SOC Lead, Professional Services Delivery Engineer IV - IN
Rackspace US, Inc.
IndiaremotePosted 1 month ago
Skill Required
SOC-LeadSecurity-Operations-ManagerCybersecurity-LeadMSSP-Security-EngineerSIEM-AdministratorCybersecurity-Delivery-LeadSOC-Team-LeadSOCCloud SecurityCybersecurityEngineeringServerlessISO 27001automationObservabilitydesigningsecuritybuildingdesignDevOpsAzureCloudSIEMAWSGCPandGoAIFulltime
Key highlights
- Role: Security Lead for security Operations
- Required Experience: Leading a team of SOC analysts and engineers
- Environment: MSSP (multi-customer) and Large-scale Public Cloud
- Core Technology: Microsoft Sentinel and Elastic Security SIEM
- Cloud Platforms: Azure, AWS, and GCP
- Notable Recognition: Named a Best Place to Work by Fortune, Forbes, and Glassdoor
Role overview
Rackspace Cyber Defence is seeking a Security Lead for Security Operations to lead and manage a multi-disciplinary security operations centre (SOC). This role is responsible for delivering proactive, risk-based, and intelligence-driven security services across on-premises, private, public, and multi-cloud environments, ensuring customers can defend against an evolving threat landscape.
Responsibilities
- Lead SOC operations in an MSSP environment (Microsoft Sentinel).
- Manage the leadership and management of a multi-disciplinary security operations centre (SOC) that serve Rackspace Cyber Defense customers.
- Act as the face of Rackspace’s security services.
- Oversee Security Operations Centre (SOC) activities within an MSSP environment.
- Lead security operations, threat hunting, incident response, Microsoft Sentinel administration, cloud security monitoring, compliance audits, documentation management, and team development.
- Support and Implement cloud security monitoring across Azure, AWS, and GCP.
- Manage incident detection, investigation, response, and escalation.
- Conduct proactive threat hunting and detection engineering.
- Administer and optimize Microsoft Sentinel and Elastic Security SIEM platforms.
- Design and manage Elastic Cloud Serverless SIEM deployments and integrations.
- Develop security use cases, dashboards, alerts, and automation workflows.
- Maintain SOC documentation, playbooks, SOPs, and reports.
- Support cloud security monitoring across Azure, AWS, and GCP.
- Drive AI-enabled security initiatives and operational improvements.
- Support security audits, compliance, and governance activities.
- Lead and mentor SOC analysts and engineers.
- Manage customer engagements, service delivery, and SLA compliance.
- Handle Critical Incidents (P1), closure, and deep investigation and analysis of critical security incidents.
- Perform post-breach forensic incident analysis reporting and advanced threat hunting.
- Develop custom dashboards and reporting templates.
- Develop complex to customer-specific use cases.
- Threat Hunting & Detection Engineering: Develop use cases and detection rules based on emerging threats and attack techniques.
- Perform analysis and map threats to MITRE ATT&CK framework.
- AI & Security Automation: Implement automation and orchestration workflows to improve SOC efficiency.
- Compliance, Audit & Governance: Ensure compliance with ISO 27001, SOC 2, PCI-DSS, NIST, CIS Controls, and other regulatory requirements.
Requirements
- Self-starting, experienced, and motivated Security Lead.
- Commercially aware and service-oriented.
- Proven record of accomplishment in delivering and managing a security operations centre (SOC).
- Experience of leading a team of Security Operations analysts and Engineers.
- Experience of working in MSSP in multi-customer environment.
- Experience of working in large-scale, public cloud environments and using cloud-native security monitoring tools.
- Experience with Azure Security Centre and Microsoft Sentinel.
- Experience with Vulnerability Management: Qualys, Microsoft Defender.
- Experience with Endpoint Management: CrowdStrike and Microsoft Defender for Endpoint.
- Experience with GCP Security Command Centre, Chronicle.
- Experience with AWS Security Hub including AWS Guard Duty.
- Experience with Microsoft Defender XDR suite.
- Highly self-motivated and proactive individual who wants to learn and grow.
- Attention to detail.
- Willingness to go above and beyond in delighting the customer.
- Good communicator who can explain security concepts to both technical and nontechnical audiences.
Nice to have
- Microsoft Certified: Cybersecurity Architect Expert (SC-100)
- Microsoft Certified: Security Operations Analyst (SC-200)
- AZ-500: Azure Security Engineer
Additional details
- Rackspace Cyber Defence builds on 20+ years of securing customer environments.
- Goal is to go beyond traditional security controls to deliver cloud-native, DevOps-centric, fully integrated 24x7x365 cyber defense capabilities.
- Mission: Proactively detect and respond to cyber-attacks – 24x7x365.
- Mission: Defend against new and emerging risks that impact their business.
- Mission: Reduce their attack surface across private cloud, hybrid cloud, public cloud, and multi-cloud environments.
- Mission: Reduce their exposure to risks that impact their identity and brand.
- Mission: Develop operational resilience.
- Mission: Maintain compliance with legal, regulatory and compliance obligations.
- Rackspace Technology is a multicloud solutions expert combining expertise with technologies across applications, data and security.
- Named a best place to work, year after year according to Fortune, Forbes and Glassdoor.
- Commitment to equal employment opportunity without regard to age, color, disability, gender reassignment or identity or expression, genetic information, marital or civil partner status, pregnancy or maternity status, military or veteran status, nationality, ethnic or national origin, race, religion or belief, sexual orientation, or any legally protected characteristic.
- Accommodation for disability or special needs is available upon request.