Website:
benzcalder.com
Job details:
Role Overview:
The Technical SOC Lead is a hands-on, deep technical authority responsible for defending complex, multi-tenant enterprise and financial customer environments. This role is not a passive managerial or people-coordination position.
We are seeking a candidate similar to senior technical leads in tier-one product/IT consulting firms who actively manages multiple high-complexity enterprise and global client accounts simultaneously, remaining deeply involved in the CLI/console, log engineering, high-severity incident containment, and correlation logic design.
The candidate must balance hands-on technical mastery across SIEM, SOAR, EDR, and UEBA with client-facing technical leadership—serving as the direct technical SPOC for client CISOs, incident handlers, and SOC engineering teams.
Primary Responsibilities:
- Hands-On L3 Incident Response & Forensic Containment
- Direct end-to-end incident investigations for critical P1/P2 security incidents, APT intrusions, ransomware execution, credential stuffing, and data breaches across diverse client environments.
- Act as the final technical escalation point for L1/L2 analysts. Take command of active attacks, determine infection vectors, execute remote containment (host isolation, network segmentation, process termination), and drive Root Cause Analysis (RCA).
- Perform deep-dive network traffic analysis (PCAP), memory/disk forensics, and binary/script reverse analysis to counter evasion techniques.
2. Multi-Client Technical Ownership & Delivery
- Serve as the Lead Technical SPOC across multiple large-scale enterprise, banking, and critical infrastructure accounts.
- Lead technical triage bridges and incident war rooms directly with client CISOs, Threat Leads, and Enterprise IT Directors.
- Present technical threat trends, architectural detection gaps, and forensic RCA summaries directly to client leadership
3. Advanced Detection Engineering & SIEM Architecture
- Hands-on ownership of detection logic across modern enterprise SIEMs (e.g., Google SecOps/Chronicle, Splunk ES, IBM QRadar, Microsoft Sentinel, ArcSight).
- Build, parse, and optimize complex correlation rules and analytics queries (KQL, YARA-L, SPL, AQL) mapped strictly to the MITRE ATT&CK matrix.
- Execute aggressive false-positive suppression, baseline profiling, and threshold tuning to maximize SOC alert fidelity.
4. SOAR Playbook Engineering & Automation
- Design, build, and deploy automated and semi-automated incident response playbooks on enterprise SOAR platforms (e.g., Cortex XSOAR, Secura, Splunk SOAR).
- Develop custom automation scripts (Python, PowerShell, APIs) to integrate SIEM/SOAR with EDR platforms (CrowdStrike Falcon, SentinelOne, Carbon Black), next-gen firewalls, IAM, and ticketing platforms.
5. Proactive Threat Hunting & UEBA Modeling
- Execute continuous, hypothesis-driven threat hunts across cloud (AWS/GCP/Azure), on-premises telemetry, and identity providers to uncover hidden adversary persistence.
- Tune UEBA risk models to pinpoint lateral movement, insider threat activity, anomalous privilege escalation, and account takeover.
Required Technical Profile:
- 8–10+ years of core, hands-on SOC and incident handling experience, with at least 3+ years operating in an L3 Senior Technical / Lead capacity.
- Mandatory Multi-Client / MSSP Experience: Demonstrated track record managing threat defense and security operations for multiple concurrent enterprise clients.
- Active Technical Involvement: Must currently spend significant working time in consoles, query editors (KQL, SPL, YARA-L), and incident bridges rather than purely administrative/managerial tasks.
- Multi-SIEM Fluency: Deep administrative and engineering competence in at least two major SIEM solutions (e.g., Google Chronicle/SecOps, Microsoft Sentinel, Splunk ES, QRadar, ArcSight).
- EDR/XDR Mastery: Live containment and hunting expertise across CrowdStrike Falcon, SentinelOne, Cortex XDR, or Microsoft Defender XDR.
- Scripting Competence: Practical capability to write automation scripts and custom parsers (Python, PowerShell, Bash, Regex).
Preferred Certifications:
- Management/Governance: CISM, CISSP
- Incident Response & Operations: GCIH, GCIA, GCED, or ECSA/CEH
- Platform Specializations: Google Cloud SecOps Credential, Microsoft SC-200, Splunk Certified Architect, or Cortex XSOAR Certified
Location:
Andheri East, Mumbai
Click on Apply to know more.