Overview
SOC lead or Manager Jobs in Greater Bengaluru Area at Terralogic
Title: SOC lead or Manager
Company: Terralogic
Location: Greater Bengaluru Area
Job Title: SOC lead / Manager
Job location: Bangalore / Chennai
Year of Exp : 6+ years
Job Summary:
We are seeking a seasoned SOC Lead who can lead the SIEM deployment end-to-end architecture, implementation, and optimisation of enterprise SIEM solutions. Must have a deep understanding of log ingestion pipelines, parser development, and threat detection engineering to ensure our security operations are data-driven and resilient.
Key Responsibilities:
1. End-to-End Solution Deployment •
Architecture & Design: Develop High-Level Design (HLD) and Low-Level Design (LLD) documents for SIEM infrastructure, including sizing, retention policies, and high availability (HA/DR) configurations.
• Implementation: Perform the full installation and configuration of SIEM components (collectors, indexers, search heads, or cloud-native connectors).
• Log Onboarding: Integrate logs from a wide array of sources: firewalls, EDR, cloud (AWS/Azure/GCP), IAM, databases, and custom applications.
2. Engineering & Optimization •
Parser Development: Build custom parsers (Regex, Logstash, or KQL-based) for
non-standard log sources to ensure proper normalization and mapping to schemas like
ECS or ASIM.
• Content Development: Design and implement correlation rules and detection logic based on the MITRE ATT&CK framework.
• Performance Tuning:
Monitor SIEM health, optimize search queries to reduce latency, and manage license/EPS consumption effectively.
3. Consulting & Strategy
•Use Case Workshops: Work with stakeholders to define business-specific security use
cases and translate them into technical requirements.
• Automation: Integrate SIEM with SOAR platforms to automate incident response playbooks and streamline SOC workflows.
• Documentation: Maintain comprehensive technical documentation, including data dictionaries, ingestion specs, and standard operating procedures. (SOPs).
Required Skills & Qualifications:
6+ in cybersecurity, with at least 6+ years dedicated specifically to SIEM administration, engineering and deployment.
• Platform Expertise: Deep hands-on experience with at least one major SIEM (Splunk, Sentinel, QRadar, or Elastic).
Certification in these platforms is highly preferred.
Technical Proficiency:
• Strong knowledge of Regular Expressions (Regex) and scripting (Python, PowerShell, or
Bash).
• Solid understanding of networking (TCP/IP, DNS, HTTP) and OS internals (Linux/Windows).
• Familiarity with cloud security architecture (Azure Log Analytics, AWS CloudWatch).
• Frameworks: Practical experience applying MITRE ATT&CK, NIST, or ISO 27001 controls within a SIEM context.