Active listing
Lead SOC Analyst, Assistant Manager
About the role
Incident Response & Investigations team within KPMG Operational Security protects the enterprise by detecting and responding to cyber threats. The Lead SOC Analyst, Assistant Manager drives complex incident triage, forensic analysis, threat‑hunting and tooling automation while mentoring junior analysts. Based in Bangalore, India with a secondary site in Gurgaon, hybrid on‑site work model (On-site).
What you’ll do
- Perform triage, investigation, containment and remediation of high‑severity incidents
- Act as senior technical escalation point and guide analysts during incident handling
- Conduct forensic data collection and analysis across endpoints, network, cloud and identity sources
- Produce detailed incident timelines, notes and post‑incident summaries
- Support detection rule tuning and threat‑hunting activities
- Contribute to SOC tooling automation, playbook improvement and audit support
- Mentor junior analysts and share investigative techniques
What you’ll bring
- SOC or incident response experience
- Strong understanding of attack techniques and investigative methodologies
- Analyze alerts across SIEM, EDR, cloud, identity and network tools
- Scripting/automation with Python or PowerShell
- Familiarity with MITRE ATT&CK or NIST CSF frameworks
- Excellent written and verbal communication
Nice to have
- CompTIA CySA+ certification
- Microsoft SC‑200 Security Operations Analyst Associate
- Microsoft AZ‑500 Azure Security Engineer Associate
Skills
Education
Bachelor's