SOC Lead

Kotak Mahindra Bank
Posted on
Kotak Mahindra Bank logo

Experience
7 - 12 yrs
Salary (CTC)
₹15L - ₹30L
Job Location
Mumbai, India
Vacancy
1
Designation
Security Operations Center Lead
Job Type
Not specified

Job Description

SOC Lead – Job Description

Role Purpose

Lead and govern the Bank’s Security Operations Center (SOC) to ensure effective monitoring, incident response, regulatory compliance, SOC maturity (CMM alignment), and service delivery. The role provides oversight of SOC coverage, onboarding governance, use case effectiveness, alert quality, and vendor performance.

Key Responsibilities

  1. Provide governance and oversight of SOC operations, processes, KPIs, KRIs and service delivery.
  2. Ensure all Bank assets are onboarded and monitored as per approved security monitoring standards.
  3. Review and govern SIEM onboarding, monitoring coverage, and closure of visibility gaps.
  4. Review use case coverage and effectiveness to ensure security alerts generate meaningful and actionable outcomes.
  5. Drive reduction of false positives and improvement of true positive detection through periodic reviews and governance.
  6. Oversee incident response activities and ensure adherence to agreed SLAs and escalation procedures.
  7. Lead SOC maturity improvement initiatives and ensure alignment with the Bank’s Cybersecurity Maturity Model (CMM) framework.
  8. Ensure compliance with regulatory, audit, and internal security requirements including RBI, ISO 27001, PCI-DSS and other applicable standards.
  9. Manage SOC service vendors/MSSPs, conduct service reviews, monitor SLA compliance and drive continuous service improvement.
  10. Stay updated on emerging threats, latest SOC technologies, product enhancements and industry best practices.
  11. Provide periodic dashboards, metrics and executive reports to management.

Key Deliverables

  1. 100% onboarding and monitoring coverage of Bank assets as per defined standards.
  2. Effective governance of SIEM onboarding and use case management activities.
  3. Improved alert quality with high true positive rate and reduced false positives.
  4. Compliance with SOC maturity (CMM), regulatory, audit and governance requirements.
  5. Timely incident handling and adherence to SOC service levels.
  6. Effective vendor governance and performance management.
  7. Regular SOC coverage, risk and operational reporting.



Experience & Skills

  1. 8–15 years of Cyber Security experience with at least 5 years in SOC leadership, monitoring, incident response or cyber defense roles.
  2. Strong understanding of SIEM, EDR/XDR, Threat Intelligence, Incident Response and Security Operations.
  3. Experience in Banking, Financial Services or other regulated industries preferred.
  4. Strong stakeholder, audit, governance and vendor management skills.

Preferred Certifications

  1. CISSP, CISM, GIAC, ISO 27001, SC-200 or equivalent security certifications.


No Referrers Available

There are currently no referrers available for this job. You can still apply, will let you know once there is any referrer available.