Login Sign Up

SOC Lead

HCLTech

5 - 10 years

Noida, Agra

Posted: 01/07/2026

Job Description

Hiring: Sr Subject Matter Expert (Support & Ops) SOC Lead

Location: Noida, India


About the Role

We are looking for an experienced SOC Lead (L3) to drive advanced security operations, lead major incident handling, and strengthen our cybersecurity posture. This is a high-impact role involving threat detection, investigation, and response across enterprise environments.


Key Responsibilities:


Major Incident Management

  • Act as Incident Commander for P1/P2 incidents
  • Lead war rooms and coordinate with cross-functional teams
  • Drive resolution with clear stakeholder communication (including CISO-level)

Incident Response & Investigation

  • Conduct end-to-end investigations across endpoint, identity, email, and cloud
  • Perform deep analysis using Microsoft Sentinel & Defender XDR
  • Execute containment, eradication, and recovery actions

RCA & Continuous Improvement

  • Perform detailed Root Cause Analysis (RCA)
  • Identify control gaps and implement preventive measures
  • Prepare executive and technical reports

SIEM & Threat Hunting

  • Fine-tune detection use cases in Microsoft Sentinel
  • Perform proactive threat hunting using KQL
  • Map threats using MITRE ATT&CK framework

Leadership & Mentorship

  • Guide L1/L2 analysts and enhance SOC capabilities
  • Conduct training sessions and knowledge sharing

Process & Compliance

  • Develop SOPs, playbooks, and runbooks
  • Support audits and drive SOC maturity

Required Skills

  • Strong expertise in Microsoft Sentinel & Defender XDR
  • Advanced KQL (Kusto Query Language) skills
  • Experience with EDR tools & incident response platforms
  • Knowledge of Windows, AD/Azure AD, email security, and network security
  • Familiarity with MITRE ATT&CK framework


Experience & Qualifications

  • 5+ years in SOC operations / cybersecurity incident response
  • Bachelors degree in relevant field
  • Certifications like CISSP / CISM / CEH / Microsoft Security Ops (preferred)


What We Look For

  • Strong analytical and problem-solving skills
  • Excellent communication (technical & executive level)
  • Ability to handle high-pressure incident scenarios
  • Strong stakeholder management


Nice to Have

  • Cloud security experience (Azure/AWS/GCP)
  • Exposure to compliance frameworks (ISO, GDPR)
  • Experience with SOC automation/orchestration


Why Join Us?

  • Work on global-scale cybersecurity operations
  • Access to certifications & learning programs
  • Opportunities to grow into leadership roles
  • Work with cutting-edge tools and technologies


Interested? Share your profile or connect directly!


Services you might be interested in

We Search & Apply Jobs for You!

Our team scans through 1000s of opportunities and applies to roles best suited to your profile

Save 100+ hours and focus on what matters - cracking interviews and landing offers.