Project Role : Security Architect
Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.
Must have skills : Security Breach Response Operations
Good to have skills : NA
Minimum 12 year(s) of experience is required
Educational Qualification : 15 years full time education
Summary:
We are seeking a skilled Security Incident and Response Operations Manager to join our Cybersecurity team. The ideal candidate will be responsible for monitoring, investigating, containing, and responding to cybersecurity incidents and security breaches. This role requires strong analytical skills, knowledge of security operations, and the ability to work in a fast-paced, 24x7 environment to protect organizational assets and ensure business continuity.
Security Incident and Response Operations Manager
Roles & Responsibilities:
Monitor security alerts and incidents using SIEM and security monitoring tools.
Investigate, analyze, and respond to cybersecurity incidents, including malware, phishing, ransomware, insider threats, and unauthorized access attempts.
Perform incident triage, containment, eradication, and recovery activities.
Conduct root cause analysis and document findings with recommendations for remediation.
Coordinate with IT, Infrastructure, Network, Cloud, and Application teams during security incidents.
Build and strengthen client relationships, act as a trusted advisor, and support business growth opportunities.
Manage SOC team of L1/L2/L3 and platform engineering
Manage multiple SOC delivery and clients
Perform threat hunting and identify indicators of compromise (IOCs).
Manage incident response activities in accordance with established playbooks and security policies.
Support digital forensic investigations and evidence collection when required.
Develop and maintain incident response documentation, runbooks, and standard operating procedures.
Ensure timely escalation of critical security incidents to relevant stakeholders.
Participate in post-incident reviews and recommend preventive security improvements.
Support security audits and compliance initiatives.
Professional & Technical Skills:
Strong understanding of Incident Response (IR) lifecycle and Cybersecurity Operations.
Experience with SIEM platforms such as Microsoft Sentinel, Splunk, IBM QRadar, ArcSight, or Google Chronicle.
excellent client-facing, stakeholder management, communication, and consulting skills.
Ability to work from client office 5 days a week and manage client-facing engagements
Knowledge of Endpoint Detection and Response (EDR) tools such as Microsoft Defender, CrowdStrike Falcon, SentinelOne, or Carbon Black.
Understanding of network security, TCP/IP, DNS, VPN, firewalls, IDS/IPS, and proxy technologies.
Knowledge of malware analysis, phishing investigations, and threat intelligence.
Familiarity with MITRE ATT&CK Framework, Cyber Kill Chain, and NIST Incident Response Framework.
Experience with Windows, Linux, Active Directory, Microsoft 365, and cloud environments (Azure, AWS, or GCP).
Basic scripting knowledge (PowerShell, Python, or Bash) is preferred.
Strong analytical, troubleshooting, and communication skills.
Preferred Qualifications
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field.
Relevant certifications such as:
o CompTIA Security+
o GIAC Certified Incident Handler (GCIH)
o Certified Ethical Hacker (CEH)
o CISSP
o Microsoft Certified: Security Operations Analyst
o Splunk Core Certified Power User (preferred)
Experience
10- 12+ years of experience in Security Operations Center (SOC), Incident Response, Cybersecurity Operations, or Threat Detection.
Good to Have
Experience with SOAR platforms and security automation.
Knowledge of cloud security monitoring.
Experience with vulnerability management tools.
Understanding of threat intelligence platforms and IOC management.
Knowledge of compliance standards such as ISO 27001, NIST, PCI DSS, SOC 2, and GDPR.
Willingness to work in a 24x7 rotational support environment.
Additional Information:
The candidate should have minimum 12 years of experience in Security Breach Response Operations.
This position is based at our Mumbai (Client Onsite)
A 15 years full time education is required.
15 years full time education