Technical Manager - SOC

Darwinbox Digital Solutions Pvt. Ltd.

Chennai District

On-site

INR 350,000 - 550,000

Full time

33 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Darwinbox Digital Solutions Pvt. Ltd. is seeking a Lead Cybersecurity Engineer to guide design, deployment, and optimization of enterprise security controls across endpoints, networks, and cloud. You will own SIEM/EDR/TTP use cases, drive incident detection and response, and mentor junior engineers in a fast-paced security operations environment.

The role emphasizes collaboration with SOC, IAM, Cloud, and application teams, plus scripting for automation and policy hardening.

Qualifications

  • Bachelor’s or Master’s degree in IT, CS or Cybersecurity.
  • 10+ years in IT security, with at least 5+ years in security engineering/implementation.
  • Hands-on with EDR, SIEM, IDS/IPS, MDM, M365 Security, IAM/PAM, vulnerability management.
  • Strong knowledge of NIST, ISO 27001, CIS Controls & CIS Benchmarks.
  • Experience in fast-paced SOC/enterprise security operations.

Responsibilities

  • Lead design, deployment, and continuous improvement of security tools and platforms (EDR, SIEM, IDS/IPS, MDM, M365 Security).
  • Architect scalable security controls for endpoints, networks, cloud workloads, and identity systems.
  • Drive incident detection/response engineering, alert tuning, and automation playbooks.
  • Oversee SOC automation, SOAR workflows, and threat intelligence integration.
  • Collaborate with cross-functional teams to implement and monitor security controls.

Skills

Security engineering
Incident response
Threat hunting
SOC enablement

Education

Bachelor’s or Master’s degree in IT/CS/Cybersecurity

Tools

CrowdStrike
Splunk
Microsoft Defender for Endpoint
Microsoft Intune
Entra ID

Job description

We are seeking a highly skilled and experienced Lead Cybersecurity Engineer to lead the design, engineering, deployment, optimization, and ongoing improvement of enterprise security controls and platforms. The role requires strong hands‑on expertise across EDR, SIEM, IDS/IPS, MDM, Microsoft 365 Security, identity security, vulnerability management, and security automation. The successful candidate will drive technical implementation initiatives, strengthen detection and response capabilities, support SOC operations, and ensure security controls align with organizational strategy, risk posture, and compliance requirements.

Key Responsibilities :
  • Lead the design, engineering, deployment, and continuous improvement of enterprise security tools and platforms, including EDR, SIEM, IDS/IPS, MDM, and Microsoft 365 security solutions.
  • Architect and implement scalable security controls to protect endpoints, networks, cloud workloads, identity systems, and business‑critical infrastructure.
  • Manage and optimize integrations across security platforms, including EDR, SIEM, SOAR, MDM, IAM, and related monitoring tools.
  • Drive incident detection and response engineering through alert tuning, detection use case development, correlation logic, and automation playbooks.
  • Oversee deployment and enforcement of endpoint security controls, including DLP, USB/device control, device compliance policies, and endpoint hardening standards.
  • Collaborate with SOC, Infrastructure, IAM, Cloud, and application teams to ensure security controls are implemented, monitored, and operationalized effectively.
  • Lead troubleshooting and root cause analysis for security events, tool failures, policy issues, log ingestion gaps, and control effectiveness concerns.
  • Establish and maintain SIEM use cases, correlation rules, dashboards, reports, and operational metrics to improve monitoring and executive visibility.
  • Conduct vulnerability assessments, validate scan results, support remediation planning, and track risk reduction activities through closure.
  • Participate in change management processes to assess security impact, define control requirements, and ensure security tooling remains aligned with approved changes.
  • Drive automation initiatives using PowerShell, Python, SOAR workflows, and other scripting methods to reduce manual effort and improve response consistency.
  • Develop and maintain security baselines, hardening standards, deployment playbooks, operational guides, and technical documentation.
  • Monitor emerging threats, threat intelligence, and adversary techniques to adapt detections and controls based on current attack trends.
  • Provide technical leadership, coaching, and mentorship to junior engineers, SOC analysts, and cross‑functional teams.
Technical Responsibilities
  • Engineer, deploy, and administer EDR platforms such as CrowdStrike and Microsoft Defender for Endpoint, including policy tuning, threat detection, response actions, and control validation.
  • Implement and manage SIEM platforms such as CrowdStrike NG SIEM or Splunk, including log onboarding, parsing, normalization, dashboarding, and advanced correlation logic.
  • Design, implement, and support IDS/IPS and network security monitoring solutions to improve threat visibility, prevention, and investigation capability.
  • Administer and optimize Microsoft 365 Security capabilities, including Microsoft Defender Suite, Entra ID, Conditional Access, Secure Score improvements, and identity protection controls.
  • Manage MDM platforms such as Microsoft Intune or equivalent solutions for device compliance, device posture, policy enforcement, and access control.
  • Implement of identity security controls, including MFA, Conditional Access, privileged access controls, least privilege, and Zero Trust principles.
  • Build and maintain SOC automation and SOAR workflows for incident triage, evidence collection, containment actions, enrichment, notification, and reporting.
  • Integrate and manage threat intelligence feeds across security tools to support proactive detection, enrichment, and threat hunting.
  • Perform log source integration across servers, endpoints, network devices, cloud platforms, firewalls, identity systems, and business‑critical applications.
  • Support compliance and audit activities, including HIPAA, NIST, ISO 27001, and CIS‑aligned evidence gathering, configuration review, reporting, and technical control validation.
Required Skills and Experience
  • Strong hands‑on experience in security engineering, control implementation, and enterprise security tool deployment.
  • Proven expertise in incident detection, incident response, alert tuning, threat hunting, and SOC enablement.
  • Experience with firewalls, endpoint protection, cloud security controls, identity controls, and Microsoft security ecosystems.
  • Working knowledge of scripting and automation using PowerShell, Python, or similar languages.
  • Ability to troubleshoot complex multi‑layer security issues across endpoint, network, identity, cloud, and application environments.
  • Strong understanding of modern attack techniques, adversary behaviors, MITRE ATT&CK framework, and detection engineering principles.
  • Experience working in fast‑paced SOC, security engineering, or enterprise security operations environments.
  • Strong documentation, stakeholder communication, technical leadership, prioritization, and project execution skills.
Required Qualifications
  • Bachelor’s or Master’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
  • 10+ years of experience in IT Security, including at least 5+ years in security engineering, implementation, or platform administration roles.
  • Hands‑on experience with EDR, SIEM, IDS/IPS, MDM, Microsoft 365 Security, IAM/PAM, vulnerability management, and cloud security controls.
  • Strong understanding of security frameworks and benchmarks, including NIST, ISO 27001, CIS Controls, and CIS Benchmarks.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Neurealm • Chennai District

On-site
INR 2,800,000 - 6,000,000
Technical Manager - SOC
Technical Manager - SOC

GAVS Technologies N.A., Inc • Chennai District

On-site
INR 4,000,000 - 6,500,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software GmbH • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Careernet • Hyderabad

Hybrid
INR 2,000,000 - 3,600,000
Sr Cyber Security Engineer
Sr Cyber Security Engineer

TechBrein Solutions Private Limited • Kozhikode district

On-site
INR 1,200,000 - 2,400,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore France • Bengaluru

On-site
INR 2,000,000 - 3,500,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

Datacore • Bengaluru

On-site
INR 900,000 - 1,500,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Junior Engineer
Junior Engineer

Lyric Exponentials India Private Limited • Hyderabad

On-site
INR 1,000,000 - 1,500,000
SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 3,500,000 - 7,000,000