×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

SOC Principal

Job in Bengaluru, 560001, Bangalore, Karnataka, India
Listing for: HCLSoftware
Full Time position
Listed on 2026-09-13
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
Location: Bengaluru

SOC Principal
HCL Software | Office of the CISO

Location:

India - Bangalore / Noida / Remote
About the Role
HCL Software is seeking a SOC Principal to serve as the most senior technical authority inside our
Security Operations Center. This is a hands-on individual contributor role for someone who wants
depth and influence rather than a management span, and it sits at the point where detection quality,
investigation rigor, and incident command all converge.
You will set the technical bar for how the SOC detects, investigates, and closes out threats across a
global multi-cloud and SaaS estate, while our detection platform modernizes and our telemetry
pipeline is rebuilt.
You will work alongside SOC Engineering, Vulnerability Management, Red Team, and Product
Security, and you will be the person the organization escalates to when an incident is genuinely
ambiguous.

Key Responsibilities

Investigation and Incident Response

• Act as a technical incident commander for severity-1 and severity-2 events, coordinating across
IT, engineering, legal, communications, and customer-facing teams.

• Own the deep-dive analysis that junior tiers cannot complete: host and memory forensics,
cloud control-plane reconstruction, identity abuse chains, and lateral movement tracing.

• Drive root cause to conclusion and convert every significant incident into concrete detection,
control, and process changes with named owners.

• Set and enforce evidence handling, chain of custody, and case documentation standards
suitable for customer, regulator, and audit scrutiny.
Detection and Content Engineering

• Define detection content standards covering test coverage, version control, peer review, and
promotion through a detection-as-code pipeline.

• Maintain an ATT&CK-aligned coverage map, identify blind spots, and prioritize new content
against threat intelligence and business risk.

• Govern tuning and suppression decisions so false-positive reduction never quietly removes real
visibility.

• Partner with SOC Engineering on telemetry sufficiency, parsing quality, and log source
onboarding during platform migration.
Threat Hunting and Intelligence

• Build and run a recurring hunt program driven by hypotheses, threat intelligence, and observed
adversary tradecraft relevant to enterprise software companies.

• Operationalize intelligence into detections, hunt queries, and watchlists rather than leaving it as
reading material.

• Collaborate with Red Team on purple-team exercises and validate that emulated tradecraft is
actually detected.

Technical Leadership

• Mentor analysts across shifts, run investigation retrospectives, and raise consistency in triage
and escalation decisions.

• Author and maintain the runbook and playbook library, keeping it accurate as the platform
estate changes.

• Represent the SOC in design discussions with architecture, cloud, and product engineering
teams.

• Produce clear written analysis for leadership that separates what is known, what is suspected,
and what is still open.
Required AI Expertise

Hands-on experience implementing and evaluating AI-driven security automation, automated
triage, and generative AI investigation workflows within a modern SOC environment.

• Strong understanding of threat landscapes targeting AI/ML systems, including prompt injection,
model poisoning, data exfiltration via LLMs, MCP, and securing enterprise AI infrastructure.

• Ability to design detection strategies for AI-assisted attack vectors and adversary tradecraft
leveraging autonomous or AI-enhanced tools.

Required Qualifications

• 8+ years in security operations, incident response, or threat detection, including senior or lead
responsibility for major incidents.

• Demonstrated incident command experience on severity-1 events, with the judgment to make
containment…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary