Lead an offshore SOC pod for L1/L2 operations, ensure queue and case quality, run operational governance and incident escalation, tune detections in Splunk, coordinate across endpoint/network/email/vulnerability tools, promote responsible AI/automation, and present KPI-driven governance to U.S. stakeholders.
Position: Cybersecurity – SOC Lead (AI & Automation)
Location: Chennai - Onsite/Hybrid/Remote
Shift Timing: 5.30PM - 2.30AM IST (US Eastern Time)
Engagement Type: Full Time
Role Summary:
Lead offshore SOC execution for Customer,
combining operational leadership, detection governance, case quality oversight,
and practical automation. This role must drive disciplined day-to-day
performance while improving the use of built-in AI / automation features across
the CLW security stack without sacrificing analyst judgement, traceability, or
investigation fidelity.
Key Responsibilities:
- Lead the offshore SOC pod across L1 and L2 activities, ensure queue health, review investigation quality, and maintain strong stakeholder alignment with Customer security leadership.
- Own daily operational governance including case quality, severity calibration, shift handoffs, SLA adherence, and escalation discipline for major incidents.
- Drive continuous improvement in Splunk ES / Mission Control operations, detection logic review, alert noise reduction, and visibility gap identification.
- Coordinate across CrowdStrike, Proofpoint, Qualys, Palo Alto, Dragos, ServiceNow, and automation workflows to improve response effectiveness.
- Translate technical events into concise business risk language for U.S. stakeholders and support weekly service reviews, KPI reporting, and corrective action tracking.
- Promote responsible use of AI-assisted summarization, enrichment, and workflow acceleration within approved guardrails.
Tool Environment:
Splunk ES / Mission Control, CrowdStrike,
Qualys, Proofpoint, Palo Alto, Dragos, ServiceNow, Teams, M365 / Entra context,
automation / SOAR capabilities where approved.
Required Experience & Skills:
- Strong security operations leadership experience, including direct management of analysts or provider teams in a 24x7 or follow-the-sun model.
- Advanced proficiency in Splunk-based SOC operations and solid working knowledge of endpoint, network, email, and vulnerability telemetry.
- Ability to coach analysts, review investigations, and enforce consistent case quality and operational rigor.
- Strong executive-facing communication and ability to run governance reviews with facts, metrics, and remediation actions.
- Experience working with offshore teams serving U.S.-based stakeholders.
Preferred Qualifications:
- Manufacturing / OT security exposure, especially where corporate-to-plant visibility and escalation discipline matter.
- Experience with ServiceNow workflows, playbook optimization, and approved automation / SOAR patterns.
- Awareness of MITRE ATT&CK-aligned detection engineering and risk-based incident prioritization.
Offshore India Operating Model:
- Work as an embedded offshore team member supporting U.S.-based stakeholders with dependable daily communication, disciplined documentation, and clear ownership of actions and follow-ups.
- Operate with strong handoff hygiene across shifts, including concise status updates, ticket notes, evidence capture, and risk-based escalation to Customer leads.
- Support a manufacturing-aware operating model where uptime, safety, OT change sensitivity, and controlled execution are treated as essential requirements.
- Use ServiceNow and Microsoft Teams effectively for workflow coordination, incident tracking, approvals, and stakeholder communication.
- Be prepared to align with late afternoon / evening IST overlap with U.S. Eastern time and participate in critical incident bridges when required.
Success Measures:
- Stable, measurable SOC operations with better case quality, tighter escalation hygiene, and improved visibility coverage.
- Documented reduction in alert noise and stronger detection fidelity across the CLW stack.
- Clear governance cadence and dependable offshore team performance.
Similar Jobs
Cloud • Fintech • Food • Information Technology • Software • Hospitality
Provide frontline technical and functional support for Toast customers across chat, voice, and tickets. Troubleshoot hardware/software, manage multiple interactions, communicate complex concepts clearly, meet SLAs/KPIs, collaborate on process improvements, and support 24x7 rotational shifts with initial in-office period.
Top Skills:
Chat SystemsPos SystemsTicketing SystemsToast
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Performs private equity, hedge fund, and debt fund accounting for global clients. Responsibilities include maintaining fund structures, recording investor commitments and capital activity, booking transactions, finalizing accounts, preparing NAV workbooks and reports, calculating management fees, preferred returns, carried interest, and performance ratios, and supporting investor and client reporting. The role also handles fund instruments such as bank debt, TRS, MBS, and CLOs while working UK/US night shifts in a hybrid Mumbai-based environment.
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Senior fund accounting role supporting private equity, hedge fund and debt clients. Manage complex fund structures, investor capital activities, NAV preparation, economic allocations, fee and carried interest calculations, investor and fund reporting, and client interactions. Requires knowledge of waterfall methods, performance ratios, and instruments like TRS, MBS, and CLOs.
What you need to know about the Chennai Tech Scene
To locals, it's no secret that South India is leading the charge in big data infrastructure. While the environmental impact of data centers has long been a concern, emerging hubs like Chennai are favored by companies seeking ready access to renewable energy resources, which provide more sustainable and cost-effective solutions. As a result, Chennai, along with neighboring Bengaluru and Hyderabad, is poised for significant growth, with a projected 65 percent increase in data center capacity over the next decade.


