Manager, Security Analytics & Operations - SOC lead
On-siteHyderabad, Telangana, India
Job Summary
Manage real-time SOC operations during assigned shifts by monitoring alerts, assigning incidents, and maintaining situational awareness. Serve as the primary escalation point for complex events, acting as Incident Commander to coordinate containment strategies and communicate status updates. Ensure quality control by reviewing incident reports for accuracy and compliance with internal policies and regulatory standards. Conduct shift handovers to ensure seamless transitions of active investigations. Mentor analysts through on-the-job training and debriefs to improve skills and knowledge sharing. Track performance metrics to identify bottlenecks and provide regular updates to leadership. Optimize SOC processes and documentation by identifying inefficiencies and implementing new tools or workflows. Coordinate with IT teams to ensure monitoring systems and data feeds remain functional. Support regulatory compliance by organizing routine drills and simulations to prepare the team for various cyber scenarios.
Required Qualifications
- 5+ years of experience in cybersecurity operations or incident response
- at least 2–3 years in a senior SOC analyst or similar role
- demonstrated ability to handle high-severity incidents and lead others
- Prior experience in a team lead, technical lead, or supervisory capacity
- Advanced hands-on experience with SOC tools and processes
- expertise in using SIEM and EDR tools for analysis
- understanding of SOAR (Security Orchestration, Automation, and Response) platforms for workflow automation
- In-depth familiarity with incident response procedures (containment, eradication, recovery) as formalized in frameworks like NIST or SANS
- Able to step in and perform any analyst task (from triage to deep forensic analysis) if needed
- Proven track record of coordinating team activities or leading small teams during critical operations
- experience as a senior analyst who has taken charge during incidents or mentored junior staff
- Strong organizational skills to manage 24/7 shift scheduling and ensure coverage
- Excellent communication and interpersonal skills
- Capable of effectively communicating with technical team members
- translating technical issues into actionable information for managers
- Ability to provide clear guidance under pressure is essential for managing live security incidents
- Recognized credentials demonstrating both technical depth and leadership potential
- advanced technical certs like SANS GCIA, GCIH (or similar) to validate incident handling expertise
- broad security management or professional certifications such as CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) to indicate knowledge of governance and leadership in security operations
Desired Qualifications
- Experience in a team lead, technical lead, or supervisory capacity
- Exposure to IAM domains such as identity governance and administration, access request and approval, access certifications, role management, privileged access management, single sign-on, multifactor authentication, or directory services
- Scrum Master, Agile, project management, business analysis, or process improvement certification or equivalent practical experience
- Experience supporting regulated environments, audit response, control documentation, risk remediation, or compliance-driven technology initiatives
- Ability to build structured templates, dashboards, operating procedures, and reporting routines that improve transparency and repeatability
- Experience identifying repeatable work patterns and partnering with technology teams to automate tracking, reporting, intake, follow-up, evidence collection, or other recurring IAM program management activities
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.