Active listing
Lead SOC Analyst, Assistant Manager
About the role
Incident Response & Investigations team within KPMG Group Digital's Operational Security function builds and operates the SOC to detect, investigate, and respond to cyber threats. The Lead SOC Analyst, Assistant Manager, provides advanced technical expertise, mentors junior analysts, and leads complex incident investigations across SIEM, EDR, cloud and network environments. Gurgaon, India (with secondary location Bangalore), hybrid onsite model; relocation assistance not mentioned.
What you’ll do
- Perform triage, investigation, containment, and remediation of high‑severity incidents
- Act as senior technical escalation point and guide analysts during incidents
- Conduct forensic data collection and analysis across endpoints, network, cloud, and identity sources
- Produce incident timelines, investigation notes, and post‑incident summaries
- Support detection rule tuning and threat‑hunting activities
- Contribute to SOC tooling improvements and automation playbooks
What you’ll bring
- SOC incident response experience
- Strong understanding of attack techniques and threat actor behaviors
- Analyze alerts across SIEM, EDR, cloud, identity, network tools
- Scripting/automation with Python or PowerShell
- Familiarity with MITRE ATT&CK and NIST CSF frameworks
- Excellent written and verbal communication