SOC Manager
Sisainfosec · Bangalore · India · On-site
Posted Jun 24, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Role Overview
We are seeking a highly experienced and technically strong SOC Manager to lead and evolve our Security Operations Center into a mature, engineering-driven, and outcome-focused capability in the AI driven world.
This role requires a hybrid leader who can:
Drive 24x7 SOC operations excellence
Own SIEM/SOAR engineering & detection lifecycle
Collaborate closely with Product & Development teams
Influence platform enhancements through operational intelligence
Build and mentor high-performing security teams
Highlight risks and gaps in logging methodologies
Improve security posture across multi-tenant cloud and on-prem environments
Key Responsibilities
1. SOC Operations Leadership & Incident Governance
Lead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.
Serve as final escalation point (L3/L4) for complex and high-severity incidents.
Define and enforce incident response lifecycle aligned with NIST, ISO 27001, and MITRE ATT&CK.
Ensure adherence to SLA / OLA targets (MTTA, MTTR, containment time).
Conduct executive-level incident briefings and publish detailed RCA reports.
Ensure compliance with organizational security policies and audit requirements.
Oversee case quality assurance and investigation standards.
2. SOC Engineering & Detection Engineering
Own SIEM/SOAR architecture optimization and performance tuning.
Lead log onboarding strategy (cloud, on-prem, hybrid environments).
Ensure proper log normalization, parsing, enrichment, and correlation.
Drive full detection use-case lifecycle:
Threat modelling
Use-case creation
Validation & tuning
Performance measurement
Decommissioning of ineffective rules
Reduce alert fatigue through risk-based alerting, contextual enrichment, and behavioural analytics.
Implement detection-as-code practices with version-controlled rule management.
Ensure high ingestion performance and scalable log retention strategies.
3. Threat Hunting & Advanced Analysis
Establish and lead proactive threat hunting programs.
Map detection coverage against MITRE ATT&CK framework.
Perform advanced investigations including:
Packet capture analysis
Endpoint telemetry analysis
Log correlation across multiple data sources
Integrate threat intelligence feeds and manage IOC lifecycle.
Identify emerging attack patterns and update detection coverage accordingly.
4. Product Engineering & Platform Enhancement Ownership
Act as the primary SOC liaison for Product and Engineering teams.
Translate operational pain points into structured enhancement requirements.
Maintain and prioritize a backlog of platform improvements.
Provide structured feedback on:
Detection gaps
Alert noise
Data ingestion latency
Query performance issues
UX inefficiencies impacting analysts
Participate in sprint planning and architecture discussions and provide inputs for enhancements
Be part of pilot validation of new…