Team Member - SOC Governance and Incident Oversight

Mumbai, Maharashtra4-6 yrsPermanentOn-siteINR 12 - 15 LPA

Hiring for: One of India’s leading non-banking financial companies (NBFCs), focused on driving financial inclusion across rural and semi-urban markets.

Role: Team Member - SOC Governance and Incident Oversight

Experience: 4 to 6 years

Location(s): Kurla, Mumbai

Salary: Up to INR 15 LPA (including 5% variable pay)


Job Description


Role Purpose

Responsible for governance and oversight of the outsourced Security Operations Centre (SOC) function, including independent validation of SOC performance, security incident closure, alert quality, service-level adherence and applicable regulatory requirements. The role will provide physical oversight of IBM SOC operations from Bengaluru, drive effective utilization of existing security investments, improve SOC processes and independently validate the quality and completeness of SOC deliverables and incident closures.


Key Responsibilities


SOC Governance & Service Oversight

• Provide day-to-day governance and oversight of the outsourced IBM SOC function.

• Operate from Bengaluru to facilitate physical oversight and effective coordination with the SOC.

• Review SOC operations against agreed SLAs, KPIs, processes and security requirements.

• Independently validate SOC reports, dashboards, metrics and operational deliverables submitted by IBM.

• Identify service gaps, recurring issues and control weaknesses and track them to closure.

• Coordinate with internal Information Security stakeholders and IBM SOC teams for operational governance.


Security Incident Oversight & Quality Assurance

• Monitor security incidents handled by the SOC and ensure adherence to defined response and closure TATs.

• Perform quality checks on incident categorization, severity assessment, investigation summary and closure justification.

• Independently validate evidence supporting incident closure before acceptance.

• Track overdue, recurring and high-risk security incidents and escalate deviations appropriately.

• Review incident trends and identify opportunities to strengthen detection and response capabilities.

• Ensure appropriate root-cause analysis and corrective actions are documented for significant incidents.


Regulatory Compliance & RBI Requirement Oversight

• Monitor SOC processes and incident management activities against applicable regulatory requirements.

• Track compliance with RBI Observations relating to timely closure of security incidents.

• Maintain evidence and management reporting required to demonstrate adherence to incident closure TATs.

• Track regulatory observations, audit findings and remediation actions relating to SOC operations.

• Support internal, regulatory and audit reviews by providing validated SOC governance and incident management evidence.


Alert & Detection Governance

• Review the quality and effectiveness of security alerts generated by the SOC.

• Monitor false-positive trends and coordinate with SOC teams for appropriate rule tuning.

• Review alert categorization, prioritization and escalation mechanisms.

• Identify gaps in detection coverage and recommend improvements to monitoring use cases.

• Ensure changes to detection rules and monitoring logic are appropriately documented and governed.


Threat Hunting & Incident Investigation Oversight

• Coordinate and oversee threat-hunting activities for significant or suspicious security events.

• Review incidents indicating potential malware, ransomware or advanced threat activity.

• Ensure appropriate investigation and threat-hunting activities are performed following significant SIEM alerts.

• Review investigation findings and ensure remediation and preventive actions are tracked.

• Identify recurring attack patterns and recommend improvements to SOC detection capabilities.


SIEM & Log Governance

• Review SIEM log sources and ensure appropriate security-relevant events are being monitored.

• Drive optimization of log ingestion to focus on Events of Interest and improve monitoring effectiveness.

• Review log correlation requirements and identify opportunities for improved detection through correlation.

• Coordinate with infrastructure, application and security teams for relevant log-source onboarding and optimization.

• Review SIEM use cases and identify opportunities for automation and improved detection efficiency.


Security Tool Utilization & Automation

• Identify opportunities to maximize existing Information Security investments including DLP, DAM, Security.AI, IS-GRC, Palo Alto security products and SIEM capabilities.

• Identify repetitive SOC governance and monitoring activities that can be automated.

• Coordinate with technical teams and vendors for integration and automation initiatives.

•Track implementation and effectiveness of agreed automation initiatives.


Reporting, Metrics & Management Governance

• Prepare and review periodic SOC governance dashboards and management reports.

• Track incident volumes and severity, closure TAT, SLA adherence, false-positive trends, alert quality, recurring incidents, threat-hunting activities, open incidents and regulatory/audit observations.

• Provide management with meaningful insights on SOC effectiveness and areas requiring improvement.

• Ensure accuracy and completeness of reports received from the outsourced SOC.


Key Deliverables

• Effective governance and oversight of outsourced SOC operations.

• Independent validation of SOC reports and deliverables.

• Timely closure and quality assurance of security incidents.

• Compliance tracking for regulatory and audit observations, including RBI requirements.

• Improved alert quality and reduction of unnecessary false positives.

• Improved SIEM log optimization and correlation.

• Effective oversight of threat-hunting activities.

• Increased utilization and automation of existing security tools.

• Accurate and timely SOC management reporting.

• Continuous improvement of SOC processes, controls and service quality.


Candidate Profile


Education:

Bachelor’s degree in Computer Science, Information Technology, Cyber Security or a related discipline. Relevant certifications such as CISSP, CISM, CRISC, CEH, Security+ or equivalent are advantageous.


Experience:


Relevant experience in SOC governance, security operations oversight, incident management, cyber security governance or MSSP management, preferably in an outsourced SOC environment. Experience with SIEM, security monitoring, incident lifecycle management, SLA/TAT monitoring and regulatory/audit requirements is desirable.

Skills

Cyber Security GovernanceIncident Lifecycle ManagementMSSP ManagementRegulatory Compliance and AuditSecurity Incident ManagementSecurity MonitoringSecurity Operations Center (SOC) ManagementSIEMSLA/TAT MonitoringSOC Governance

Posted September 29, 2026