Role & responsibilities
The UAT and Production SIEM-DAM environment which needs to be supported in DC & DR.
Continuous Monitoring & Threat Detection
Oversee SOC operations ensuring timely detection and incident response.
Integrate SIEM, SOAR, XDR, IDS/IPS, UEBA, and threat intelligence platforms for advanced monitoring.
Monitor trading and clearing platforms, APIs, and connectivity gateways for anomalies and vulnerabilities.
Track zero-day vulnerabilities, emerging threats, and APTs targeting financial markets.
Incident Response & Crisis Management
Lead incident triage, investigation, containment, and recovery.
Conduct root cause analysis and post-incident reviews to prevent recurrence.
Coordinate major incident response with regulators (SEBI, CERT-In, RBI) and law enforcement.
Conduct red/blue team simulations, tabletop exercises, and cyber drills to validate readiness.
Technology & Process Optimization
Compliance & Regulatory Reporting
Ensure compliance with SEBI CSCRF, CERT-In directives, DPDPA, PCI DSS, ISO 27001.
Prepare and submit mandatory incident reports within required timelines.
Maintain audit-ready documentation and support external/internal audits and risk assessments.
Provide executive dashboards and reports on incidents, threats, and SOC performance.
Threat Intelligence & Proactive Defence
Build and integrate Cyber Threat Intelligence (CTI) programs relevant to financial services.
Implement proactive threat-hunting programs to detect and mitigate risks early.
Collaborate with security architecture and engineering teams to improve detection and prevention.
Preferred candidate profile

Keyskills: Rest Api Integration QRadar FMS Log Parsing Ibm Qradar SIEM-DAM SOAR Understanding