{"id":1280277,"url":"https://alion.io/job/sisainfosec-soc-manager","title":"SOC Manager","company":{"id":2278839,"name":"Sisainfosec","domain":"sisainfosec.com","url":"https://alion.io/company/sisainfosec","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":null,"truth_index":null},"role":"Security","role_family":"Security","seniority":"staff","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Bengaluru, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":25000,"max_usd":59000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":415},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AlienVault OTX","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Defense in Depth","optional":false},{"name":"GCP","optional":false},{"name":"HIPAA","optional":false},{"name":"IBM QRadar","optional":false},{"name":"ISO 27001","optional":false},{"name":"Kubernetes","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PCI DSS","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"SOC 2","optional":false},{"name":"Splunk","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-08-19T11:42:31Z","employer_posted_date":null,"last_verified_at":"2026-08-19T11:42:31Z","board_verified":false,"closed_at":null,"days_open":45,"trust":{"level":"not_scored","repost_count":null,"flags":[],"days_open":45},"description":"Role Overview :\n\nWe are seeking a highly experienced and technically strong SOC Manager to lead and evolve our Security Operations Center into a mature, engineering-driven, and outcome-focused capability in the AI driven world.\n\nThis Role Requires a Hybrid Leader Who Can :\n\n- Drive 24x7 SOC operations excellence.\n\n- Own SIEM/SOAR engineering & detection lifecycle.\n\n- Collaborate closely with Product & Development teams.\n\n- Influence platform enhancements through operational intelligence.\n\n- Build and mentor high-performing security teams.\n\n- Highlight risks and gaps in logging methodologies.\n\n- Improve security posture across multi-tenant cloud and on-prem environments.\n\nKey Responsibilities : \n\nSOC Operations Leadership & Incident Governance :\n\n- Lead 24x7 SOC operations including detection, triage, escalation, containment, and recovery.\n\n- Serve as final escalation point (L3/L4) for complex and high-severity incidents.\n\n- Define and enforce incident response lifecycle aligned with NIST, ISO 27001, and MITRE ATT&CK.\n\n- Ensure adherence to SLA / OLA targets (MTTA, MTTR, containment time).\n\n- Conduct executive-level incident briefings and publish detailed RCA reports.\n\n- Ensure compliance with organizational security policies and audit requirements.\n\n- Oversee case quality assurance and investigation standards.\n\nSOC Engineering & Detection Engineering :\n\n- Own SIEM/SOAR architecture optimization and performance tuning.\n\n- Lead log onboarding strategy (cloud, on-prem, hybrid environments).\n\n- Ensure proper log normalization, parsing, enrichment, and correlation.\n\n- Drive full detection use-case lifecycle :\n\n1. Threat modelling.\n\n2. Use-case creation.\n\n3. Validation & tuning.\n\n4. Performance measurement.\n\n5. Decommissioning of ineffective rules.\n\n- Reduce alert fatigue through risk-based alerting, contextual enrichment, and behavioural analytics.\n\n- Implement detection-as-code practices with version-controlled rule management.\n\n- Ensure high ingestion performance and scalable log retention strategies.\n\nThreat Hunting & Advanced Analysis :\n\n- Establish and lead proactive threat hunting programs.\n\n- Map detection coverage against MITRE ATT&CK framework.\n\n- Perform advanced investigations including:\n\n1. Packet capture analysis.\n\n2. Endpoint telemetry analysis.\n\n3. Log correlation across multiple data sources.\n\n- Integrate threat intelligence feeds and manage IOC lifecycle.\n\n- Identify emerging attack patterns and update detection coverage accordingly.\n\nProduct Engineering & Platform Enhancement Ownership :\n\n- Act as the primary SOC liaison for Product and Engineering teams.\n\n- Translate operational pain points into structured enhancement requirements.\n\n- Maintain and prioritize a backlog of platform improvements.\n\n- Provide structured feedback on:\n\n1. Detection gaps.\n\n2. Alert noise.\n\n3. Data ingestion latency.\n\n4. Query performance issues.\n\n5. UX inefficiencies impacting analysts.\n\n- Participate in sprint planning and architecture discussions and provide inputs for enhancements.