SOC Manager

Sisainfosec

Bengaluru

On-site

INR 1,500,000 - 2,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sisainfosec is looking for a highly experienced SOC Manager to lead the Security Operations Center. This pivotal role requires someone who can guide SOC operations, improve security posture across environments, and mentor security teams. The ideal candidate will possess extensive experience in cybersecurity and hold strong knowledge in SIEM platforms and network security.

This position mandates a five-day in-office work model in Bangalore or Mumbai, ensuring hands-on leadership during major incidents and operational excellence.

Qualifications

  • 10+ years of cybersecurity experience required.
  • Experience as a SOC Lead or Manager for 4–5 years.
  • Hands-on with at least one SIEM platform.
  • Deep understanding of network and cloud security.

Responsibilities

  • Lead 24x7 SOC operations and incident governance.
  • Own SIEM/SOAR engineering and detection lifecycle.
  • Establish and lead proactive threat hunting programs.
  • Act as primary liaison for Product engineering teams.
  • Train and mentor L1/L2/L3 analysts in the SOC.

Skills

10–12 years of cybersecurity experience
4–5 years in SOC Lead / SOC Manager role
Hands-on experience in SIEM platforms (e.g., Splunk, QRadar)
Network security knowledge
Cloud security experience (AWS, Azure)
Strong documentation skills

Education

Relevant technical certifications (CISSP, CISM)

Tools

SIEM tools (Splunk, Sentinel)
Threat intelligence platforms

Job description

We are seeking a highly experienced and technically strong SOC Manager to lead and evolve our Security Operations Center into a mature, engineering‑driven, and outcome‑focused capability in the AI driven world.

This role requires a hybrid leader who can:

