SOC Lead
HCLTech
5 - 10 years
Noida, Agra
Posted: 01/07/2026
Job Description
Hiring: Sr Subject Matter Expert (Support & Ops) SOC Lead
Location: Noida, India
About the Role
We are looking for an experienced SOC Lead (L3) to drive advanced security operations, lead major incident handling, and strengthen our cybersecurity posture. This is a high-impact role involving threat detection, investigation, and response across enterprise environments.
Key Responsibilities:
Major Incident Management
- Act as Incident Commander for P1/P2 incidents
- Lead war rooms and coordinate with cross-functional teams
- Drive resolution with clear stakeholder communication (including CISO-level)
Incident Response & Investigation
- Conduct end-to-end investigations across endpoint, identity, email, and cloud
- Perform deep analysis using Microsoft Sentinel & Defender XDR
- Execute containment, eradication, and recovery actions
RCA & Continuous Improvement
- Perform detailed Root Cause Analysis (RCA)
- Identify control gaps and implement preventive measures
- Prepare executive and technical reports
SIEM & Threat Hunting
- Fine-tune detection use cases in Microsoft Sentinel
- Perform proactive threat hunting using KQL
- Map threats using MITRE ATT&CK framework
Leadership & Mentorship
- Guide L1/L2 analysts and enhance SOC capabilities
- Conduct training sessions and knowledge sharing
Process & Compliance
- Develop SOPs, playbooks, and runbooks
- Support audits and drive SOC maturity
Required Skills
- Strong expertise in Microsoft Sentinel & Defender XDR
- Advanced KQL (Kusto Query Language) skills
- Experience with EDR tools & incident response platforms
- Knowledge of Windows, AD/Azure AD, email security, and network security
- Familiarity with MITRE ATT&CK framework
Experience & Qualifications
- 5+ years in SOC operations / cybersecurity incident response
- Bachelors degree in relevant field
- Certifications like CISSP / CISM / CEH / Microsoft Security Ops (preferred)
What We Look For
- Strong analytical and problem-solving skills
- Excellent communication (technical & executive level)
- Ability to handle high-pressure incident scenarios
- Strong stakeholder management
Nice to Have
- Cloud security experience (Azure/AWS/GCP)
- Exposure to compliance frameworks (ISO, GDPR)
- Experience with SOC automation/orchestration
Why Join Us?
- Work on global-scale cybersecurity operations
- Access to certifications & learning programs
- Opportunities to grow into leadership roles
- Work with cutting-edge tools and technologies
Interested? Share your profile or connect directly!
Services you might be interested in
We Search & Apply Jobs for You!
Our team scans through 1000s of opportunities and applies to roles best suited to your profile
Save 100+ hours and focus on what matters - cracking interviews and landing offers.
