Cyber Ops Lead I SOC Lead

Tata Consultancy Services

Draper (UT)

On-site

USD 100,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Discretionary Annual Incentive
Comprehensive Medical Coverage
Family Support: Parental Leaves
Auto & Home Insurance
Certification & Training Reimbursement

Job summary

Tata Consultancy Services in Draper, UT, is seeking a Cyber Ops Lead I SOC Lead with 7+ years in security operations. You will own the SOC case queue, lead day-to-day operations, and coordinate with Tech Operations.

This role requires certifications, cloud security experience, and the ability to develop playbooks, mentor analysts, and report metrics to the Director. On-site work in Draper is required.

Qualifications

  • 7+ years in a Security Operations Center or similar cyber defense role.
  • 1–2 years in a lead, senior analyst, or shift-lead capacity.
  • Demonstrated experience managing case/ticket queues and driving them to resolution in a fast-paced environment.
  • Working knowledge of SIEM, EDR, and case/ticket management tooling.
  • Solid understanding of incident response fundamentals (triage, containment, escalation).
  • Comfortable working cross-functionally with Technology Operations, IT, and Engineering teams.

Responsibilities

  • Own the SOC case queue: triage incoming alerts, tickets, and requests; assign priority and ownership; track cases through to resolution.
  • Maintain SLAs for case handling and escalation; identify and clear bottlenecks before they become backlogs.
  • Ensure consistent documentation, categorization, and closure quality across all cases.
  • Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.
  • Coordinate shift coverage and on-call rotations to maintain continuous monitoring.
  • Serve as a senior escalation point for analysts on complex or ambiguous cases.
  • Drive continuous improvement of detection content, playbooks, and standard operating procedures.
  • Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams.
  • Coordinate response and remediation activities that require Tech Operations involvement.
  • Participate in change management and operational reviews where security input is needed.
  • Support incident response efforts, including initial triage, containment recommendations, and coordination across teams during active incidents.
  • Contribute to post-incident reviews and help translate lessons learned into process or tooling improvements.
  • Mentor and provide day-to-day guidance to SOC analysts; support onboarding and skills development.
  • Help set expectations for case quality, communication, and escalation practices.
  • Track and report on SOC operational metrics to the Director, Cyber Defense & Strategy.

Skills

Regulated industry
Cloud security
SOC playbooks
Queue triage
Escalation paths
Team leadership
Reporting

Tools

SIEM
EDR
Ticketing system

Job description

  • Experience in a regulated industry (healthcare, financial services, or similar) handling
  • Relevant certifications such as GCIH, GCIA, Security+, CySA+, or equivalent.
  • Familiarity with cloud environments (AWSlAzure) and common cloud security tooling.
  • Prior experience building or refining SOC playbooks, runbooks, or standard operating procedures.
  • SOC case queue is triaged consistently with clear ownership and no unexplained aging
  • Escalation paths to Tech Operations are documented and running smoothly, with fewer dropped handoffs.
  • Analyst team has clear expectations, regular feedback, and improving case quality.
  • Director, Cyber Defense & Strategy has reliable visibility into SOC health through regular reporting
Job Description

Role - Cyber Ops Lead I SOC Lead

Experience Required -7+ Years

Must Have Technical/Functional Skills
  • Experience in a regulated industry (healthcare, financial services, or similar) handling

sensitive data.

  • Relevant certifications such as GCIH, GCIA, Security+, CySA+, or equivalent.
  • Familiarity with cloud environments (AWSlAzure) and common cloud security tooling.
  • Prior experience building or refining SOC playbooks, runbooks, or standard operating procedures.
  • SOC case queue is triaged consistently with clear ownership and no unexplained aging
  • Escalation paths to Tech Operations are documented and running smoothly, with fewer dropped handoffs.
  • Analyst team has clear expectations, regular feedback, and improving case quality.
  • Director, Cyber Defense & Strategy has reliable visibility into SOC health through regular reporting
Roles & Responsibilities
Key Responsibilities
Case & Queue Management
  • Own the SOC case queue: triage incoming alerts, tickets, and requests; assign priority and ownership; track cases through to resolution.
  • Maintain SLAs for case handling and escalation; identify and clear bottlenecks before they become backlogs.
  • Ensure consistent documentation, categorization, and closure quality across all cases.
SOC Leadership & Operations

Lead day-to-day SOC operations, including monitoring, alert triage, and initial incident response.

