Sr. SOC Engineer (L3)

Larsen & Toubro

Chennai District

On-site

INR 2,500,000 - 4,000,000

Full time

27 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Larsen & Toubro is seeking a seasoned SOC L3 expert to act as the senior escalation point for threat hunting, incident investigations, security engineering, and strategic cyber defence initiatives across multi-tenant GPU cloud environments.

The role emphasizes zero-trust, regulatory alignment, on-call support, and collaboration with Threat Intelligence and Red Team to strengthen defenses and drive incident-response excellence.

Qualifications

  • 8–15 years of cybersecurity experience with cloud security and zero-trust focus.
  • Deep expertise in SIEM platforms such as Splunk, QRadar, Chronicle, or equivalents.
  • Advanced knowledge of modern EDR/XDR solutions and threat hunting methodologies.

Responsibilities

  • Lead investigation of sophisticated cyber attacks and advanced persistent threats (APTs).
  • Perform proactive threat hunting across enterprise environments.
  • Develop advanced detection engineering use cases.
  • Design and optimize SIEM, SOAR, XDR, and cloud security monitoring capabilities.
  • Conduct forensic investigations across endpoints, networks, cloud, and identity platforms.
  • Develop incident response playbooks and automation workflows.
  • Lead post-incident reviews and lessons-learned sessions.
  • Provide security recommendations to architecture and engineering teams.
  • Mentor SOC L1/L2 analysts and support career development.
  • Coordinate with Threat Intelligence and Red Team functions.
  • Support security audits, compliance, and executive reporting.
  • ON-CALL Support for L2/L1 support team.

Skills

Threat hunting
Incident response
SIEM/XDR
Cloud security
Zero trust
Forensics
Automation
Kubernetes security
Identity Security
Leadership & mentoring

Education

BE/BTech in CS/EC

Tools

Splunk
QRadar
Chronicle
Sentinel/XDR

Job description

Job Purpose

The SOC L3 acts as the Senior technical escalation point within the SOC, leading threat hunting, advanced incident investigations, security engineering improvements, and strategic cyber defence initiatives. Protect multi tenant GPU cloud with defense in depth, ensuring zero trust, auditability, and regulatory alignment.

Job Purpose

The SOC L3 acts as the Senior technical escalation point within the SOC, leading threat hunting, advanced incident investigations, security engineering improvements, and strategic cyber defence initiatives. Protect multi tenant GPU cloud with defense in depth, ensuring zero trust, auditability, and regulatory alignment.

Role Description
Key Responsibilities
  • Lead investigation of sophisticated cyber attacks and advanced persistent threats (APTs).
  • Perform proactive threat hunting across enterprise environments.
  • Develop advanced detection engineering use cases.
  • Design and optimize SIEM, SOAR, XDR, and cloud security monitoring capabilities.
  • Conduct forensic investigations across endpoints, networks, cloud, and identity platforms.
  • Develop incident response playbooks and automation workflows.
  • Lead post-incident reviews and lessons-learned sessions.
  • Provide security recommendations to architecture and engineering teams.
  • Mentor SOC L1/L2 analysts and support career development.
  • Coordinate with Threat Intelligence and Red Team functions.
  • Support security audits, compliance, and executive reporting.
  • ON-CALL Support for L2/L1 support team.
Implementation
  • Enforce IAM/RBAC, least privilege, and network micro segmentation; secrets/KMS integration.
  • Define secure baselines for OS, containers, CUDA drivers, and platform services; supply chain controls (image signing/SBOM).
  • Implement and management experience of cloud network security controls such as security groups, firewalls, WAF, DDoS, micro-segmentation, EDR, DLP, PIM/PAM and secure connectivity etc
Operations
  • Continuous vulnerability management, patch cadence, threat detection (EDR/XDR), and audit log integrity.
  • Periodic access reviews, key rotation, and compliance evidence packs.
Reliability & Incident
  • Incident response (containment/forensics/eradication); purple team exercises; tabletop drills.
Data Protection
  • Encryption in transit/at rest, tenant isolation boundaries, data retention, legal holds, and purge workflows.
Experience & Educational Requirements
Qualifications and Experience
EDUCATIONAL QUALIFICATIONS: (degree, training, or certification required)

