{"id":1269764,"url":"https://alion.io/job/sisa-soc-manager","title":"SOC Manager","company":{"id":2144267,"name":"SISA","domain":"sisa.ai","url":"https://alion.io/company/sisa-ai","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Keka","truth_index":{"grade":"B","score":75,"open_postings":8,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-28T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":26000,"max_usd":61000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":415},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AlienVault OTX","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Defense in Depth","optional":false},{"name":"GCP","optional":false},{"name":"HIPAA","optional":false},{"name":"IBM QRadar","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kubernetes","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PCI DSS","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"SOC 2","optional":false},{"name":"Splunk","optional":false}],"status":"live","first_seen_at":"2026-06-24T05:54:45Z","employer_posted_date":"2026-06-24","last_verified_at":"2026-09-28T12:35:34Z","board_verified":true,"closed_at":null,"days_open":96,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":95},"description":"Role Overview\nWe are seeking a highly experienced and technically strong SOC Manager to lead and evolve our Security Operations Center into a mature, engineering-driven, and outcome-focused capability in the AI driven world.\nThis role requires a hybrid leader who can:\nDrive 24x7 SOC operations excellence\nOwn SIEM/SOAR engineering & detection lifecycle\nCollaborate closely with Product & Development teams\nInfluence platform enhancements through operational intelligence\nBuild and mentor high-performing security teams\nHighlight risks and gaps in logging methodologies\nImprove security posture across multi-tenant cloud and on-prem environments\n\nKey Responsibilities\n1. SOC Operations Leadership & Incident Governance\nLead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.\nServe as final escalation point (L3/L4) for complex and high-severity incidents.\nDefine and enforce incident response lifecycle aligned with NIST, ISO 27001, and MITRE ATT&CK.\nEnsure adherence to SLA / OLA targets (MTTA, MTTR, containment time).\nConduct executive-level incident briefings and publish detailed RCA reports.\nEnsure compliance with organizational security policies and audit requirements.\nOversee case quality assurance and investigation standards.\n\n2. SOC Engineering & Detection Engineering\nOwn SIEM/SOAR architecture optimization and performance tuning.\nLead log onboarding strategy (cloud, on-prem, hybrid environments).\nEnsure proper log normalization, parsing, enrichment, and correlation.\nDrive full detection use-case lifecycle:\nThreat modelling\nUse-case creation\nValidation & tuning\nPerformance measurement\nDecommissioning of ineffective rules\nReduce alert fatigue through risk-based alerting, contextual enrichment, and behavioural analytics.\nImplement detection-as-code practices with version-controlled rule management.\nEnsure high ingestion performance and scalable log retention strategies.\n\n3. Threat Hunting & Advanced Analysis\nEstablish and lead proactive threat hunting programs.\nMap detection coverage against MITRE ATT&CK framework.\nPerform advanced investigations including:\nPacket capture analysis\nEndpoint telemetry analysis\nLog correlation across multiple data sources\nIntegrate threat intelligence feeds and manage IOC lifecycle.\nIdentify emerging attack patterns and update detection coverage accordingly.\n\n4. Product Engineering & Platform Enhancement Ownership\nAct as the primary SOC liaison for Product and Engineering teams.\nTranslate operational pain points into structured enhancement requirements.\nMaintain and prioritize a backlog of platform improvements.\nProvide structured feedback on:\nDetection gaps\nAlert noise\nData ingestion latency\nQuery performance issues\nUX inefficiencies impacting analysts\nParticipate in sprint planning and architecture discussions and provide inputs for enhancements\nBe part of pilot validation of new features prior to production release.\nQuantify impact of enhancements (false positive & incident reduction %, MTTR improvement, automation coverage growth).\n\n5. Client Onboarding & Security Architecture Oversight\nLead secure onboarding of customers across:\nAWS / Azure / GCP\nOn-prem data centers\nHybrid architectures\nConduct log gap assessments and telemetry validation.\nAlign detection coverage to client risk profiles.\nParticipate in customer governance calls and QBRs.\nProvide architectural recommendations to improve customer security posture.\n\n6. Team Leadership & Capability Development\nLead, mentor, and manage L1/L2/L3 analysts.\nEstablish skill matrix and structured career progression roadmap.\nConduct periodic case audits and performance reviews.\nDevelop training programs in:\nAdvanced detection engineering\nThreat hunting\nForensics\nAutomation\nDrive hiring, onboarding, and succession planning.\nBuild a high-performance, accountability-driven culture.\n\n7. Metrics, Reporting & Continuous Improvement\nDefine and monitor SOC KPIs:\nMTTA / MTTR\nFalse positive ratio\nDetection accuracy\nAutomation coverage\nIncident recurrence rate & reasoning\nPublish monthly executive dashboards.\nConduct quarterly SOC maturity assessments.\nDrive continuous improvement roadmap aligned with business growth.\n\nMandatory Technical Skills\n10-12 years of cybersecurity experience.\nMinimum 4-5 years in SOC Lead / SOC Manager role.\nStrong hands-on experience in at least one SIEM platform:\nSplunk / Sentinel / QRadar / Elastic / AlienVault / DNIF / McAfee ESM.\nExperience implementing SOAR automation.\nDeep understanding of:\nNetwork security (Firewall, IDS/IPS, WAF)\nEDR/XDR platforms\nCloud security (AWS, Azure)\nIdentity & Access Management\nStrong knowledge of:\nMITRE ATT&CK & Defend\nNIST & NIST IR Framework\nDefense-in-Depth architecture\nExperience with query writing and log analysis on SIEM technologies.\n\nPreferred Technical & Engineering Skills\nScripting (Python / PowerShell / Bash) would be added advantage.\nExposure to DevSecOps environments.\nKnowledge of container and Kubernetes, cloud security.\nData analytics for anomaly detection.\nFamiliarity with compliance frameworks:\nISO 27001\nSOC 2\nPCI-DSS\nHIPAA\n\nCertifications (Preferred)\nCISSP / CISM\nCEH\nCompTIA Security+\nGIAC Certifications (GCIA / GCIH / GCED)\nCloud Security Certifications (AWS / Azure / GCP/ Oracle)\n\nLeadership Competencies\nStrong executive communication and stakeholder management.\nAbility to manage high-pressure incidents.\nStrategic thinking with operational excellence.\nEngineering mindset with product-oriented thinking.\nStrong documentation and governance discipline.\n\nWork Model\nMandatory 5-day work from office (Bangalore or Mumbai).\nOn-call availability during major incidents or IR situations.\n\nSkills\nSecurity Incident Response\nCommunication Skills\nCollaboration\nCybersecurity Strategy\nCertifications Management\nThreat Analysis\nContinuous Learning\nLeadership Team Management\nPolicy Development","description_format":"text","description_chars":5858,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Continuous learning"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response","Artificial Intelligence","Cybersecurity","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-25T23:37:36Z"}],"liveness":{"score":16,"band":"cold","label":"Long shot","p_open":1,"p_active":0.45,"p_room":0.36,"age_days":95,"expected_fill_days":49,"reasons":["conf:8","velocity","win:tail","crowd:"],"computed_at":"2026-09-28T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/sisa-soc-manager","json_url":"https://alion.io/job/sisa-soc-manager.json","meta":{"generated_at":"2026-09-29T03:01:30Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2686,"day_limit":5000,"remaining_today":2314,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}