Back to jobs
M
Hiring companyMETRO/MAKRO

Verified today

Level 3 Cyber Defense Operations Center Specialist

Pune, Maharashtra, India Full-time On-site

About the role

Metro Global Solution Center (MGSC), the internal solution partner for METRO, seeks a Level 3 Cyber Defense Operations Center (CDOC) Specialist in Pune, India. The role leads advanced security operations with a focus on SIEM and SOAR technologies, driving detection engineering, automated response, and complex incident handling. Day-to-day work includes optimizing detection rules, developing playbooks, managing high-severity incidents, and mentoring Level 1 and 2 analysts. The position is full-time, on-site, and includes a 24/7 on-call rotation.

What you’ll do

  • Oversee daily operations including SIEM/SOAR tuning, alert triage, and coordinated incident response to ensure effective real-time threat monitoring.
  • Lead end-to-end security incident response, including analysis, containment, mitigation, and reporting, leveraging SIEM/SOAR insights and cross-team coordination for swift resolution.
  • Design and implement detective controls for emerging threats and vulnerabilities.
  • Perform proactive threat hunting across multiple platforms and environments.
  • Support in designing and maintaining detection rules, response playbooks, and escalation paths aligned with threat intelligence and compliance.
  • Continuously enhance SIEM/SOAR/XDR alert use cases and threat detection capabilities.
  • Act as a senior liaison with threat intelligence and infrastructure teams to enhance detection and response capabilities.
  • Research emerging threats, vulnerabilities, and attack techniques to improve defenses.

What you’ll bring

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
  • 7-11 years of total experience in SOC in a large multi-national organization or in a known MSSP.
  • Minimum 8 years of Incident Response experience.
  • At least 2 years of experience on SOAR capabilities.
  • Deep hands-on expertise with SIEM, SOAR, XDR technologies such as Google Chronicle, Crowdstrike Logscale, Splunk.
  • Strong working knowledge of endpoint security tools and concepts, including EDR (CrowdStrike, Defender, Cortex), DLP, and MDM.
  • Strong knowledge of MITRE ATT&CK, NIST CSF frameworks, and cyber kill chain concepts.
  • Advanced proficiency in automating incident response using SOAR technologies.

Nice to have

A Master's degree or relevant certifications (e.g., CISSP, CISM, SANS/GIAC, ECIH, GCIH, CEH, DFIR) may be preferred.

Skills

SIEMSOARXDRGoogle ChronicleCrowdstrike LogscaleSplunkEDRMITRE ATT&CK

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.