Back to search
Callaway Digital Technologies Linkedin · Posted today

Information Security Operations Specialist

India

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Job Description

Job Summary

Information Security Lead with 8-12 years of extensive experience in Security Operations Center (SOC), Incident Response (IR), proactive Threat Hunting, Threat Intelligence & Vulnerability Management and handling complex security escalations. The candidate will act as a senior escalation point for high-severity security incidents, conduct advanced investigations, develop threat hunting hypotheses, and provide actionable intelligence to improve the organization’s overall security posture.

The role requires hands-on expertise across SIEM, EDR/XDR, network security monitoring, malware analysis, threat intelligence platforms, and cloud security monitoring.

Roles & Responsibilities:

  • Coordinate and lead incident response activities for cybersecurity incidents.
  • Ensure timely escalation, containment, eradication, and recovery from security incidents.
  • Experience in handling P1 incidents, driving investigation till closure.
  • Lead complex investigations, handle critical escalations from L1/L2 teams, and perform root-cause analysis
  • Provide analysis and trending of security log data from security devices.
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel.
  • Experience working with SOAR platforms and security automation technologies.
  • Hands-on experience with EDR/XDR solutions such as Microsoft Defender XDR, CrowdStrike Falcon.
  • Experience with vulnerability management tools such as Qualys, Tenable, or Rapid7 is preferred.
  • Good to have knowledge and experience in Advance SOC environment, SOC automation, AI usage in SOC.
  • Perform threat hunting and proactive security investigations.

SOC Operations

  • Lead day-to-day Security Operations Center (SOC) operations.
  • Ensure effective security monitoring, incident detection, investigation, response, and resolution in accordance with defined SLAs.
  • Act as the primary operational escalation point for critical and high-severity security incidents.
  • Coordinate major incident response activities with internal technical teams, and external stakeholders.
  • Monitor operational KPIs, service quality, and SLA compliance, driving continuous service improvements.
  • Review and approve incident reports, root cause analysis (RCA), and post-incident review documentation.
  • Ensure accurate incident documentation and timely communication throughout the incident lifecycle.
  • 24x7 on call support to team members.
  • Creating runbooks/playbooks and SOPs.

Security Monitoring & Threat Detection

  • Oversee continuous monitoring using SIEM, SOAR, EDR/XDR, and other security technologies.
  • Review, validate, and optimize SIEM correlation rules, detection use cases, alert tuning, and dashboards.
  • Lead threat hunting initiatives and support proactive identification of advanced threats.
  • Work closely with Threat Intelligence teams to operationalize Indicators of Compromise (IOCs) and emerging threat intelligence.
  • Ensure timely investigation and escalation of suspicious activities and security events.
  • Team Leadership
  • Lead, mentor, and manage a team of internal L3 Security Analysts & collaborate with external vendor L1/L2 security analysts, fostering a culture of collaboration, accountability, and continuous learning.
  • Provide technical guidance and support during complex investigations and major security incidents.
  • Conduct performance reviews, one-on-one mentoring, and technical coaching sessions.
  • Identify training needs and support professional development through knowledge-sharing sessions, simulations, and tabletop exercises.
  • Review analyst investigations and incident handling to ensure quality, consistency, and adherence to operational procedures.

Threat Intelligence

  • Proficient in intelligence analysis, analytical models and threat intelligence frameworks such as the cyber kill chain and the diamond model.
  • Skilled in OSINT gathering and OSINT investigations.
  • Familiar with threat intelligence tools such as threat intelligence platforms.
  • Experienced with navigation and collecting information from dark web sources.
  • Proficient at extracting tactics, techniques and procedures from reporting and mapping them to the MITRE ATT&CK framework.
  • Proven experience analyzing and responding to advanced persistent threats, malware campaigns, and cyber-attacks
  • Monitor global threat landscape, including adversary tactics, techniques, and procedures (TTPs), to anticipate and mitigate risks
  • Correlate intelligence with internal telemetry to identify vulnerabilities, indicators of compromise (IOCs), and potential attack vectors
  • Drive continuous improvement of threat intelligence processes, tooling, and frameworks Collaborate cross-functionally with IT, digital, and business teams to embed threat intelligence into security strategy and operations
  • Provide mentorship and technical guidance to junior analysts, acting as a domain expert
  • Evaluate external intelligence sources, vendors, and technologies to strengthen intelligence capabilities
  • Support executive decision-making by translating complex threats into business risk impacts

Vulnerability Management

  • Proficiency with vulnerability scanning tools (e.g., Nessus, Qualys, Rapid7) and familiarity with security frameworks (e.g., NIST, ISO 27001).
  • Ability to analyze vulnerability data, assess risks, and prioritize responses based on potential impact.
  • Good understanding of Windows, UNIX and Linux operating systems functions and security.
  • Perform thorough risk assessments on identified vulnerabilities, considering both the technical aspects and the business context.
  • Collaborate with IT and OT teams to prioritize and facilitate the timely patching of vulnerabilities.
  • Prepare detailed reports on vulnerability findings, including risk assessments, recommended actions, and patch management status.
  • Develop and maintain Vulnerability Management policies, procedures, and related documentation to ensure consistent and effective practices.
  • Stay abreast of the latest cybersecurity threats and vulnerabilities, incorporating this intelligence into Vulnerability Management processes.
  • Communicate effectively with various stakeholders, including IT and OT teams, management, and external partners, to ensure a comprehensive understanding of vulnerabilities, impacts, and mitigation strategies.
  • Provide expertise and support during cybersecurity incidents related to vulnerabilities.
  • Assist in compliance efforts and audits, ensuring that Vulnerability Management practices meet industry standards and regulatory requirements.
  • Regularly review and recommend improvements to the Vulnerability Management program to enhance security posture.

Preferred Certifications

  • GCIH - GIAC Certified Incident Handler
  • GCIA - GIAC Certified Intrusion Analyst
  • CEH - Certified Ethical Hacker
  • Microsoft Certified: Security Operations Analyst (SC-200)
Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search