  • Drive 24x7 SOC operations excellence
  • Own SIEM/SOAR engineering & detection lifecycle
  • Collaborate closely with Product & Development teams
  • Influence platform enhancements through operational intelligence
  • Build and mentor high‑performing security teams
  • Highlight risks and gaps in logging methodologies
  • Improve security posture across multi‑tenant cloud and on‑prem environments
Key Responsibilities
1. SOC Operations Leadership & Incident Governance
  • Lead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.
  • Serve as final escalation point (L3/L4) for complex and high‑severity incidents.
  • Define and enforce incident response lifecycle aligned with NIST, ISO 27001, and MITRE ATT&CK.
  • Ensure adherence to SLA / OLA targets (MTTA, MTTR, containment time).
  • Conduct executive‑level incident briefings and publish detailed RCA reports.
  • Ensure compliance with organizational security policies and audit requirements.
  • Oversee case quality assurance and investigation standards.
2. SOC Engineering & Detection Engineering
  • Own SIEM/SOAR architecture optimization and performance tuning.
  • Lead log onboarding strategy (cloud, on‑prem, hybrid environments).
  • Ensure proper log normalization, parsing, enrichment, and correlation.
  • Drive full detection use‑case lifecycle:
    • Use‑case creation
    • Performance measurement
    • Decommissioning of ineffective rules
    • Reduce alert fatigue through risk‑based alerting, contextual enrichment, and behavioural analytics.
    • Implement detection‑as‑code practices with version‑controlled rule management.
    • Ensure high ingestion performance and scalable log retention strategies.
3. Threat Hunting & Advanced Analysis
  • Establish and lead proactive threat hunting programs.
  • Perform advanced investigations including:
    • Packet capture analysis
    • Endpoint telemetry analysis
    • Integrate threat intelligence feeds and manage IOC lifecycle.
    • Identify emerging attack patterns and update detection coverage accordingly.
4. Product Engineering & Platform Enhancement Ownership
  • Act as the primary SOC liaison for Product and Engineering teams.
  • Translate operational pain points into structured enhancement requirements.
  • Maintain and prioritize a backlog of platform improvements.
  • Provide structured feedback on:
    • Query performance issues
    • UX inefficiencies impacting analysts
    • Participate in sprint planning and architecture discussions and provide inputs for enhancements
    • Be part of pilot validation of new features prior to production release.
    • Quantify impact of enhancements (false positive & incident reduction %, MTTR improvement, automation coverage growth).
5. Client Onboarding & Security Architecture Oversight
  • Lead secure onboarding of customers across:
    • Conduct log gap assessments and telemetry validation.
    • Align detection coverage to client risk profiles.
    • Participate in customer governance calls and QBRs.
    • Provide architectural recommendations to improve customer security posture.
6. Team Leadership & Capability Development
  • Lead, mentor, and manage L1/L2/L3 analysts.
  • Establish skill matrix and structured career progression roadmap.
  • Conduct periodic case audits and performance reviews.
  • Develop training programs in:
    • Threat hunting
    • Automation
  • Drive hiring, onboarding, and succession planning.
  • Build a high‑performance, accountability‑driven culture.
  • Define and monitor SOC KPIs:
    • MTTA / MTTR
    • False positive ratio
    • Detection accuracy
    • Automation coverage
    • Incident recurrence rate & reasoning
  • Conduct quarterly SOC maturity assessments.
  • Drive continuous improvement roadmap aligned with business growth.
Mandatory Technical Skills
  • 10–12 years of cybersecurity experience.
  • Minimum 4–5 years in SOC Lead / SOC Manager role.
  • Strong hands‑on experience in at least one SIEM platform:
    • Splunk / Sentinel / QRadar / Elastic / AlienVault / DNIF / McAfee ESM.
  • Deep understanding of:
    • Network security (Firewall, IDS/IPS, WAF)
    • EDR/XDR platforms
    • Cloud security (AWS, Azure)
    • Identity & Access Management
  • Strong knowledge of:
    • MITRE ATT&CK & Defend
    • NIST & NIST IR Framework
    • Defense‑in‑Depth architecture
    • Experience with query writing and log analysis on SIEM technologies.
Preferred Technical & Engineering Skills
  • Scripting (Python / PowerShell / Bash) would be added advantage.
  • Exposure to DevSecOps environments.
  • Knowledge of container and Kubernetes, cloud security.
  • Data analytics for anomaly detection.
  • Familiarity with compliance frameworks:
    • ISO 27001
    • SOC 2
    • PCI‑DSS
    • HIPAA
Certifications (Preferred)
  • CISSP / CISM
  • CEH
  • CompTIA Security+
  • GIAC Certifications (GCIA / GCIH / GCED)
  • Cloud Security Certifications (AWS / Azure / GCP/ Oracle)
  • Strong executive communication and stakeholder management.
  • Ability to manage high‑pressure incidents.
  • Strategic thinking with operational excellence.
  • Engineering mindset with product‑oriented thinking.
  • Strong documentation and governance discipline.
Work Model
  • Mandatory 5‑day work from office (Bangalore or Mumbai).
  • On‑call availability during major incidents or IR situations.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
SOC Manager
SOC Manager

Angel One • Bengaluru

Hybrid
INR 1,800,000 - 3,200,000
SOC / Security Operations Lead
SOC / Security Operations Lead

Paytm • Dadri

On-site
INR 3,500,000 - 7,000,000
SOC Specialist
SOC Specialist

METRO/MAKRO • Pune District

On-site
INR 4,000,000 - 7,000,000
SOC Manager
SOC Manager

SQ1 Security • Chennai District

On-site
INR 1,200,000 - 1,800,000
SOC / Security Operations Lead
SOC / Security Operations Lead

One97 Communications Limited • Dadri

On-site
INR 3,000,000 - 6,000,000
SOC-Associate Director
SOC-Associate Director

SISA • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

Hybrid
INR 1,000,000 - 1,500,000
Head - SOC Incident Response
Head - SOC Incident Response

Adani Enterprises Limited • Ahmedabad District

On-site
INR 2,200,000 - 4,500,000
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000