Get more replies from employers
Send a job-specific resume in minutes.
SISA in Bengaluru is looking for a Lead Threat Analyst to enhance SOC operations and manage a team of Threat Analysts. The role involves daily reviews of security alerts, mentoring junior analysts, and providing Incident Response support.
The ideal candidate should have hands-on experience with SIEM tools such as Qradar or Splunk and possess team management skills. Join us to contribute to a robust security posture and continuous improvement in incident response.
Serve as an escalation point for all Threat Analysts on shift for complex or unusual alerts, cases, requests, and incidents.
Daily review of security alerts and logs with follow‑up on any suspicious activity.
Review cases escalated by Threat Analysts to investigate, respond, and remediate; ensure an effective flow of escalated cases; and conduct quality assurance of cases.
Mentor associate team members and contribute to streamlining SOC operations for continuous improvement.
Ensure an escalated flow of the Incident Management System; assist the team in developing the incident response strategy and creating and assigning response actions to Threat Analysts as needed.
Provide timely and actionable insights to executive leadership and cross‑functional teams.
Develop and deliver SOC dashboards, threat summaries, and risk reports to stakeholders.
Perform investigation of network and hosts/endpoints for malicious activity, including analysis of packet captures, and assist in efforts to detect, confirm, contain, remediate, and recover from attacks.
Proactively monitor, identify, and analyze complex internal and external threats, including viruses, targeted attacks, and unauthorized access, and mitigate risk to IT systems.
Establish and maintain robust SOPs, incident playbooks, escalation matrices, and case management workflows.
Ensure SOC processes are aligned with regulatory frameworks such as ISO 27001, NIST CSF, GDPR, PCI DSS, or local data protection laws.
Support internal and external audits and contribute to enterprise risk management initiatives.
Define approach and strategy to help improve customer security posture and reduce attack surface.
Root‑cause analysis and troubleshoot complex issues with existing security and privacy protection protocols.
Respond to inbound security monitoring alerts, emails, and inquiries from the organization.
Provide support for Incident Response, including evidence collection, documentation, communications, and reporting.
Responsible for onboarding the clients; both in cloud and on‑prem or as per solution.
Have good understanding and exposure of the security landscape and cybersecurity tools.
Own end‑to‑end planning of the annual budget for the service line, including headcount, tools, training, and infrastructure.