Principal Detection and Response Specialist

7 - 12 years

15 - 30 Lacs

Posted:20 hours ago| Platform: Naukri logo

Apply

Work Mode

Hybrid

Job Type

Full Time

Job Description

Role & responsibilities

  • (India only) Act as the SOC Manager/Team Lead as we grow out our capability in India.
  • Direct advanced threat hunting engagements, leveraging deep knowledge of attacker TTPs and the MITRE ATT&CK framework.
  • Oversee triage and investigation of critical security incidents; implement and coordinate mitigation strategies.
  • Lead the implementation advanced detection analytics using SIEM and EDR platforms.
  • Lead postincident reviews to identify detection gaps and recommend systemic improvements.
  • Mentor team members on investigative techniques and tooling.
  • Lead the refinement of detection logic and incident playbooks.
  • Lead the implementation and development of new capabilities and tooling.
  • Provide subject matter expertise specific tools and technologies.
  • Participation in 24x7 on-call rotation (as required).
  • Engagement with customers as required for onboarding and incident response.

Preferred candidate profile

  • 7+ years in related role, with at least 3+ in a leadership, team lead or management role.
  • English language fluency.
  • Analytical skills, problem solving and critical thinking with a desire and eagerness to acquire new knowledge and constantly learn.
  • Expert knowledge of cyber kill chain (including TTPs), incident response, digital forensics, and malware analysis.
  • Expert knowledge of security, network and broader information technology concepts.
  • Expert scripting/automation skills (Python, PowerShell, or similar) for detection rule creation and enrichment workflows.
  • Ability to lead the implementation and configuring 4 or more of the following:
    • Endpoint Detection and Response (EDR)
    • Security Information Event Management (SIEM)
    • Intrusion Detection and Prevention Systems (IDS/IPS)
    • Vulnerability Management/Cloud Security Posture Management
    • Identity and Access Management (IAM)
    • Email Security / Phishing
    • Remote Access Solutions
    • DNS Security
  • Executive communication skills with ability to translate technical threats into business risk language.

Key Technologies

  • Splunk (SIEM, Enterprise Security and SOAR)
  • Crowdstrike
  • Cisco (EDR, Firepower, Stealthwatch, Security Services Edge, Umbrella, Cyber Vision etc..)
  • Microsoft Defender Suite and Microsoft Sentinel
  • Qualys
  • CyberArk
  • Cloudflare (ZTNA and WAF/DDoS)
  • Elastic
  • Abnormal
  • Darktrace
  • Fortinet Firewalls[JC1]

[JC1]List is not exhaustive and we are willing to train/teach new technologies as long as they have transferrable skills/experiences with similar technologies.

Mock Interview

Practice Video Interview with JobPe AI

Start Job-Specific Interview
cta

Start Your Job Search Today

Browse through a variety of job opportunities tailored to your skills and preferences. Filter by location, experience, salary, and more to find your perfect fit.

Job Application AI Bot

Job Application AI Bot

Apply to 20+ Portals in one click

Download Now

Download the Mobile App

Instantly access job listings, apply easily, and track applications.

coding practice

Enhance Your Skills

Practice coding challenges to boost your skills

Start Practicing Now

RecommendedJobs for You

mumbai, mumbai suburban, mumbai (all areas)

mumbai, mumbai suburban, mumbai (all areas)

hyderabad, pune, gurugram, bengaluru