SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA

Bengaluru

On-site

INR 3,000,000 - 5,200,000

Full time

25 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SISA is seeking an experienced SOC Manager to lead the Security Operations Center, driving 24x7 operations, incident governance, and SOC engineering across cloud, on-prem, and hybrid environments in a demanding AI-driven security landscape.

You will mentor teams, align detection coverage with MITRE ATT&CK, and partner with Product/Engineering to deliver robust security enhancements and reduced alert fatigue.

Qualifications

  • 10-12 years of cybersecurity experience.
  • 4-5 years in SOC Lead/Manager role.
  • Hands-on experience with at least one SIEM: Splunk, Sentinel, QRadar, Elastic, AlienVault, DNIF, or McAfee ESM.
  • Strong knowledge of MITRE ATT&CK and NIST/NIST IR Frameworks.
  • Cloud security, IAM, and EDR/XDR understanding.
  • Scripting knowledge (Python/PowerShell/Bash) is a plus.

Responsibilities

  • Lead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.
  • Serve as final escalation point (L3/L4) for complex incidents.
  • Define and enforce incident response lifecycle aligned with standards.
  • Ensure SLA/OLA targets and publish RCA reports.
  • Oversee detection engineering, log onboarding, and rule tuning.
  • Drive threat hunting programs and align to MITRE ATT&CK.
  • Collaborate with Product & Engineering to prioritize platform improvements.

Skills

SOC Leadership
Incident Response
SIEM & SOAR
Threat Hunting
MITRE ATT&CK
NIST & ISO 27001
Cloud Security
Team Management
Stakeholder Communication
Log Analysis

Tools

Splunk
Sentinel
QRadar
Elastic
AlienVault
DNIF
McAfee ESM

Job description

Role Overview

We are seeking a highly experienced and technically strong SOC Manager to lead and evolve our Security Operations Center into a mature, engineering-driven, and outcome-focused capability in the AI driven world.

Role Overview

We are seeking a highly experienced and technically strong SOC Manager to lead and evolve our Security Operations Center into a mature, engineering-driven, and outcome-focused capability in the AI driven world.

