Apply Edge Start your job search

SOC Team Lead – Managed Security Services

SOCROOM · Bengaluru, Karnataka, India

Apply & track with Apply Edge

Company Description SOCRoom by Procain consulting, helps businesses strengthen security operations with continuous monitoring, faster response, and expert SOC support. We work with organisations that need better visibility, alert handling, incident response, and security operations coverage without building a full SOC in-house. Our services include Managed SOC, SOC as a Service, SOC Staff Augmentation, Cloud Security Monitoring, threat detection, alert triage, and incident response support. Built on the principle of Detect. Prevent. Prevail., SOCRoom by Procain consulting, helps teams move from security alerts to real action - faster, sharper, and with greater operational confidence.Key responsibilitiesTeam leadership and shift operationsLead, mentor and schedule a team of L1/L2 analysts to maintain 24x7 coverage and consistent service quality.Own shift handovers, ensuring every open incident transfers with current status, next action and owner.Conduct quality reviews of closed incidents, verifying verdicts (true positive, benign positive, false positive) and documentation.Coach analysts on investigation methodology, KQL and tooling; drive onboarding and structured skills development.Incident detection and responseAct as the escalation point for high-severity incidents, including lateral movement, privileged account compromise and data exfiltration.Direct investigations from initial alert through entity analysis, timeline reconstruction, containment and closure.Coordinate containment actions with customer IT and security teams, and with L3 / incident response specialists where needed.Lead post-incident reviews and translate lessons learned into detection and process improvements.Microsoft Sentinel platform ownershipOversee analytics rule lifecycle: design, testing, tuning, alert grouping, suppression and retirement of noisy rules.Develop and review KQL queries, hunting queries, workbooks and watchlists.Guide automation using playbooks (Logic Apps) and automation rules to reduce manual triage effort.Work with engineering teams on data connector onboarding, log source health and ingestion cost optimization.Wazuh operations (where deployed)Supervise monitoring of Wazuh-managed customer environments, including agent health, rule and decoder tuning, and alert triage.Support integration of Wazuh alerts into central SOC workflows and ticketing.Customer engagement and reportingServe as a technical point of contact for customers during incidents and in regular service reviews.Produce monthly SOC reports covering incident trends, SLA performance, detection coverage and recommendations.Ensure adherence to contractual SLAs for time-to-triage, time-to-escalate and time-to-notify.Maintain and improve runbooks, escalation matrices and standard operating procedures.Required qualifications (mandatory)Bachelor's degree in Computer Science, Information Security or a related field, or equivalent professional experience.5+ years of experience in a SOC, MSSP or MDR environment, including at least 1–2 years leading or mentoring analysts.Hands-on experience with Microsoft Sentinel (minimum 2 years in production), covering analytics rules, incidents, entity investigation, workbooks, watchlists, UEBA and playbooks.Strong proficiency in KQL for detection engineering, threat hunting and investigation.Working knowledge of the Microsoft security ecosystem: Defender XDR (Endpoint, Identity, Office 365, Cloud Apps), Entra ID and Azure activity logs.Solid understanding of the incident response lifecycle, the MITRE ATT&CK framework and common attack techniques.Good knowledge of networking, Windows and Linux internals, Active Directory and cloud security fundamentals.Experience working to customer SLAs in a multi-tenant or managed services environment.Excellent written and verbal communication skills, including incident reporting to technical and executive audiences.Willingness to work in a 24x7 rotational environment and to be available for on-call escalations.Preferred qualificationsHands-on experience with Wazuh: agent deployment, custom rules and decoders, active response, file integrity monitoring and vulnerability detection.Microsoft certifications such as SC-200 (Security Operations Analyst), AZ-500 or SC-100.Industry certifications such as GCIH, GCIA, CySA+, BTL1/BTL2, or equivalent incident response credentials.Experience with other SIEM/SOAR platforms (Splunk, QRadar, Elastic) and EDR tools (CrowdStrike, SentinelOne).Scripting skills in PowerShell or Python for automation and enrichment.Exposure to threat intelligence platforms, threat hunting programs and detection-as-code practices.Familiarity with compliance frameworks such as ISO 27001, SOC 2, PCI DSS or NIST CSF.Key competenciesLeadership: builds a motivated, accountable team and develops analysts into senior contributors.Analytical judgment: makes sound, timely decisions under pressure with incomplete information.Customer focus: communicates clearly and calmly with customers during active incidents.Continuous improvement: uses data to reduce false positives, improve detection coverage and streamline workflows.