AI SOC Lead

Cyble
Bengaluru
Workplace: OnsiteFull timeUSD 18,000 - 25,000 annuallyFunction: Data Science & Machine LearningExperience: 4-6 yearsSkills: ["Communication","Analytical thinking","Leadership","Decision-making","Cross-functional collaboration"]

Lead 24×7 SOC operations and manage a Tier 1–3 analyst team, ensuring SLA adherence and escalation for critical incidents. Drive AI-augmented detection and response by integrating and tuning SIEM/SOAR/EDR tools, building AI-assisted triage playbooks, and refining detections using Cyble Vision and dark web intelligence feeds. Own incident response, reporting, SOC metrics (MTTD/MTTR), and continuous automation to improve detection fidelity and reduce dwell time.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Cyble
Cyble
4 months ago

AI SOC Lead

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 21 hours agoStatus: Live

Job Summary

Lead 24×7 SOC operations and manage a Tier 1–3 analyst team, ensuring SLA adherence and escalation for critical incidents. Drive AI-augmented detection and response by integrating and tuning SIEM/SOAR/EDR tools, building AI-assisted triage playbooks, and refining detections using Cyble Vision and dark web intelligence feeds. Own incident response, reporting, SOC metrics (MTTD/MTTR), and continuous automation to improve detection fidelity and reduce dwell time.
Location: Bengaluru
Workplace: Onsite
Employment Type: Full time
Job Function: Data Science & Machine Learning
Seniority: Manager level

Key Responsibilities

  • •Lead, mentor, and develop a Tier 1–3 SOC analyst team and oversee 24×7 SOC operations with SLA adherence.
  • •Serve as the primary escalation point for complex or high-severity incidents and lead end-to-end incident response for critical events.
  • •Champion AI/ML tooling for detection and response, including integrating and tuning AI-powered SIEM/SOAR/EDR and developing AI-assisted playbooks for triage.
  • •Oversee alert triage workflows, maintaining detection rules/correlation logic across SIEM and XDR and auditing triage accuracy against SLAs.
  • •Track SOC metrics (MTTD, MTTR, false positives, coverage gaps), refine runbooks/SOPs, and drive automation to improve analyst efficiency.

Pay and Benefits

Salary: USD 18,000 - 25,000 annually

Key Requirements

  • •4–6 years of progressive cybersecurity experience, including at least 2 years in a SOC leadership or senior analyst role.
  • •Hands-on experience with SIEM platforms such as Splunk, Microsoft Sentinel, or IBM QRadar.
  • •Strong incident response, digital forensics, and threat hunting experience.
  • •Experience integrating or operating AI/ML-powered security tools (e.g., UEBA, NDR, AI-assisted SOAR).
  • •Proficiency with attack frameworks (MITRE ATT&CK, Cyber Kill Chain, Diamond Model) and automation scripting in Python, PowerShell, or KQL.
Experience:4-6 yearsCybersecuritySOCSIEMSOAREDRXDRAI/ML security
Skills:CommunicationAnalytical thinkingLeadershipDecision-makingCross-functional collaboration
Certifications:CISSPCISMGCIAGCIHGDATCEHMicrosoft SC-200ISO 27001NIST CSFSOC 2PCI-DSS
Tech Stack:SIEMSOAREDRXDRSplunkMicrosoft SentinelIBM QRadarPalo Alto XSOARSplunk SOARMicrosoft Sentinel PlaybooksAWSAzureGCPPythonPowerShellKQLMITRE ATT&CKCyber Kill ChainDiamond ModelUEBA

Eligibility

Nationality:US National
Work Authorization:Authorization required. Sponsorship not provided.

Company Brief

Cyble
Provides cyber threat intelligence, dark web monitoring, and digital risk protection services to help organizations detect, investigate, and remediate cyber threats, data leaks, and fraud across surface, deep, and dark web sources.
Industry: Cybersecurity
Website