  • Coordinate shift coverage and on-call rotations to maintain continuous monitoring.
  • Serve as a senior escalation point for analysts on complex or ambiguous cases.
  • Drive continuous improvement Of detection content, playbooks, and standard operating procedures.
Partnering with Technology Operations
  • Act as the primary liaison between Cyber Defense and Tech Operations on issues that span both teams (eg., system changes, outages, access requests, infrastructure-related findings).
  • Coordinate response and remediation activities that require Tech Operations involvement, ensuring clear handoffs and shared visibility into status.
  • Participate in change management and operational reviews where security input is needed.
Incident Response
  • Support incident response efforts, including initial triage, containment recommendations, and coordination across teams during active incidents.
  • Contribute to post-incident reviews and help translate lessons learned into process or tooling improvements.
Mentorship & Team Development
  • Mentor and provide day-to-day guidance to SOC analysts; support onboarding and skills development.
  • Help set expectations for case quality, communication, and escalation practices.
Reporting & Metrics
  • Track and report on SOC operational metrics (case volume, time-to-triage, time-to-resolution, escalation rates) to the Director, Cyber Defense & Strategy.
  • Flag trends or recurring issues that indicate a need for process, tooling, or staffing changes.
Required Qualifications

5+ years of experience in a Security Operations Center or similar cyber defense role, including

at least 1-2 years in a lead , senior analyst, or shift-lead capacity

  • Demonstrated experience managing case/ticket queues and driving them to resolution in a fast-paced environment.
  • Working knowledge Of SIEM, EDR, and case/ticket management tooling
  • Solid understanding Of incident response fundamentals (triage, containment, escalation).
  • Comfortable working cross-functionally with Technology Operations, IT, and Engineering teams.
  • Strong written and verbal communication skills; able to translate technical detail for varied audiences.
  • Willingness and ability to work on-site in Draper, UT, including participation in on-call/shift coverage as needed.

Base Salary Range : $100,000 to $120,000 Per Annum

TCS Employee Benefits Summary

Discretionary Annual Incentive.

Comprehensive Medical Coverage: Medical & Health, Dental & Vision, Disability Planning & Insurance, Pet Insurance Plans.

Family Support: Maternal & Parental Leaves.

Insurance Options: Auto & Home Insurance, Identity Theft Protection.

Convenience & Professional Growth: Commuter Benefits & Certification & Training Reimbursement.

Time Off: Vacation, Time Off, Sick Leave & Holidays.

Legal & Financial Assistance: Legal Assistance, 401K Plan, Performance Bonus, College Fund, Student Loan Refinancing.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Operations Center Technical Lead
Security Operations Center Technical Lead

Invictus International Consulting, LLC • Colorado Springs (CO)

On-site
USD 200,000 - 230,000
Director of IT Security Operations
Director of IT Security Operations

The Security Executive Council • United States

On-site
USD 170,000 - 210,000
Medical, dental, and vision coverage
401(k) company match
Generous Paid Time Off
+1
Senior SOC Analyst (Direct Hire Fortune 100CO)
Senior SOC Analyst (Direct Hire Fortune 100CO)

Confidential • Houston (TX)

On-site
USD 110,000 - 150,000
SOC Analyst I
SOC Analyst I

SOClogix, Inc. • Catonsville (MD)

On-site
USD 55,000 - 75,000
Health insurance
Dental insurance
Vision insurance
+6
Security Operations Center (SOC) Manager/Team Lead
Security Operations Center (SOC) Manager/Team Lead

Ariento • Franklin (TN)

On-site
USD 100,000 - 130,000
SOC Manager with BS Degree
SOC Manager with BS Degree

Acumenz Consulting • United States

On-site
USD 120,000 - 150,000
Senior SOC Analyst (Direct Hire EAD OKAY)
Senior SOC Analyst (Direct Hire EAD OKAY)

Confidential • United States

On-site
USD 120,000 - 180,000
Cybersecurity Operations Analyst (SOC) - Day Shift
Cybersecurity Operations Analyst (SOC) - Day Shift

Jcssolutions • Alexandria (VA)

On-site
USD 105,000 - 150,000
Health insurance
Dental insurance
Vision insurance
+5
Security Operations Center (SOC) Manager
Security Operations Center (SOC) Manager

NR Labs LLC • Washington, Northern (KY)

Hybrid
USD 160,000 - 210,000
Security Operations Center Technical Lead
Security Operations Center Technical Lead

invictusic • Colorado Springs (CO)

On-site
USD 120,000 - 180,000