AGMÂ Security Operations & Incident Response
Ahmedabad, Gujarat, India
â ď¸ We'll shut down after Aug 1st - try foođŚ for all jobs in tech â ď¸
Adani Group
Adani Group, a leading integrated business conglomerate enriching lives, creating sustainable value, and empowering India through #GrowthWithGoodness- Oversee real-time incident handling, escalation management, and response coordination for cyber threats, breaches, and anomaliesÂ
- Act as the primary escalation point during high-severity incidents, ensuring containment and rapid resolutionÂ
- Design and maintain incident response runbooks, playbooks, SLA matrices, and crisis communication protocolsÂ
- Lead and manage triage activitiesÂ
- Ensure tight integration between SOC operations, threat intelligence, DFIR, and red/blue teamsÂ
- Drive detection engineering efforts to improve alert quality, correlation logic, and MITRE ATT&CK mappingÂ
- Implement continuous improvement programs in MTTR, false positive reduction, and analyst productivityÂ
- Lead post-incident RCA reviews, reporting, and feedback loops to enhance readinessÂ
- Manage relationships with OEMs, MSSPs, and security product vendors for technology alignmentÂ
- Mentor SOC managers, team leads, and analysts to build a resilient and responsive operations teamÂ
- Ensure compliance with security and privacy standards (e.g., NIST, IEC 62443, ISO 27001, DPDP Act)Â
- Deep expertise in SIEM (e.g., Splunk, QRadar, LogRhythm, SentinelOne), SOAR platforms, EDR/XDR tools, threat intelligence platformsÂ
- Strong knowledge of network security, log analysis, endpoint telemetry, and OT-specific telemetry correlationÂ
- Familiarity with MITRE ATT&CK, cyber kill chain, and threat hunting techniquesÂ
- Knowledge of OT security architectures including SCADA, PLCs, DCS, and OT network segmentationÂ
- Scripting and automation exposure (Python, PowerShell, Bash) preferredÂ
- Familiarity with OT SOC environments, ICS protocol detection (Modbus, DNP3), and industrial anomaly detection tools (e.g., Nozomi, Claroty)Â
Leadership & Personality Traits:Â
- Strategic thinker with an operations-first mindset and execution rigorÂ
- Calm, decisive, and clear-headed in crisis and high-pressure scenariosÂ
- Strong stakeholder engagement and communication skills across technical and executive levelsÂ
- Proven ability to lead multi-location teams with cultural sensitivity and high performanceÂ
- Continuous learner with a growth mindset and passion for cybersecurity excellenceÂ
Â
Preferred Industry Background:Â
- Large industrial conglomerates (Power, Ports, Renewables, Mining, Airports)Â
- OT and IT OEMsÂ
- MSSPs, SOC service providersÂ
- Consulting firms with cyber defence practices (e.g., Big 4)Â
- Bachelorâs or Masterâs in Cybersecurity, Computer Science, or EngineeringÂ
- Preferred certifications: CISSP, CISM, GCIA, GCIH, or SOC-related credentialsÂ
- 12 + years of cybersecurity experience, with at least 6 years in SOC/IR leadership rolesÂ
- Experience managing global SOC operations or OT-specific cyber operations is a strong plusÂ
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index đ°
Tags: Automation Bash CISM CISSP Compliance Computer Science Cyber Kill Chain DFIR DNP3 EDR Forensics GCIA GCIH ICS IEC 62443 Incident response Industrial ISO 27001 Log analysis LogRhythm MITRE ATT&CK Modbus Network security NIST PowerShell Privacy Python QRadar SCADA Scripting SIEM SOAR SOC Splunk Threat intelligence XDR
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.