{"id":1250058,"url":"https://alion.io/job/good-co-security-operations-lead","title":"Security Operations Lead","company":{"id":3801248,"name":"Good Co","domain":"goodco.co.in","url":"https://alion.io/company/good-co-2","size_band":null,"is_staffing_agency":true,"employer_type":"agency","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":23000,"max_usd":56000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":9},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"GDPR","optional":false},{"name":"IAM","optional":false},{"name":"IBM QRadar","optional":false},{"name":"Incident Management","optional":false},{"name":"ISO 27001","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"NIST CSF","optional":false},{"name":"PCI DSS","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false}],"status":"live","first_seen_at":"2026-08-04T12:05:43Z","employer_posted_date":null,"last_verified_at":"2026-08-04T12:05:43Z","board_verified":false,"closed_at":null,"days_open":59,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":59},"description":"Roles & Responsibilities:\n\n- Lead and manage the Security Operations Center (SOC) function, ensuring 24x7 monitoring, detection, investigation, and response to cybersecurity incidents.\n\n- Own the operational security posture by managing threat detection, incident response, vulnerability management, and security monitoring processes.\n\n- Develop and maintain SOC processes, playbooks, escalation procedures, and incident response workflows aligned with industry standards.\n\n- Lead a team of security analysts, engineers, and incident responders; provide mentoring, coaching, and performance management.\n\n- Monitor and analyze security alerts from SIEM, EDR, IDS/IPS, firewalls, cloud security platforms, and other security tools.\n\n- Drive incident investigations, root cause analysis, containment, remediation, and post-incident reviews.\n\n- Manage threat intelligence operations, including identifying emerging threats, indicators of compromise (IOCs), and attack patterns.\n\n- Improve SOC maturity through automation, SOAR implementation, process optimization, and operational metrics.\n\n- Define and track SOC KPIs/KRIs, including incident response time, detection effectiveness, false positives, and threat trends.\n\n- Collaborate with infrastructure, cloud, application, and compliance teams to strengthen security controls.\n\n- Support security audits, regulatory compliance requirements, and risk assessments.\n\n- Ensure alignment with cybersecurity frameworks such as ISO 27001, NIST CSF, MITRE ATT&CK, and industry best practices.\n\n- Coordinate with external vendors, managed security service providers (MSSPs), and incident response partners when required.\n\n- Prepare executive-level security reports, dashboards, and risk updates for senior management.\n\nPreferred Candidate Profile:\n\n- Experience: 815 years of experience in cybersecurity, with significant experience leading SOC operations, incident response, or security monitoring teams.\n\n- Proven experience managing a SOC team in an enterprise environment, preferably in UAE/GCC markets.\n\n- Strong hands-on experience with SIEM platforms (Splunk, Sentinel, QRadar), EDR/XDR solutions, threat intelligence, vulnerability management, and cloud security monitoring.\n\n- Strong understanding of security incident lifecycle, threat hunting, malware analysis, network security, IAM, and security architecture.\n\n- Experience developing SOC processes, operational procedures, and automation workflows.\n\n- Ability to lead investigations involving APTs, phishing, ransomware, and insider threats.\n\n- Strong stakeholder management skills with the ability to communicate security risks to technical and business leadership.\n\n- Experience working with compliance and regulatory requirements such as ISO 27001, NIST, PCI-DSS, GDPR, or UAE regulatory frameworks.\n\nPreferred Certifications:\n\n- CISSP, CISM, GIAC certifications (GCIH, GCIA, GCFA), OSCP/OSCE, CCSP, or ISO 27001 Lead Auditor.\n\nSkills\nCyber Security, IT Incident Management, IT Risk Management, Information Security, IT Audit","description_format":"text","description_chars":3032,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-25T18:00:00Z"}],"liveness":{"score":5,"band":"cold","label":"Long shot","p_open":0.4,"p_active":0.332,"p_room":0.35,"age_days":58,"expected_fill_days":24,"reasons":["seen:58","agency","velocity","win:tail"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/good-co-security-operations-lead","json_url":"https://alion.io/job/good-co-security-operations-lead.json","meta":{"generated_at":"2026-10-03T03:57:55Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3966,"day_limit":5000,"remaining_today":1034,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}