freehire launches on Product Hunt on 26 August.

Follow →

Cybersecurity – SOC Lead (AI & Automation)

Summary

Lead offshore SOC team, drive AI/automation in security operations, ensure case quality and stakeholder alignment.

Position: Cybersecurity – SOC Lead (AI & Automation)
Location: Chennai - Onsite/Hybrid/Remote
Shift Timing: 5.30PM - 2.30AM IST (US Eastern Time)
Engagement Type: Full Time

Role Summary:
Lead offshore SOC execution for Customer, combining operational leadership, detection governance, case quality oversight, and practical automation. This role must drive disciplined day-to-day performance while improving the use of built-in AI / automation features across the CLW security stack without sacrificing analyst judgement, traceability, or investigation fidelity.

Key Responsibilities:
  • Lead the offshore SOC pod across L1 and L2 activities, ensure queue health, review investigation quality, and maintain strong stakeholder alignment with Customer security leadership.
  • Own daily operational governance including case quality, severity calibration, shift handoffs, SLA adherence, and escalation discipline for major incidents.
  • Drive continuous improvement in Splunk ES / Mission Control operations, detection logic review, alert noise reduction, and visibility gap identification.
  • Coordinate across CrowdStrike, Proofpoint, Qualys, Palo Alto, Dragos, ServiceNow, and automation workflows to improve response effectiveness.
  • Translate technical events into concise business risk language for U.S. stakeholders and support weekly service reviews, KPI reporting, and corrective action tracking.
  • Promote responsible use of AI-assisted summarization, enrichment, and workflow acceleration within approved guardrails.

Tool Environment:
Splunk ES / Mission Control, CrowdStrike, Qualys, Proofpoint, Palo Alto, Dragos, ServiceNow, Teams, M365 / Entra context, automation / SOAR capabilities where approved.

Required Experience & Skills:
  • Strong security operations leadership experience, including direct management of analysts or provider teams in a 24x7 or follow-the-sun model.
  • Advanced proficiency in Splunk-based SOC operations and solid working knowledge of endpoint, network, email, and vulnerability telemetry.
  • Ability to coach analysts, review investigations, and enforce consistent case quality and operational rigor.
  • Strong executive-facing communication and ability to run governance reviews with facts, metrics, and remediation actions.
  • Experience working with offshore teams serving U.S.-based stakeholders.

Preferred Qualifications:
  • Manufacturing / OT security exposure, especially where corporate-to-plant visibility and escalation discipline matter.
  • Experience with ServiceNow workflows, playbook optimization, and approved automation / SOAR patterns.
  • Awareness of MITRE ATT&CK-aligned detection engineering and risk-based incident prioritization.

Offshore India Operating Model:
  • Work as an embedded offshore team member supporting U.S.-based stakeholders with dependable daily communication, disciplined documentation, and clear ownership of actions and follow-ups.
  • Operate with strong handoff hygiene across shifts, including concise status updates, ticket notes, evidence capture, and risk-based escalation to Customer leads.
  • Support a manufacturing-aware operating model where uptime, safety, OT change sensitivity, and controlled execution are treated as essential requirements.
  • Use ServiceNow and Microsoft Teams effectively for workflow coordination, incident tracking, approvals, and stakeholder communication.
  • Be prepared to align with late afternoon / evening IST overlap with U.S. Eastern time and participate in critical incident bridges when required.

Success Measures:
  • Stable, measurable SOC operations with better case quality, tighter escalation hygiene, and improved visibility coverage.
  • Documented reduction in alert noise and stronger detection fidelity across the CLW stack.
  • Clear governance cadence and dependable offshore team performance.


See also