SOC Principal

HCLSoftware

Bengaluru

On-site

INR 4,500,000 - 7,500,000

Full time

14 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

HCL Software is seeking a SOC Principal to serve as the senior technical authority in our Security Operations Center. This hands-on role focuses on depth and influence rather than management, shaping detection, investigation rigor, and incident command across a global multi-cloud and SaaS estate.

You will set the technical bar for detections, forensics, and response, collaborating with SOC Engineering, Red Team, and Product Security.

Qualifications

  • >8+ years in security operations, incident response, or threat detection, including senior or lead responsibility for major incidents.
  • ">Demonstrated incident command experience on severity-1 events, with sound judgment.
  • ">Deep hands-on expertise with SIEM platforms and detection content development, including query languages and tuning.
  • ">Strong working knowledge of EDR telemetry, identity and SSO attack patterns, and cloud security operations across AWS, Azure, or GCP.
  • ">Fluency with MITRE ATT&CK as an operational tool, including coverage mapping and gap analysis.
  • ">Practical scripting and automation ability (Python, PowerShell) for enrichment and tooling.
  • ">Excellent written communication, including incident narratives for executives, customers, and auditors.

Responsibilities

  • Act as a technical incident commander for severity-1 and severity-2 events, coordinating across IT, engineering, legal, communications, and customer-facing teams.
  • Own the deep-dive analysis: host and memory forensics, cloud control-plane reconstruction, identity abuse chains, and lateral movement tracing.
  • Drive root cause to conclusion and convert significant incidents into concrete detection, control, and process changes with named owners.
  • Set and enforce evidence handling, chain of custody, and case documentation standards suitable for customer, regulator, and audit scrutiny.
  • Define detection content standards covering test coverage, version control, peer review, and promotion through a detection-as-code pipeline.
  • Maintain an ATT&CK-aligned coverage map, identify blind spots, and prioritize new content against threat intelligence and business risk.
  • Govern tuning and suppression decisions so false positives don’t remove real visibility.
  • Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source reliability.
  • Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed adversary tradecraft.

Skills

Incident command
Threat detection
AI security
Scripting (Python/PowerShell)
Written communication

Tools

SIEM platforms
EDR telemetry
Threat intelligence
Detection-as-code tooling

Job description

About the Role

HCL Software is seeking a SOC Principal to serve as the most senior technical authority inside our

Security Operations Center. This is a hands-on individual contributor role for someone who wants

depth and influence rather than a management span, and it sits at the point where detection quality,

investigation rigor, and incident command all converge.

You will set the technical bar for how the SOC detects, investigates, and closes out threats across a

global multi-cloud and SaaS estate, while our detection platform modernizes and our telemetry

pipeline is rebuilt.

You will work alongside SOC Engineering, Vulnerability Management, Red Team, and Product

Security, and you will be the person the organization escalates to when an incident is genuinely

Key Responsibilities
Investigation and Incident Response
  • Act as a technical incident commander for severity-1 and severity-2 events, coordinating across

    IT, engineering, legal, communications, and customer-facing teams.

  • Own the deep-dive analysis that junior tiers cannot complete: host and memory forensics,

    cloud control-plane reconstruction, identity abuse chains, and lateral movement tracing.

  • Drive root cause to conclusion and convert every significant incident into concrete detection,

    control, and process changes with named owners.

  • Set and enforce evidence handling, chain of custody, and case documentation standards

    suitable for customer, regulator, and audit scrutiny.

Detection and Content Engineering
  • Define detection content standards covering test coverage, version control, peer review, and

    promotion through a detection-as-code pipeline.

  • Maintain an ATT&CK-aligned coverage map, identify blind spots, and prioritize new content

    against threat intelligence and business risk.

  • Govern tuning and suppression decisions so false-positive reduction never quietly removes real

    visibility.

  • Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source

Threat Hunting and Intelligence
  • Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed

    adversary tradecraft relevant to enterprise software companies.

  • Operationalize intelligence into detections, hunt queries, and watchlists rather than leaving it as

    reading material.

  • Collaborate with Red Team on purple-team exercises and validate that emulated tradecraft is

    actually detected.

Technical Leadership
  • Mentor analysts across shifts, run investigation retrospectives, and raise consistency in triage

    and escalation decisions.

  • Author and maintain the runbook and playbook library, keeping it accurate as the platform

    estate changes.

  • Represent the SOC in design discussions with architecture, cloud, and product engineering

    teams.

  • Produce clear written analysis for leadership that separates what is known, what is suspected,

    and what is still open.

Required AI Expertise
  • Hands-on experience implementing and evaluating AI-driven security automation, automated

    triage, and generative AI investigation workflows within a modern SOC environment.

  • Strong understanding of threat landscapes targeting AI/ML systems, including prompt injection,

    model poisoning, data exfiltration via LLMs, MCP, and securing enterprise AI infrastructure.

  • Ability to design detection strategies for AI-assisted attack vectors and adversary tradecraft

    leveraging autonomous or AI-enhanced tools.

Required Qualifications
  • 8+ years in security operations, incident response, or threat detection, including senior or lead

    responsibility for major incidents.

  • Demonstrated incident command experience on severity-1 events, with the judgment to make

  • Deep hands-on expertise with SIEM platforms and detection content development, including

    query languages, correlation logic, and detection tuning.

  • Strong working knowledge of EDR telemetry, identity and SSO attack patterns, and cloud

    security operations across AWS, Azure, or GCP.

  • Fluency with MITRE ATT&CK as an operational tool rather than a slide, including coverage

    mapping and gap analysis.

  • Practical scripting and automation ability (Python, PowerShell, or equivalent) for enrichment,

    analysis, and tooling.

  • Excellent written communication, including the ability to produce incident narratives that hold up

    in front of executives, customers, and auditors.

Preferred Qualifications
  • Experience through a SIEM platform migration, including detection content translation,

    parallel-run validation, and log pipeline rework.

  • Experience with leading technologies (Wiz, Crowdstrike

  • Background in a software or product company, with an understanding of how enterprise SOC

    work connects to customer trust and product security.

  • Familiarity with detection-as-code practices, CI/CD for content, and automated detection

    testing.

  • Experience investigating attacks against SaaS, CI/CD, and software supply chain targets.

  • Exposure to AI-assisted triage and investigation workflows, with a considered view of where

    human judgment remains mandatory.

  • Certifications valued but not required: GCIA, GCIH, GCFA, GNFA, GDAT, or equivalent.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Manager
SOC Manager

SISA • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
SISA Information Security - Security Operations Center Manager - SIEM/SOAR
SISA Information Security - Security Operations Center Manager - SIEM/SOAR

SISA • Bengaluru

On-site
INR 3,000,000 - 5,200,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000
Director of Cyber Security Operations
Director of Cyber Security Operations

HCLSoftware • Bengaluru

On-site
INR 6,000,000 - 9,000,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Director Cyber Security
Director Cyber Security

HCLTech • Dadri, Mhalunge, Jigani

Hybrid
INR 4,000,000 - 7,000,000
Information Security Engineer Lead
Information Security Engineer Lead

Callaway Digital Technologies • Hyderabad

Hybrid
INR 1,200,000 - 1,800,000
SOC Manager
SOC Manager

Keka Technologies • Bengaluru

On-site
INR 350,000 - 600,000
Associate SOC Analyst
Associate SOC Analyst

ISA • Maharashtra

On-site
INR 600,000 - 1,000,000