Source description
About the role
Lead enterprise-wide security monitoring, detection, and incident response across SIEM, endpoints, cloud (O365/Azure), and network infrastructure. Act as the primary escalation point for complex and high-severity incidents; perform deep-dive investigations, threat correlation, and root cause analysis. Drive SOC operations, including use-case development, alert tuning, playbook creation, and continuous improvement of detection capabilities. Own and govern security exception processes (e.g., admin access, firewall rule bypasses), ensuring risk-based decisions, proper approvals, and audit readiness. Oversee email and endpoint security posture, including phishing analysis, quarantine management, and advanced threat detection via EDR tools. Lead vulnerability management programs, including prioritization (risk-based), remediation tracking, and coordination with IT/application teams. Guide and review penetration testing activities and validate remediation effectiveness. Define and enforce system hardening standards and security baselines across servers, endpoints, and enterprise tools. Conduct advanced threat hunting and malware analysis to proactively identify emerging threats. Manage and optimize security tools (SIEM, EDR, DLP, IDS/IPS) and improve overall security visibility. Mentor junior analysts and provide technical guidance during investigations and daily SOC operations. Collaborate with cross-functional teams (IT, DevOps, Infrastructure) to integrate security into operations and projects. Support audits, regulatory compliance, and customer security assessments; represent security in external discussions when required. Maintain and enhance security documentation, dashboards, and reporting metrics for leadership visibility. Drive security awareness initiatives and promote a strong security culture across the organization. Skills Strong hands-on expertise in SIEM platforms (e.g., Splunk, Microsoft Sentinel, QRadar) including use-case creation and log correlation. Deep understanding of SOC operations, incident response lifecycle, and threat detection methodologies. Advanced knowledge of endpoint, network, and cloud security controls (EDR, IDS/IPS, Firewalls, DLP, CASB). Strong experience with Microsoft 365 / Azure security and identity protection. Expertise in vulnerability management, risk prioritization, and remediation strategies. Practical experience in threat hunting, malware analysis, and forensic investigation techniques. Solid understanding of networking concepts, protocols, and attack vectors. Strong knowledge of security frameworks and standards (OWASP Top 10, NIST, ISO 27001, CIS Controls, Zero Trust). Proficiency in scripting/automation (Python, PowerShell, Bash) for SOC efficiency and response automation. Familiarity with security testing tools (e.g., Burp Suite, Metasploit, Wireshark, Nessus/OpenVAS). Strong analytical thinking, decision-making, and ability to handle high-pressure incident scenarios. Effective communication skills with the ability to explain technical risks to non-technical stakeholders. Leadership and mentoring capabilities within a SOC or security team. 3. Qualification Bachelor s degree in computer science, Information Technology, Cybersecurity, or a related field. 6 8 years of experience in IT Security, with significant hands-on experience in SOC operations and incident response. Relevant certifications preferred: CompTIA PenTest+, CEH Master, CISM, CCSP, or Microsoft Security certifications (SC-200, SC-300). Proven experience in managing enterprise security tools and handling complex security incidents. Experience in leading or mentoring SOC teams and driving security initiatives. Strong understanding of security governance, risk management, and compliance requirements. Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
More at Utthunga Technologies