Turn this role into an interview — a resume and cover letter built around what this employer wants.
Vodafone's Security Operations Centre seeks a SOC Lead to head 24x7 monitoring and incident response across markets, delivering high-quality detection and rapid remediation.
You will drive automation, SOAR and AI-enabled capabilities, mentor a global team, and report performance to senior leadership. Requires 8+ years in security ops and strong SIEM expertise.
Select how often (in days) to receive an alert:
Aggregate function: Shared Services
Business Area: Technology _VOIS
Posting Country: India
Full Time / Part Time: Full Time
Contract Type: Permanent
At Vodafone, we’re working hard to build a better future. A more connected, inclusive and sustainable world. As a dynamic global community, it's our human spirit, together with technology, that empowers us to achieve this.
We challenge and innovate in order to connect people, businesses, and communities across the world. Delighting our customers and earning their loyalty drive us, and we experiment, learn fast and get it done, together.
With us, you can be truly be yourself and belong, share inspiration, embrace new opportunities, thrive, and make a real difference.
We are seeking an experienced SOC Lead to head Vodafone’s Security Operations Centre (SOC) as part of Cyber Defence Operations (CDO). This role is accountable for the end-to-end delivery of SOC monitoring and response services across markets, ensuring consistent, high-quality detection and incident response in a 24x7 environment.
The role combines operational leadership, deep technical expertise, and a strong transformation mindset, with a particular focus on embedding automation and AI-driven capabilities into live SOC operations. Acting as a bridge between operational excellence and SOC modernisation, the individual will ensure that new capabilities are effectively adopted, governed, and optimised to strengthen Vodafone’s global cyber defence posture.
Lead and manage 24x7 SOC operations, ensuring consistent, high-quality alert monitoring, triage, and incident response across all markets. Own and drive SOC service performance against key KPIs including MTTT, MTTR, triage quality, and SLA adherence, delivering measurable improvements in detection quality, response speed, and efficiency. Oversee the full alert lifecycle, ensuring accurate investigation, containment, escalation, and high-quality incident reporting. Continuously enhance detection capabilities by improving SIEM use cases, alert logic, and playbooks, reducing false positives and increasing coverage across priority threat scenarios. Drive the adoption of automation, SOAR, and AI-assisted capabilities to improve speed, consistency, and scalability, with appropriate governance and human oversight. Lead SOC transformation initiatives focused on reducing alert fatigue, streamlining workflows, and improving analyst productivity. Build, coach, and develop a high-performing SOC team through structured capability development, performance management, and knowledge sharing. Act as the final escalation point for complex or high-risk incidents, applying expert judgement to validate and close cases. Deliver clear, data-driven SOC performance and incident reporting to senior leadership. Foster a culture of continuous improvement through post-incident reviews, detection retrospectives, and operational learning.
An experienced cybersecurity professional with 8+ years in security operations, including at least 4+ years in a SOC leadership or senior incident response role. A proven leader of 24x7 SOC teams, with a strong track record of improving MTTT/MTTR, triage quality, and operational performance. A technical authority in incident response, capable of leading complex investigations and making sound decisions under pressure. Highly experienced with SIEM platforms such as Splunk, Microsoft Sentinel, Google SecOps, ArcSight, or QRadar, and familiar with EDR/NDR technologies. Skilled in driving SOC automation, SOAR, and AI-enabled capabilities, with a clear understanding of governance and responsible use. Knowledgeable across network, endpoint, and cloud security, with a strong grasp of attacker techniques and the MITRE ATT&CK framework. An analytical decision-maker who balances risk, speed, and business impact in ambiguous situations. Passionate about developing people and building sustainable SOC capability for the future. Educated to degree level in Cyber Security, Computer Science, Information Technology, or a related discipline (or equivalent practical experience). Holder of relevant certifications such as GIAC, CISSP, or vendor-specific SOC certifications; interest or exposure to AI/ML in security is an advantage. Committed to continuous learning, innovation, and contribution to the wider security community.
Concerned you may not meet every requirement? Vodafone is committed to creating an inclusive workplace where everyone can thrive. If you are excited about this role but your experience does not align exactly with every aspect of the job description, you are encouraged to apply. You may be the right candidate for this or another opportunity, and the recruitment team will support you in exploring where your skills fit best.
The opportunity to lead a globally impactful SOC function within a recognised Cyber Defence Centre of Excellence. Exposure to large-scale, complex cyber defence operations across multiple international markets. The chance to shape and influence the future of SOC operations through automation and AI-driven transformation. A collaborative, inclusive environment that supports professional growth and continuous learning. The ability to work with advanced security technologies and experienced cyber defence professionals.
Advanced SOC leadership in a highly automated, AI-enabled operational environment. Strategic integration of SOAR and AI capabilities into live security operations. Enhanced stakeholder communication and executive-level cyber risk reporting. Scalable SOC governance and performance management across global operations. Deepened expertise in emerging threat landscapes and modern detection engineering.
Vodafonerecognisesand celebrates the value of diversity in building a workforce that reflects the customers and communities it serves. No form of discrimination is tolerated. This includes, but is not limited to, discrimination based on race,colour, age, veteran status, gender identity, gender expression, sexual orientation, pregnancy, maternity or parental status, ethnicity, disability, religion or belief, political affiliation, trade union membership, nationality, citizenship, indigenous status, medical condition, HIV status, neurodiversity, social origin, cultural background, marital or civil partnership status, or socio-economic background.
At Vodafone, we’re working hard to build a better future. A more connected, inclusive and sustainable world. As a dynamic global community, it's our human spirit, together with technology, that empowers us to achieve this.
We challenge and innovate in order to connect people, businesses, and communities across the world. Delighting our customers and earning their loyalty drive us, and we experiment, learn fast and get it done, together.
With us, you can truly be yourself and belong, share inspiration, embrace new opportunities, thrive, and make a real difference.
Vodafone is committed to attracting, developing and retaining the very best people by offering a motivating and inclusive workplace in which talent is truly recognised and rewarded. We are committed to promoting Inclusion for All with the belief that diversity plays an important role in the success of our business. We actively encourage everyone to consider becoming a part of our journey.