SOC-Associate Director

SISA

Bengaluru

On-site

INR 1,000,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

SISA in Bengaluru is looking for a Lead Threat Analyst to enhance SOC operations and manage a team of Threat Analysts. The role involves daily reviews of security alerts, mentoring junior analysts, and providing Incident Response support.

The ideal candidate should have hands-on experience with SIEM tools such as Qradar or Splunk and possess team management skills. Join us to contribute to a robust security posture and continuous improvement in incident response.

Qualifications

  • Hands-on experience required on SIEM tools like Qradar or Splunk.
  • More than 1 year of experience in L3/Lead roles and team management.
  • Good understanding of database and cybersecurity products essential.

Responsibilities

  • Serve as escalation point for Threat Analysts on unusual alerts.
  • Daily review and follow-up on security alerts and logs.
  • Mentor associate team members and enhance SOC operations.
  • Develop SOC dashboards and threat reports for stakeholders.
  • Respond to security alerts and provide Incident Response support.

Skills

SIEM tool experience (Qradar, Splunk, Alien Vault, Arcsight, McAfee)
L3 / Lead experience and team management
Team management
Network management / operations management
Understanding of database and security products
Building threat hypothesis and threat intelligence

Job description

Serve as an escalation point for all Threat Analysts on shift for complex or unusual alerts, cases, requests, and incidents.

Daily review of security alerts and logs with follow‑up on any suspicious activity.

Review cases escalated by Threat Analysts to investigate, respond, and remediate; ensure an effective flow of escalated cases; and conduct quality assurance of cases.

Mentor associate team members and contribute to streamlining SOC operations for continuous improvement.

Ensure an escalated flow of the Incident Management System; assist the team in developing the incident response strategy and creating and assigning response actions to Threat Analysts as needed.

Provide timely and actionable insights to executive leadership and cross‑functional teams.

Develop and deliver SOC dashboards, threat summaries, and risk reports to stakeholders.

Perform investigation of network and hosts/endpoints for malicious activity, including analysis of packet captures, and assist in efforts to detect, confirm, contain, remediate, and recover from attacks.

Proactively monitor, identify, and analyze complex internal and external threats, including viruses, targeted attacks, and unauthorized access, and mitigate risk to IT systems.

Establish and maintain robust SOPs, incident playbooks, escalation matrices, and case management workflows.

Ensure SOC processes are aligned with regulatory frameworks such as ISO 27001, NIST CSF, GDPR, PCI DSS, or local data protection laws.

Support internal and external audits and contribute to enterprise risk management initiatives.

Define approach and strategy to help improve customer security posture and reduce attack surface.

Root‑cause analysis and troubleshoot complex issues with existing security and privacy protection protocols.

Respond to inbound security monitoring alerts, emails, and inquiries from the organization.

Provide support for Incident Response, including evidence collection, documentation, communications, and reporting.

Responsible for onboarding the clients; both in cloud and on‑prem or as per solution.

Have good understanding and exposure of the security landscape and cybersecurity tools.

Own end‑to‑end planning of the annual budget for the service line, including headcount, tools, training, and infrastructure.

Mandatory Skills Required For The Role
  • Hands‑on working experience on any SIEM tool (Qradar, Splunk, Alien Vault, Arcsight, McAfee).
  • More than 1 year of L3 / Lead experience and team management is required.
  • Team management and network management / operations management.
  • Good understanding of database, security products (Firewall, IDS/IPS, AV/ EDR) and other tech products in cyberspace.
  • Hands‑on experience in building threat hypothesis and threat intelligence.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Technical Specialist - Cyber Security L3
Technical Specialist - Cyber Security L3

Lenovo • Bengaluru

On-site
INR 1,400,000 - 2,100,000
Team Lead - SOC
Team Lead - SOC

Indian Financial Technology And Alliedservices • Hyderabad

On-site
INR 1,800,000 - 2,500,000
Senior SOC Analyst/SOC Lead
Senior SOC Analyst/SOC Lead

NTT DATA BUSINESS SOLUTIONS • Hyderabad

Hybrid
INR 1,200,000 - 2,400,000
SOC Manager
SOC Manager

Sisainfosec • Bengaluru

On-site
INR 1,500,000 - 2,500,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Cyber Security - Subject Matter Expert
Cyber Security - Subject Matter Expert

Lenovo • Bengaluru Urban

On-site
INR 1,500,000 - 2,500,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
L3 SOC Analyst
L3 SOC Analyst

UST • Bengaluru

On-site
INR 1,500,000 - 2,100,000
TECHNICAL LEAD - SOC Monitoring
TECHNICAL LEAD - SOC Monitoring

Happiest Minds Technologies • Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Team Lead - SOC
Team Lead - SOC

IFTAS - Indian Financial Technology & Allied Services • Hyderabad

On-site
INR 1,200,000 - 2,100,000