826,151open jobs
53,202companies
135,845added this week
Browse all
Salary
≈ $38k – $90k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Staff · 10+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 26, 2026. First seen by Alion on Jun 24, 2026.

Overview
Company
Impact
Profile match
SISA delivers cutting-edge AI-powered cybersecurity solutions for enterprises — from threat detection to compliance, safeguard what matters most.

Role Overview

We are seeking a highly experienced and technically strong SOC Manager to lead and evolve our Security Operations Center into a mature, engineering-driven, and outcome-focused capability in the AI driven world.

This role requires a hybrid leader who can:

    • Drive 24x7 SOC operations excellence
    • Own SIEM/SOAR engineering & detection lifecycle
    • Collaborate closely with Product & Development teams
    • Influence platform enhancements through operational intelligence
    • Build and mentor high-performing security teams
    • Highlight risks and gaps in logging methodologies
    • Improve security posture across multi-tenant cloud and on-prem environments

Key Responsibilities

1. SOC Operations Leadership & Incident Governance

    • Lead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.
    • Serve as final escalation point (L3/L4) for complex and high-severity incidents.
    • Define and enforce incident response lifecycle aligned with NIST, ISO 27001, and MITRE ATT&CK.
    • Ensure adherence to SLA / OLA targets (MTTA, MTTR, containment time).
    • Conduct executive-level incident briefings and publish detailed RCA reports.
    • Ensure compliance with organizational security policies and audit requirements.
    • Oversee case quality assurance and investigation standards.

2. SOC Engineering & Detection Engineering

    • Own SIEM/SOAR architecture optimization and performance tuning.
    • Lead log onboarding strategy (cloud, on-prem, hybrid environments).
    • Ensure proper log normalization, parsing, enrichment, and correlation.
    • Drive full detection use-case lifecycle:
    • Threat modelling
    • Use-case creation
    • Validation & tuning
    • Performance measurement
    • Decommissioning of ineffective rules
    • Reduce alert fatigue through risk-based alerting, contextual enrichment, and behavioural analytics.
    • Implement detection-as-code practices with version-controlled rule management.
    • Ensure high ingestion performance and scalable log retention strategies.

3. Threat Hunting & Advanced Analysis

    • Establish and lead proactive threat hunting programs.
    • Map detection coverage against MITRE ATT&CK framework.
    • Perform advanced investigations including:
    • Packet capture analysis
    • Endpoint telemetry analysis
    • Log correlation across multiple data sources
    • Integrate threat intelligence feeds and manage IOC lifecycle.
    • Identify emerging attack patterns and update detection coverage accordingly.

4. Product Engineering & Platform Enhancement Ownership

    • Act as the primary SOC liaison for Product and Engineering teams.
    • Translate operational pain points into structured enhancement requirements.
    • Maintain and prioritize a backlog of platform improvements.
    • Provide structured feedback on:
    • Detection gaps
    • Alert noise
    • Data ingestion latency
    • Query performance issues
    • UX inefficiencies impacting analysts
    • Participate in sprint planning and architecture discussions and provide inputs for enhancements
    • Be part of pilot validation of new features prior to production release.
    • Quantify impact of enhancements (false positive & incident reduction %, MTTR improvement, automation coverage growth).

5. Client Onboarding & Security Architecture Oversight

    • Lead secure onboarding of customers across:
    • AWS / Azure / GCP
    • On-prem data centers
    • Hybrid architectures
    • Conduct log gap assessments and telemetry validation.
    • Align detection coverage to client risk profiles.
    • Participate in customer governance calls and QBRs.
    • Provide architectural recommendations to improve customer security posture.

6. Team Leadership & Capability Development

    • Lead, mentor, and manage L1/L2/L3 analysts.
    • Establish skill matrix and structured career progression roadmap.
    • Conduct periodic case audits and performance reviews.
    • Develop training programs in:
    • Advanced detection engineering
    • Threat hunting
    • Forensics
    • Automation
    • Drive hiring, onboarding, and succession planning.
    • Build a high-performance, accountability-driven culture.

7. Metrics, Reporting & Continuous Improvement

    • Define and monitor SOC KPIs:
    • MTTA / MTTR
    • False positive ratio
    • Detection accuracy
    • Automation coverage
    • Incident recurrence rate & reasoning
    • Publish monthly executive dashboards.
    • Conduct quarterly SOC maturity assessments.
    • Drive continuous improvement roadmap aligned with business growth.

Mandatory Technical Skills

    • 10-12 years of cybersecurity experience.
    • Minimum 4-5 years in SOC Lead / SOC Manager role.
    • Strong hands-on experience in at least one SIEM platform:
    • Splunk / Sentinel / QRadar / Elastic / AlienVault / DNIF / McAfee ESM.
    • Experience implementing SOAR automation.
    • Deep understanding of:
    • Network security (Firewall, IDS/IPS, WAF)
    • EDR/XDR platforms
    • Cloud security (AWS, Azure)
    • Identity & Access Management
    • Strong knowledge of:
    • MITRE ATT&CK & Defend
    • NIST & NIST IR Framework
    • Defense-in-Depth architecture
    • Experience with query writing and log analysis on SIEM technologies.

