The Security Operations - IR Lead will be responsible for detecting and responding to cyber security threats, partnering with global SOC teams, and acting as a liaison with stakeholders. Key duties include monitoring security systems, conducting in-depth incident investigations, developing response plans, and coordinating mitigation efforts. The role also involves documenting incidents, mentoring junior staff, staying current with threats, and driving tabletop exercises to enhance readiness. Proactive threat hunting, security system upgrades, and risk remediation are also crucial, along with generating security reports and ensuring compliance with standards.
Good To Have:- People Management experience.
Must Have:- Detect and respond to cyber security threats.
- Partner with internal SOC team and keep CISO informed.
- Monitor security systems and networks for breaches.
- Conduct in-depth investigations into security incidents.
- Develop and implement incident response plans.
- Coordinate with cross-functional teams for incident mitigation.
- Document incident response activities.
- Stay current with emerging cybersecurity threats and vulnerabilities.
- Define and Drive tabletop exercises.
- Perform proactive threat hunts.
- Upgrade security systems and remediate risks.
- 6-10 years experience in security incident response, vulnerability management, or penetration testing.
- Practical experience with threat detection, monitoring, and incident response implementation.
- Ability to query and write detection rules.
- Experience with SIEM (Qradar/Splunk), SOAR, WAF, AV, Firewalls.
- Experience conducting technical analysis of security events including Malware analysis and digital forensics.
- Excellent analytical and problem-solving skills.
- Effective communication skills.
- Bachelor’s degree in information security or related fields.
- Experience in public cloud infrastructure (Azure, GCP, AWS).
- Familiarity with security frameworks (NIST, ISO 27001/2).
- Proven experience with vulnerability management products (Tenable, Qualys, Nexpose).
- Demonstrated understanding of information security concepts (firewalls, intrusion prevention, TCP/IP, log management).