Padmi

SIEM/SOC Architect + Threat Engineering Lead

MumbaiPosted 3 months ago
CybersecuritySeniorFull Time; Regular
Apply at LIC HOUSING FINANCE LIMITED

Opens the source posting on shine.com

Source description

About the role

View original

Hiring Requirement Form Basic Position Details Position Title: SIEM/SOC Architect + Threat Engineering Lead Location: Mumbai Candidate Profile Requirements Mandatory Criteria Age Limit as on: 25-32 Education Qualification: B.E/B Tech/BCA in computer Science or IT Minimum % Required: 60 Minimum Experience Required: 4 years Relevant Industry/Domain Experience: At least 4 years experience in BFSI Preferred Criteria (if applicable) Preferred Skills: Good understanding of Cyber SOC Certifications (if any): CISSP/ CISM or equivalent Languages Required: English Interview & Selection Process Interview (Online / In-person): First round online and second In-Person Any other important instructions: Roles & Responsibilities SOC Strategy, Governance & Leadership Define SOC vision, roadmap, and maturity model (aligned with NIST / MITRE / RBI expectations) Establish SOC operating model (L1, L2, L3, Threat Hunting, Engineering) Manage the Internal SOC team and External vendors / MSSPs Ensure alignment with Business risk appetite and Regulatory requirements (RBI, NHB, ISO 27001) Own and manage SIEM platform Responsible to provide regular assurance on: Complete and accurate log ingestion Data parsing, normalization, and enrichment Optimize correlation rules Enhance visibility across enterprise SOC detection capability are mapped to MITRE ATT&CK framework Known attack vectors and emerging threats Threat Intelligence Management Integrate threat intelligence feeds (internal & external) into SOC workflows Correlate IOCs (IP, domain, hash) and TTPs (attacker behaviour) Enable proactive defence & threat hunting Drive proactive threat hunting exercises Identify Hidden threats and Advanced persistent threats (APT) Continuously tune the solution to Reduce false positives and Improve detection accuracy Lead complete incident lifecycle management i.e. Detection, Analysis, Containment and Recovery As and when required conduct root cause analysis Post-incident reviews Deploy and manage SOAR platform Stakeholder Management & Reporting Act as bridge between SOC team, IT teams and Senior management Provide Executive dashboards and Risk-based reporting Translate Technical findings Business impact Focus on Automation: Alert triage Incident enrichment Response workflows Define: Log retention policies Cost optimization strategy Design, implement, and maintain: SIEM rules/use cases and Correlation logic Behavioural analytics rules Context-aware alerting Incident severity levels and Escalation framework Response SLAs SOC Performance & Metrics Management such as MTTD (Mean Time to Detect), MTTR (Mean Time to Respond), False positive rate, Percentage Coverage of log sources, Automation ratio, etc. Continuously improve: Detection quality Response efficiency EDR / XDR Management Manage enterprise endpoint security tools Regularly ensure Full endpoint coverage and Proper policy enforcement across Oversee: Detection of endpoint-based threats Response actions (isolation, remediation) Integrate EDR alerts into SIEM for unified visibility Develop playbooks for: Phishing attacks Malware outbreaks Insider threats Log Integration & Enterprise Visibility Integrate logs from: Network & Security Devices Firewalls, IDS/IPS, proxies EDR/XDR Active Directory / IAM Security Solutions such as DLP, Email Security Gateway, CASB, CloudTrail, etc. Business / Advanced Systems such as AI/ML platforms, critical applications and Custom applications Vulnerability Management Integration and threat exposure management: Integrate logs from Vulnerability Assessment, threat exposure tools and perform logs Correlation Enable: Risk-based prioritization Continuous visibility of attack surface Identification of exploitable assets and exploitable paths Integrate vulnerability logs, CTEM data into SIEM Correlate the Vulnerability Exposure data + real-time threats Brand Monitoring & Digital Risk Protection Monitor organizations external digital footprint , including: Fake domains / phishing websites Social media impersonation Dark web mentions (credentials, leaks) App store impersonations Use tools/services for: Brand abuse detection Data leak monitoring Coordinate actions: Domain takedown Phishing response Customer awareness Integrate brand monitoring alerts into SIEM/SOC workflows Compliance & Audit Support Ensure SOC is aligned to RBI cybersecurity framework, other RBI/ NHB guidelines and ISO 27001 controls As and when required provide audit support, audit evidence, Logs and incident reports

One address, no account. We’ll tell you when matching roles go live.

More at LIC HOUSING FINANCE LIMITED

Related open roles

View all roles