Preferred Technical & Engineering Skills

    • Scripting (Python / PowerShell / Bash) would be added advantage.
    • Exposure to DevSecOps environments.
    • Knowledge of container and Kubernetes, cloud security.
    • Data analytics for anomaly detection.
    • Familiarity with compliance frameworks:
    • ISO 27001
    • SOC 2
    • PCI-DSS
    • HIPAA

Certifications (Preferred)

    • CISSP / CISM
    • CEH
    • CompTIA Security+
    • GIAC Certifications (GCIA / GCIH / GCED)
    • Cloud Security Certifications (AWS / Azure / GCP/ Oracle)

Leadership Competencies

    • Strong executive communication and stakeholder management.
    • Ability to manage high-pressure incidents.
    • Strategic thinking with operational excellence.
    • Engineering mindset with product-oriented thinking.
    • Strong documentation and governance discipline.

Work Model

    • Mandatory 5-day work from office (Bangalore or Mumbai).
    • On-call availability during major incidents or IR situations.

Skills

  • Security Incident Response
  • Communication Skills
  • Collaboration
  • Cybersecurity Strategy
  • Certifications Management
  • Threat Analysis
  • Continuous Learning
  • Leadership Team Management
  • Policy Development
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
826,151 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Bengaluru
≈ $30k – $67k per year (Estimated) • In office • 6+ years exp • Pune
DevOps
RTOS
Linux
TCP/IP
Cybersecurity
PKI
Apply
≈ $34k – $87k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
AI/ML
LLM
LLM Guardrails
NIST AI RMF
DevOps
GCP
Azure
CI/CD
AWS
Shift-Left
Cybersecurity
OWASP Top 10
PCI DSS
Shift-Left Security
Threat Modeling
OWASP
Apply
≈ $34k – $80k per year (Estimated) • In office • Full-Time • 8+ years exp • Hyderabad
DevOps
GCP
Azure
CI/CD
AWS
Kubernetes
Platform Engineering
Shift-Left
Cybersecurity
ISO 27001
HIPAA
Shift-Left Security
Apply
≈ $34k – $77k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Noida
Python
Perl
Chips/EDA
Synopsys Design Compiler
Synopsys Fusion Compiler
Synopsys SpyGlass
Formal Verification
Apply
≈ $33k – $75k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Bengaluru
DevOps
Incident Management
Apply
$45k – $78k per year • In office • South Korea
Python
JavaScript
TypeScript
SQL
Node JS
Node JS
Fastify
Prisma
Databases
Databricks
AI/ML
Claude Code
dbt
Frontend
Next.js
React.js
Mobile
React Native
DevOps
Terraform
GCP
GitHub Actions
AWS CDK
Azure
CI/CD
AWS
GitHub
Design
Figma
Management
Slack
Confluence
Jira
Apply
$117k – $177k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Washington
Python
Java
AI/ML
Copilot
Cursor
Claude Code
Prompt Engineering
AI Agents
LLM
OpenAI Codex
Agentforce
DevOps
Rest API
gRPC
Terraform
Helm
AWS
Docker
Kubernetes
IAM
Cybersecurity
HashiCorp Vault
Open Policy Agent
OWASP Top 10
SOC 2
Least Privilege
Cryptography
Vault
Apply
$80k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Seattle
Python
AI/ML
AI Agents
Machine Learning
Robotics
MuJoCo
Design
Blender
Apply
$72k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Seattle
DevOps
GCP
Apply
Data Analyst 1 day ago
≈ $27k – $74k per year (Estimated) • In office • South Korea
Python
SQL
Analytics
Looker
Apply
$13k – $19k per year • In office • Full-Time • 5+ years exp • Mumbai
DevOps
IAM
Cybersecurity
ISO 27001
NIST CSF
SOC 2
FedRAMP
Apply
$26k – $37k per year • In office • Full-Time • 8+ years exp • Bengaluru
DevOps
IAM
Cybersecurity
ISO 27001
PCI DSS
SOC 2
SIEM
DLP
Apply
Digital Forensic Lead 4 months ago
$42k – $47k per year • In office • Full-Time • Bachelor's Degree • Bengaluru
Python
Bash
DevOps
Linux
Windows
Cybersecurity
Autopsy
FTK
EnCase
X-Ways Forensics
Apply
$21k – $26k per year • In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru
Python
PowerShell
Cybersecurity
MITRE ATT&CK
IBM QRadar
SIEM
Apply
SOC L2- Qradar 5 months ago
$10k – $19k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Bengaluru
Python
PowerShell
Cybersecurity
MITRE ATT&CK
STIX
TAXII
IBM QRadar
SIEM
Apply
≈ $28k – $79k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru
DevOps
Azure
AWS
Cloudflare
SLI/SLO/SLA
DNS
DHCP
VPN
BGP
OSPF
Cybersecurity
Zero Trust
Management
ITIL
Apply
In office • Full-Time • Bengaluru
Databases
SAP HANA
Management
ITIL
Apply
≈ $30k – $80k per year (Estimated) • In office • Bengaluru
Apply
≈ $26k – $58k per year (Estimated) • In office • 7+ years exp • Master's Degree • Bengaluru
Apply
≈ $51k – $105k per year (Estimated) • In office • 12+ years exp • Master's Degree • Bengaluru
Databases
Snowflake
Databricks
AI/ML
AI Agents
DevOps
Terraform
Azure
CI/CD
AWS
Analytics
Informatica
Apply
See all jobs
This is one of many
826,151 more open roles from verified company boards, updated every day.