SOC LEAD

Anveta Manpower Solutions

Hyderabad

On-site

INR 3,000,000 - 4,500,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Anveta Manpower Solutions seeks a SOC Lead to provide senior-level direction for threat detection, incident response, and continuous improvement across cybersecurity operations in a 24x7 SOC. You will lead incident investigations, develop SOPs, and coordinate with MDR partners to strengthen security outcomes.

The role requires hands-on expertise with SentinelOne EDR, Mimecast, SIEMs, and the MITRE ATT&CK framework, plus strong reporting, RCA, and stakeholder communication skills.

Qualifications

  • 7+ years in 24x7 SOC with lead/senior analyst experience.
  • Experience with SentinelOne EDR, Mimecast, and SIEMs.
  • Ability to produce investigation reports and RCA documents.
  • Strong written and verbal communication for senior stakeholders.

Responsibilities

  • Lead 247 SOC shift activities and handovers.
  • Triage and investigate security events in SentinelOne and Mimecast.
  • Develop SOPs and Playbooks for Event Response.
  • Maintain ServiceNow dashboards and incident tracking.
  • Coordinate with L2 Threat Management and MDR partners.

Skills

Incident triage
SentinelOne EDR
Mimecast
SIEM tools
MITRE ATT&CK
SOPs & Playbooks
Root cause analysis
Scripting (PowerShell/Python)
Leadership (24x7 SOC)
Documentation & reports

Education

Bachelor's degree in CS/IT
Security certifications (CISSP, etc.)
SentinelOne & Mimecast certs
Mimecast Security Certification

Tools

SentinelOne EDR
Mimecast
Tenable
ServiceNow
Azure AD / Entra
Rapid7
QRadar
AWS GuardDuty

Job description

Reporting To:

Manager, Security Operations Event Response team (L1)

Brief Job Description:

The SOC Lead is a senior individual contributor who provides functional leadership, technical direction and operational oversight for SOC capabilities. The role focuses on strengthening threat detection, incident response and continuous improvement across cybersecurity operations.

Technical Skills Required:
  • Incident detection, triage, and investigation in a 24x7 SOC environment
  • Sentinel One EDR -alert investigation, Deep Visibility, Event Search (PowerQuery), exclusion and policy management
  • Email threat investigation using Mimecast gateway - phishing triage, sender policy review, whitelisting verification
  • SIEM: Microsoft Sentinel, Rapid7, or IBM QRadar - query writing, alert rule tuning, use case development
  • MITRE ATT&CK framework - independently mapping observed indicators to adversary TTPs
  • SOP authoring and Playbook development for SOC operations
  • Post-incident analysis and Root Cause Analysis documentation
  • Windows and Linux systems including scripting - PowerShell, Bash, or Python.
Technologies Required:
  • Sentinel One EDR - primary detection and response platform
  • Mimecast - email security gateway
  • Tenable (or equivalent) vulnerability management tool (preferred)
  • ServiceNow - ticketing, SLA management, and dashboard reporting
  • Microsoft Entra ID / Azure AD - identity investigation and conditional access
  • Rapid7 & IBM Qradar: SIEM and SOAR
  • AWS Security: GuardDuty, CloudTrail, EC2 investigation (preferred)
Verbal / Written Skills Required:
  • Clear and structured written and verbal communication — able to brief senior stakeholders concisely during active incidents
  • Ability to produce investigation reports, RCA documents, and management dashboards without editorial support
  • Proficiency in drafting SOPs and Playbooks that analysts can execute independently without managerial guidance
Teamwork / Adaptability Requirements:
  • Ability to lead and hold a shift team to investigation quality standards without requiring escalation for enforcement decisions
  • Comfortable operating in a high-pressure, post-incident environment with multiple concurrent priorities
  • Commitment to continuous learning and active knowledge sharing across the team
  • Adaptable to multi-region APAC operational requirements across Singapore, Malaysia, Korea, China, and Indonesia
Shift Work / Travel Required:

Yes - 24x7 rotational shift operations. No international travel required in standard operations. APAC time zone coverage required.

Years of Experience Required
(Min~Max):

Minimum 7 Years | Maximum 10 Years - with at least 2+ years in a technical lead or senior analyst role in a 24x7 SOC environment.

Education Required:

Any Graduate: Preferred: Bachelor’s degree in computer science, Information Technology, or Cybersecurity (or equivalent experience).

Preferred: CompTIA Security+ | CySA+ | GSEC | SC-200 | CISSP | SentinelOne Certification | Mimecast Certification

Date Recruitment to be Filled:
(On or before)

Immediate

Role Summary:

This role leads a team that supports a High-impact incident management process and resolutions. The SOC Lead is a senior individual contributor who provides functional leadership, technical direction and operational oversight for SOC capabilities. The role focuses on strengthening threat detection, incident response and continuous improvement across cybersecurity operations.

This role requires strong expertise in SOC operations, incident response, detection engineering and security platforms along with guiding analysts and deliver scalable operational improvements.

Core Responsibilities
  • Hands-on experience with SIEM platforms including query writing, alert rule tuning, and use case development from scratch.
  • Strong understanding of SIEM use case lifecycle from threat scenario identification through detection logic design, testing, and ongoing tuning to reduce false positives
  • Provide functional leadership and operational coordination for 247 SOC shift activities including shift handover ownership, coverage planning, and analyst task assignment
  • Independently triage and investigate security events in SentinelOne EDR and Mimecast email gateway - from alert to documented conclusion, not just to mitigation
  • Develop, maintain, and enforce Standard Operating Procedures and Playbooks for the Event Response team covering alert triage, escalation, containment, and closure
  • Conduct alert quality reviews - validate that analyst investigation outputs answer the investigative question before tickets are closed in ServiceNow
  • Build and maintain ServiceNow dashboards for incident tracking, SLA visibility, and team performance reporting for management consumption
  • Enrich and contextualise alerts with threat intelligence - identify TTPs used by threat actors and map findings to MITRE ATT&CK
  • Analyse security events, collect evidence, and support deeper investigations in coordination with the L2 Threat Management team and external MDR partners
  • Maintain incident reporting systems and knowledge databases; contribute to post-incident analysis, RCA documentation, and continuous improvement actions
  • Guide and coach L1 analysts on investigation technique, documentation standards, and tool usage during shift operations
Key Requirements:
  • Strong expertise in SOC operations and incident response in a 247 environment with demonstrated ability to independently close critical severity alerts
  • Hands-on experience with SentinelOne EDR - alert investigation, Deep Visibility, Event Search (Power Query), exclusion and policy management
  • Experience in Vulnerability assessment, Tenable (or equivalent) vulnerability management tool (preferred)
  • Proficiency in Mimecast email gateway -phishing triage, sender policy review, and whitelisting with appropriate verification
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000
SOC L1 Analyst
SOC L1 Analyst

Verint • Bengaluru

On-site
INR 1,000,000 - 1,500,000
SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 2,400,000 - 4,200,000
SOC Analyst
SOC Analyst

AlifCloud IT Consulting Pvt. Ltd. • Maharashtra

On-site
INR 350,000 - 520,000
SOC Lead (Security Operations Center Lead)
SOC Lead (Security Operations Center Lead)

Grazitti Interactive • Panchkula

On-site
INR 2,500,000 - 4,000,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000