BE/B-Tech or equivalent with Computer Science or Electronics & Communication

RELEVANT EXPERIENCE: (no. of years of technical, functional, and/or leadership experience or specific exposure required)
  • 8–15 years cybersecurity; strong cloud security, zero trust, and data privacy in regulated environments.
  • Deep expertise in Sentinel, Splunk, QRadar, Chronicle, or equivalent SIEM platforms.
  • Advanced knowledge of Microsoft Defender XDR, Defender for Cloud, CrowdStrike, SentinelOne, and other XDR solutions.
  • Strong threat hunting expertise using MITRE ATT&CK framework.
  • Expertise in cloud security (Azure, AWS, GCP).
  • Digital forensics and malware reverse engineering knowledge.
  • Security automation using Python, PowerShell, Logic Apps, SOAR platforms.
  • Detection engineering and threat modeling skills.
  • Knowledge of Zero Trust Architecture and Identity Security.
  • Ability to lead major security incidents and crisis management efforts.
  • Experience with Active Directory, Microsoft Entra ID, CyberArk, or enterprise PAM solutions.
  • Experience with NIST CSF, NIST 800-61, MITRE, CIS Controls, and ATTACK evaluations.
  • Experience building SOC metrics, executive dashboards, and reporting for senior leadership.
  • Experience with security architecture reviews and cloud landing zone security.
  • Investigate advanced identity-based attacks involving Active Directory, Microsoft Entra ID, PAM, IAM, Kerberos, and hybrid identity environments.
  • Lead investigations involving Kubernetes, container runtime, virtualization platforms, and GPU infrastructure security.
Tools / Tech

SIEM (Splunk/ELK), EDR/XDR, image scanners (Trivy/Clair), OPA/Gatekeeper, Vault/KMS/HSM, HashiCorp Boundary (or equivalent), NVIDIA DCGM, NVIDIA BCM, Firewalls, DDOS, WAF, LB, VAM, PAM

Certifications

CISSP; CISM/CISA; CCSP; ISO 27001 Lead Implementer/Auditor, GCFA, GCTI, CISSP, CCSP, AZ-500, SC-100, SC-200, GIAC Certifications, Microsoft Cybersecurity Architect Expert, Kubernetes Security Specialist.

KPIs

Mean time to detect/respond, vulnerability backlog burn down, audit non conformities, policy violation rate.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

PeopleStrong • Chennai District

On-site
INR 1,800,000 - 2,600,000
Security Analyst - L2
Security Analyst - L2

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,200,000 - 1,600,000
SOC L3 Expert
SOC L3 Expert

Maandag® Middle East • India

On-site
INR 800,000 - 1,200,000
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Cyber Security Engineer II
Cyber Security Engineer II

high radius • Hyderabad

On-site
INR 900,000 - 1,500,000
Technical Specialist - Cyber Security L3
Technical Specialist - Cyber Security L3

Lenovo • Bengaluru

On-site
INR 1,400,000 - 2,100,000
Security Technician - SOC Analyst
Security Technician - SOC Analyst

Fujitsu • Pune District, Bengaluru, Dadri

Hybrid
INR 900,000 - 1,300,000
ARCHITECT - SOC Monitoring
ARCHITECT - SOC Monitoring

Happiest Minds Technologies • Bengaluru

Hybrid
INR 4,000,000 - 6,500,000
Information Security Specialist
Information Security Specialist

ZEISS India • Bengaluru

On-site
INR 800,000 - 1,200,000
SOC Analyst L2
SOC Analyst L2

Keka Technologies Private Limited • Gurugram District

On-site
INR 1,200,000 - 2,500,000