Verified today
Level 3 Cyber Defense Operations Center Specialist
About the role
Metro Global Solution Center (MGSC), the internal solution partner for METRO, seeks a Level 3 Cyber Defense Operations Center (CDOC) Specialist in Pune, India. The role leads advanced security operations with a focus on SIEM and SOAR technologies, driving detection engineering, automated response, and complex incident handling. Day-to-day work includes optimizing detection rules, developing playbooks, managing high-severity incidents, and mentoring Level 1 and 2 analysts. The position is full-time, on-site, and includes a 24/7 on-call rotation.
What you’ll do
- Oversee daily operations including SIEM/SOAR tuning, alert triage, and coordinated incident response to ensure effective real-time threat monitoring.
- Lead end-to-end security incident response, including analysis, containment, mitigation, and reporting, leveraging SIEM/SOAR insights and cross-team coordination for swift resolution.
- Design and implement detective controls for emerging threats and vulnerabilities.
- Perform proactive threat hunting across multiple platforms and environments.
- Support in designing and maintaining detection rules, response playbooks, and escalation paths aligned with threat intelligence and compliance.
- Continuously enhance SIEM/SOAR/XDR alert use cases and threat detection capabilities.
- Act as a senior liaison with threat intelligence and infrastructure teams to enhance detection and response capabilities.
- Research emerging threats, vulnerabilities, and attack techniques to improve defenses.
What you’ll bring
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 7-11 years of total experience in SOC in a large multi-national organization or in a known MSSP.
- Minimum 8 years of Incident Response experience.
- At least 2 years of experience on SOAR capabilities.
- Deep hands-on expertise with SIEM, SOAR, XDR technologies such as Google Chronicle, Crowdstrike Logscale, Splunk.
- Strong working knowledge of endpoint security tools and concepts, including EDR (CrowdStrike, Defender, Cortex), DLP, and MDM.
- Strong knowledge of MITRE ATT&CK, NIST CSF frameworks, and cyber kill chain concepts.
- Advanced proficiency in automating incident response using SOAR technologies.
Nice to have
A Master's degree or relevant certifications (e.g., CISSP, CISM, SANS/GIAC, ECIH, GCIH, CEH, DFIR) may be preferred.
Skills
Education
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.