\n\n- Be part of pilot validation of new features prior to production release.\n\n- Quantify impact of enhancements (false positive & incident reduction %, MTTR improvement, automation coverage growth).\n\nClient Onboarding & Security Architecture Oversight :\n\n- Lead secure onboarding of customers across:\n\n1. AWS / Azure / GCP.\n\n2. On-prem data centers.\n\n3. Hybrid architectures.\n\n- Conduct log gap assessments and telemetry validation.\n\n- Align detection coverage to client risk profiles.\n\n- Participate in customer governance calls and QBRs.\n\n- Provide architectural recommendations to improve customer security posture.\n\nTeam Leadership & Capability Development :\n\n- Lead, mentor, and manage L1/L2/L3 analysts.\n\n- Establish skill matrix and structured career progression roadmap.\n\n- Conduct periodic case audits and performance reviews.\n\n- Develop training programs in:\n\n1. Advanced detection engineering.\n\n2. Threat hunting.\n\n3. Forensics.\n\n4. Automation.\n\n- Drive hiring, onboarding, and succession planning.\n\n- Build a high-performance, accountability-driven culture.\n\nMetrics, Reporting & Continuous Improvement :\n\n- Define and monitor SOC KPIs:\n\n1. MTTA / MTTR.\n\n2. False positive ratio.\n\n3. Detection accuracy.\n\n4. Automation coverage.\n\n5. Incident recurrence rate & reasoning.\n\n- Publish monthly executive dashboards.\n\n- Conduct quarterly SOC maturity assessments.\n\n- Drive continuous improvement roadmap aligned with business growth.\n\nMandatory Technical Skills :\n\n- 10-12 years of cybersecurity experience.\n\n- Minimum 4 - 5 years in SOC Lead / SOC Manager role.\n\n- Strong hands-on experience in at least one SIEM platform:\n\n1. Splunk / Sentinel / QRadar / Elastic / AlienVault / DNIF / McAfee ESM.\n\n- Experience implementing SOAR automation.\n\n- Deep understanding of:\n\n1. Network security (Firewall, IDS/IPS, WAF).\n\n2. EDR/XDR platforms.\n\n3. Cloud security (AWS, Azure).\n\n4. Identity & Access Management.\n\n- Strong knowledge of :\n\n1. MITRE ATT&CK & Defend.\n\n2. NIST & NIST IR Framework.\n\n3. Defense-in-Depth architecture.\n\n- Experience with query writing and log analysis on SIEM technologies.\n\nPreferred Technical & Engineering Skills :\n\n- Scripting (Python / PowerShell / Bash) would be added advantage.\n\n- Exposure to DevSecOps environments.\n\n- Knowledge of container and Kubernetes, cloud security.\n\n- Data analytics for anomaly detection.\n\n- Familiarity with compliance frameworks :\n\n1. ISO 27001.\n\n2. SOC 2.\n\n3. PCI-DSS.\n\n4. HIPAA.\n\nCertifications (Preferred) :\n\n- CISSP / CISM.\n\n- CEH.\n\n- CompTIA Security+.\n\n- GIAC Certifications (GCIA / GCIH / GCED).\n\n- Cloud Security Certifications (AWS / Azure / GCP/ Oracle).\n\nLeadership Competencies :\n\n- Strong executive communication and stakeholder management.\n\n- Ability to manage high-pressure incidents.\n\n- Strategic thinking with operational excellence.\n\n- Engineering mindset with product-oriented thinking.\n\n- Strong documentation and governance discipline.\n\nWork Model :\n\n- Mandatory 5-day work from office (Bangalore or Mumbai).\n\n- On-call availability during major incidents or IR situations.\n\nSkills :\n\n- Security Incident Response.\n\n- Communication Skills.\n\n- Collaboration.\n\n- Cybersecurity Strategy.\n\n- Certifications Management.\n\n- Threat Analysis.\n\n- Continuous Learning.\n\n- Leadership Team Management.\n\n- Policy Development.\nSkills\nCyber Security, Security Operations Center, SIEM, SOAR, Information Security, Threat Modeling, Cloud Security, Security Architect","description_format":"text","description_chars":6463,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Continuous learning"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-26T02:00:24Z"}],"visa":[],"liveness":{"score":21,"band":"cold","label":"Long shot","p_open":0.6,"p_active":0.644,"p_room":0.55,"age_days":44,"expected_fill_days":30,"reasons":["seen:44","velocity","win:tail"],"computed_at":"2026-10-03T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/sisainfosec-soc-manager","json_url":"https://alion.io/job/sisainfosec-soc-manager.json","meta":{"generated_at":"2026-10-04T02:31:22Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3621,"day_limit":5000,"remaining_today":1379,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}