Angel One
Website:
angelone.in
Job details:
Security Operations Center (SOC) Manager
Location: Bengaluru
About the Role
We are seeking an experienced Security Operations Center (SOC) Manager to lead our Cyber Defense function and strengthen the organization's capability to detect, investigate, and respond to cyber threats across enterprise environments.
This role will be responsible for overseeing Security Operations, Threat Intelligence, Threat Hunting, Incident Response, Digital Forensics, and Active Defense capabilities. The ideal candidate will bring strong leadership experience, deep technical expertise, and a proven track record of building and maturing enterprise cyber defense programs.
What You Will Do
Security Operations & Monitoring
- Lead and manage Security Operations Center (SOC) activities for continuous monitoring of enterprise environments.
- Oversee detection and analysis of threats across endpoints, networks, identities, cloud platforms, and applications.
- Ensure effective prioritization and escalation of incidents based on business impact and risk.
- Continuously improve SOC processes, playbooks, detection logic, and automation workflows.
- Support integration of security tools, telemetry sources, and automation platforms to enhance visibility and response capabilities.
Threat Intelligence & Threat Hunting
- Collect, analyze, and operationalize cyber threat intelligence from internal and external sources.
- Track adversary behaviors, campaigns, and tactics aligned with MITRE ATT&CK.
- Develop and publish actionable intelligence reports to support detection and defense strategies.
- Conduct proactive threat hunting activities to identify advanced threats that evade automated controls.
- Collaborate with Security Engineering teams to close detection gaps and improve security monitoring.
Incident Response & Digital Forensics
- Lead incident triage, containment, eradication, and recovery efforts.
- Coordinate response activities during significant security incidents.
- Conduct digital forensic investigations and root cause analysis.
- Maintain and improve incident response playbooks and escalation procedures.
- Deliver post-incident reviews and lessons learned to strengthen organizational resilience.
- Partner with Legal, HR, Communications, and business stakeholders during major incidents.
Advanced Cyber Defense
- Perform malware analysis and reverse engineering for high-severity incidents.
- Manage deception technologies and active defense initiatives.
- Conduct dark web monitoring and threat intelligence investigations to identify emerging risks.
- Execute purple team exercises to validate detection and response effectiveness.
- Monitor attack surface intelligence and emerging exposure risks.
- Leverage SOAR and XDR platforms to automate investigations and accelerate response activities.
Reporting & Leadership
- Develop and maintain key security metrics including MTTD, MTTR, detection accuracy, and false positive rates.
- Produce dashboards, executive reports, and actionable insights for leadership and the CISO organization.
- Publish internal threat advisories related to vulnerabilities, exploits, and global threat trends.
- Build, mentor, and develop a high-performing SOC team through coaching and capability development.
- Drive continuous improvement initiatives based on operational metrics and intelligence insights.
What Success Looks Like
- Early detection and rapid containment of cyber threats.
- Intelligence-led cyber defense operations.
- Improved visibility across cloud, network, endpoint, and hybrid infrastructure environments.
- Enhanced incident response maturity and forensic readiness.
- Strong collaboration with Security Engineering and Assurance teams.
- Measurable improvements in detection effectiveness and response performance.
Who You Are
Required Experience
- 10–14 years of experience in Cyber Security, Security Operations, Incident Response, Threat Hunting, or Cyber Defense.
- Proven experience managing Security Operations Centers and cyber defense teams.
- Experience leading enterprise-scale incident response and investigation activities.
Technical Skills
- Strong understanding of SIEM, SOAR, EDR/XDR, NDR, Firewall, and Threat Intelligence platforms.
- Deep knowledge of network protocols including TCP/IP, DNS, HTTP, and SMTP.
- Experience with endpoint, server, and cloud telemetry across AWS, Azure, and GCP.
- Expertise in threat hunting, detection engineering, and adversary simulation techniques.
- Knowledge of MITRE ATT&CK, Cyber Kill Chain, and Diamond Model frameworks.
- Hands-on experience in digital forensics, malware analysis, and incident response.
- Scripting and automation skills using Python, PowerShell, or Bash.
- Experience working with IOC management, threat intelligence feeds, and sandboxing technologies.
- Understanding of identity security, email security, SaaS security monitoring, and attack surface management.
Preferred Certifications
- CISSP, SSCP
- CISM
- Certified SOC Analyst (CSA)
- Certified Ethical Hacker (CEH)
- EC-Council Certified Incident Handler (ECIH)
- CompTIA Security+, CySA+, CASP+
- GIAC Security Certifications
- Additional certifications related to Threat Hunting, Incident Response, Digital Forensics, and Security Leadership
Preferred Industry Background
- FinTech
- E-commerce
- Technology & Cloud Service Providers
- IT Services
- Critical Infrastructure & Energy
- MSSP / MDR Organizations
If you are passionate about building intelligence-driven cyber defense capabilities and leading high-performing security teams, we encourage you to apply.
Click on Apply to know more.