Locations Supported
India - Bengaluru
Relocation available: No
Work pattern:
This role will be on-site
About the Opportunity
Join the Security Operations Center as a Senior SOC Analyst, a critical leadership role responsible for protecting the organization against security threats while mentoring the SOC team and driving operational excellence across 24×7 rotation. You'll be at the intersection of security, operations, and team leadership - monitoring real-time alerts, investigating complex incidents, responding to escalations, supporting infrastructure operations, and guiding SOC analysts to develop their expertise. This role is perfect for someone who thrives in a fast-paced environment, takes ownership of security outcomes, and is passionate about building a high-performing SOC team. You'll have the opportunity to shape processes, mentor the next generation of security analysts, and directly influence how the team scales and matures.
What You Will Do
Monitor real-time security alerts and investigate suspicious network, endpoint, and cloud activity through SIEM queries and threat-analysis tools; identify patterns and systemic detection gaps to improve overall SOC effectiveness.
Identify, declare, document, and escalate security incidents in line with established incident-response playbooks; lead incident investigation for complex or critical cases and mentor junior analysts on investigative techniques.
Analyze and remediate email-based threats including phishing, malware, spoofing attempts, and manage endpoint device security through EDR workflows and MDM policies, serve as the escalation point for complex email/endpoint incidents.
Review and escalate cases from SOC Analysts, provide real-time guidance on incident handling, case-by-case coaching, and mentoring to help analysts develop deeper technical and investigative skills.
Conduct regular knowledge-sharing sessions with the SOC team on threat trends, detection improvements, incident-response techniques, and lessons learned from recent incidents.
Set up and manage shift schedules for SOC Analysts, ensure adequate coverage, address scheduling conflicts, and optimize team workload distribution across 24×7 rotation.
Maintain accurate and timely incident documentation,create and improve runbooks, process documentation, and knowledge base articles to support team efficiency and consistency.
Monitor external attack surface including brand-impersonation activity, fraudulent domain registrations, and social-engineering threats; validate honeytoken decoys and mentor analysts on external threat detection.
Provide regular performance feedback, skill-development recommendations, and progress tracking to SOC Manager; identify training needs, certification opportunities, and career-growth paths for team members.
About You
Must-have experience and skills
Hands-on experience in a Security Operations Center, security monitoring, incident-response, or threat-analysis role, demonstrated ability to triage complex incidents, lead investigations, and mentor junior analysts.
Proven experience investigating advanced-threat scenarios including data-exfiltration indicators, lateral-movement attempts, privilege-escalation activities, credential harvesting, and unauthorized cloud-service access.
Advanced understanding of IT infrastructure concepts including networks (IP, DNS, ports, protocols), endpoints, identity systems (IAM, SSO, MFA), and cloud environments.
Strong leadership and mentoring skills with the ability to guide analysts, provide constructive feedback, explain complex concepts clearly, and help team members improve performance and grow technically.
Excellent communication and documentation discipline, able to write clear incident summaries, shift notes, and runbooks; comfortable presenting metrics and insights to senior leadership.
Proactive problem-solver and analytical thinker with sound judgment about escalation priorities, resource allocation, and systemic process improvements, demonstrates ownership of SOC team outcomes.
Experience managing shift schedules, on-call rotations, or team operations; comfortable with administrative/organizational tasks alongside technical work.
Nice-to-have experience
Bachelor's degree in Cybersecurity, Computer Science, Information Security, or related field.
1+ year of team-lead, shift-lead, or mentoring experience in a security or operations role.
Proficiency with Okta for SSO/authentication workflows, admin console operations, and user access management.
Exposure to advanced tools: Google SecOps, DoControl, Code42, Cloudflare email security, CrowdStrike Falcon, or incident.io.