This Role Requires a Hybrid Leader Who Can
  • Drive 24x7 SOC operations excellence.
  • Own SIEM/SOAR engineering & detection lifecycle.
  • Collaborate closely with Product & Development teams.
  • Influence platform enhancements through operational intelligence.
  • Build and mentor high-performing security teams.
  • Highlight risks and gaps in logging methodologies.
  • Improve security posture across multi-tenant cloud and on-prem environments.
Key Responsibilities
SOC Operations Leadership & Incident Governance :
  • Lead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.
  • Serve as final escalation point (L3/L4) for complex and high-severity incidents.
  • Define and enforce incident response lifecycle aligned with NIST, ISO 27001, and MITRE ATT&CK.
  • Ensure adherence to SLA / OLA targets (MTTA, MTTR, containment time).
  • Conduct executive-level incident briefings and publish detailed RCA reports.
  • Ensure compliance with organizational security policies and audit requirements.
  • Oversee case quality assurance and investigation standards.
SOC Engineering & Detection Engineering
  • Own SIEM/SOAR architecture optimization and performance tuning.
  • Lead log onboarding strategy (cloud, on-prem, hybrid environments).
  • Ensure proper log normalization, parsing, enrichment, and correlation.
  • Drive full detection use-case lifecycle :
  • Threat modelling.
  • Use-case creation.
  • Validation & tuning.
  • Performance measurement.
  • Decommissioning of ineffective rules.
  • Reduce alert fatigue through risk-based alerting, contextual enrichment, and behavioural analytics.
  • Implement detection-as-code practices with version-controlled rule management.
  • Ensure high ingestion performance and scalable log retention strategies.
Threat Hunting & Advanced Analysis
  • Establish and lead proactive threat hunting programs.
  • Map detection coverage against MITRE ATT&CK framework.
  • Perform advanced investigations including:
  • Packet capture analysis.
  • Endpoint telemetry analysis.
  • Log correlation across multiple data sources.
  • Integrate threat intelligence feeds and manage IOC lifecycle.
  • Identify emerging attack patterns and update detection coverage accordingly.
Product Engineering & Platform Enhancement Ownership
  • Act as the primary SOC liaison for Product and Engineering teams.
  • Translate operational pain points into structured enhancement requirements.
  • Maintain and prioritize a backlog of platform improvements.
  • Provide structured feedback on:
  • Detection gaps.
  • Alert noise.
  • Data ingestion latency.
  • Query performance issues.
  • UX inefficiencies impacting analysts.
  • Participate in sprint planning and architecture discussions and provide inputs for enhancements.
  • Be part of pilot validation of new features prior to production release.
  • Quantify impact of enhancements (false positive & incident reduction %, MTTR improvement, automation coverage growth).
Client Onboarding & Security Architecture Oversight
  • Lead secure onboarding of customers across:
  • AWS / Azure / GCP.
  • On-prem data centers.
  • Hybrid architectures.
  • Conduct log gap assessments and telemetry validation.
  • Align detection coverage to client risk profiles.
  • Participate in customer governance calls and QBRs.
  • Provide architectural recommendations to improve customer security posture.
Team Leadership & Capability Development
  • Lead, mentor, and manage L1/L2/L3 analysts.
  • Establish skill matrix and structured career progression roadmap.
  • Conduct periodic case audits and performance reviews.
  • Develop training programs in:
  • Advanced detection engineering.
  • Threat hunting.
  • Forensics.
  • Automation.
  • Drive hiring, onboarding, and succession planning.
  • Build a high-performance, accountability-driven culture.
Metrics, Reporting & Continuous Improvement
  • Define and monitor SOC KPIs:
  • MTTA / MTTR.
  • False positive ratio.
  • Detection accuracy.
  • Automation coverage.
  • Incident recurrence rate & reasoning.
  • Publish monthly executive dashboards.
  • Conduct quarterly SOC maturity assessments.
  • Drive continuous improvement roadmap aligned with business growth.
Mandatory Technical Skills
  • 10-12 years of cybersecurity experience.
  • Minimum 4 - 5 years in SOC Lead / SOC Manager role.
  • Strong hands-on experience in at least one SIEM platform:
  • Splunk / Sentinel / QRadar / Elastic / AlienVault / DNIF / McAfee ESM.
  • Experience implementing SOAR automation.
  • Deep understanding of:
  • Network security (Firewall, IDS/IPS, WAF).
  • EDR/XDR platforms.
  • Cloud security (AWS, Azure).
  • Identity & Access Management.
  • Strong knowledge of :
  • MITRE ATT&CK & Defend.
  • NIST & NIST IR Framework.
  • Defense-in-Depth architecture.
  • Experience with query writing and log analysis on SIEM technologies.
Preferred Technical & Engineering Skills
  • Scripting (Python / PowerShell / Bash) would be added advantage.
  • Exposure to DevSecOps environments.
  • Knowledge of container and Kubernetes, cloud security.
  • Data analytics for anomaly detection.
  • Familiarity with compliance frameworks :
  • ISO 27001.
  • SOC 2.
  • PCI-DSS.
  • HIPAA.
Certifications (Preferred)
  • CISSP / CISM.
  • CEH.
  • CompTIA Security+.
  • GIAC Certifications (GCIA / GCIH / GCED).
  • Cloud Security Certifications (AWS / Azure / GCP/ Oracle).
Leadership Competencies
  • Strong executive communication and stakeholder management.
  • Ability to manage high-pressure incidents.
  • Strategic thinking with operational excellence.
  • Engineering mindset with product-oriented thinking.
  • Strong documentation and governance discipline.
Work Model
  • Mandatory 5-day work from office (Bangalore or Mumbai).
  • On-call availability during major incidents or IR situations.
Skills
  • Security Incident Response.
  • Communication Skills.
  • Collaboration.
  • Cybersecurity Strategy.
  • Certifications Management.
  • Threat Analysis.
  • Continuous Learning.
  • Leadership Team Management.
  • Policy Development.

(ref:hirist.tech)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
SOC Manager
SOC Manager

Sisainfosec • Bengaluru

On-site
INR 1,500,000 - 2,500,000
SOC Manager
SOC Manager

Keka Technologies • Bengaluru

On-site
INR 350,000 - 600,000
SOC Manager
SOC Manager

Angel One • Bengaluru

Hybrid
INR 1,800,000 - 3,200,000
SOC / Security Operations Lead
SOC / Security Operations Lead

Paytm • Dadri

On-site
INR 3,500,000 - 7,000,000
SOC Specialist
SOC Specialist

METRO Global Solution Center IN • Maharashtra

On-site
INR 1,500,000 - 2,300,000
Head - SOC Incident Response
Head - SOC Incident Response

Adani Enterprises Limited • Ahmedabad District

On-site
INR 2,200,000 - 4,500,000
SOC / Security Operations Lead
SOC / Security Operations Lead

One97 Communications Limited • Dadri

On-site
INR 3,000,000 - 6,000,000
Senior SOC Analyst/SOC Lead
Senior SOC Analyst/SOC Lead

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 1,200,000 - 2,400,000
ARCHITECT - SOC Monitoring
ARCHITECT - SOC Monitoring

Happiest Minds Technologies • Bengaluru

Hybrid
INR 4,000,000 - 6,500,000