pune District

On-site
INR 1,500,000 - 2,100,000
Security Operations Center Analyst - L2
Security Operations Center Analyst - L2

SRM Technologies • Chennai District

On-site
INR 900,000 - 1,500,000
Product Support Engineer – Cloud Security
Product Support Engineer – Cloud Security

Persistent Systems • Pune District

Hybrid
INR 800,000 - 1,600,000
Hybrid work
Group term life insurance
Personal accident insurance
+5