Solution Architect - Security Investigations, SIEM
India
Job Description
Solution Architect - Security Investigations, SIEM
Noida, Uttar Pradesh

Job Summary

Service Owner – Security Operations, Incident Response & Cyber Defense Role Purpose The Service Owner – Security Operations, Incident Response & Cyber Defense is accountable for the strategy, governance, operational effectiveness, and continuous improvement of enterprise cyber defense capabilities. The role owns the roadmap and service direction for security monitoring, threat detection, incident investigation, forensic capabilities, e-discovery support, attack surface management, and managed security services. The Service Owner ensures effective detection, investigation, response, and continuous improvement of cybersecurity threats across the enterprise. The role partners with cybersecurity teams, infrastructure teams, application teams, legal, privacy, risk, compliance, and managed security service providers to strengthen enterprise cyber resilience and support regulatory obligations. Key Responsibilities • Define and maintain the cyber defense and security operations strategy, roadmap, and future-state capability model. • Own the lifecycle management and continuous improvement of security operations capabilities. • Govern enterprise SOC services, including: o Security alert monitoring and triage o Threat detection and analysis o Incident investigation and response o Security event escalation and coordination • Establish and improve incident response processes, playbooks, operating procedures, and lessons-learned practices. • Oversee digital forensic capabilities, including investigation support, evidence handling, and post-incident analysis. • Support e-discovery activities related to cybersecurity incidents, investigations, and legal or regulatory requirements. • Own attack surface management capabilities, including: o External attack surface scanning o Vulnerability exposure identification o Security posture monitoring o Risk-based remediation coordination • Manage MSP/MSSP relationships, service delivery, performance, and continuous improvement initiatives. • Define service KPIs, SLAs, operational metrics, and maturity objectives for security operations capabilities. • Evaluate security operations technologies and recommend improvements to detection, investigation, and response capabilities. • Partner with threat intelligence, vulnerability management, infrastructure, application, and identity teams to improve cyber defense effectiveness. • Ensure security operations capabilities support regulatory, privacy, and healthcare requirements, including HIPAA-related security and incident response obligations where applicable. Required Skills & Experience • 10+ years of experience in cybersecurity operations, cyber defense, incident response, or security engineering. • Experience owning enterprise security operations or managed security capabilities. • Strong understanding of: o SOC operating models o Security monitoring and alert management o Incident investigation and response o Digital forensics concepts o E-discovery processes o Attack surface management and exposure management o Threat detection and analysis • Experience managing MSSP/MSP relationships and security service providers. • Experience defining security operations roadmaps, governance models, and service improvements. • Strong stakeholder management skills across security, technology, legal, privacy, and business teams. • Experience working in regulated environments; healthcare experience and familiarity with HIPAA/security controls is preferred.

Key Responsibilities

Service Owner – Security Operations, Incident Response & Cyber Defense Role Purpose The Service Owner – Security Operations, Incident Response & Cyber Defense is accountable for the strategy, governance, operational effectiveness, and continuous improvement of enterprise cyber defense capabilities. The role owns the roadmap and service direction for security monitoring, threat detection, incident investigation, forensic capabilities, e-discovery support, attack surface management, and managed security services. The Service Owner ensures effective detection, investigation, response, and continuous improvement of cybersecurity threats across the enterprise. The role partners with cybersecurity teams, infrastructure teams, application teams, legal, privacy, risk, compliance, and managed security service providers to strengthen enterprise cyber resilience and support regulatory obligations. Key Responsibilities • Define and maintain the cyber defense and security operations strategy, roadmap, and future-state capability model. • Own the lifecycle management and continuous improvement of security operations capabilities. • Govern enterprise SOC services, including: o Security alert monitoring and triage o Threat detection and analysis o Incident investigation and response o Security event escalation and coordination • Establish and improve incident response processes, playbooks, operating procedures, and lessons-learned practices. • Oversee digital forensic capabilities, including investigation support, evidence handling, and post-incident analysis. • Support e-discovery activities related to cybersecurity incidents, investigations, and legal or regulatory requirements. • Own attack surface management capabilities, including: o External attack surface scanning o Vulnerability exposure identification o Security posture monitoring o Risk-based remediation coordination • Manage MSP/MSSP relationships, service delivery, performance, and continuous improvement initiatives. • Define service KPIs, SLAs, operational metrics, and maturity objectives for security operations capabilities. • Evaluate security operations technologies and recommend improvements to detection, investigation, and response capabilities. • Partner with threat intelligence, vulnerability management, infrastructure, application, and identity teams to improve cyber defense effectiveness. • Ensure security operations capabilities support regulatory, privacy, and healthcare requirements, including HIPAA-related security and incident response obligations where applicable. Required Skills & Experience • 10+ years of experience in cybersecurity operations, cyber defense, incident response, or security engineering. • Experience owning enterprise security operations or managed security capabilities. • Strong understanding of: o SOC operating models o Security monitoring and alert management o Incident investigation and response o Digital forensics concepts o E-discovery processes o Attack surface management and exposure management o Threat detection and analysis • Experience managing MSSP/MSP relationships and security service providers. • Experience defining security operations roadmaps, governance models, and service improvements. • Strong stakeholder management skills across security, technology, legal, privacy, and business teams. • Experience working in regulated environments; healthcare experience and familiarity with HIPAA/security controls is preferred.

Skill Requirements

Service Owner – Security Operations, Incident Response & Cyber Defense Role Purpose The Service Owner – Security Operations, Incident Response & Cyber Defense is accountable for the strategy, governance, operational effectiveness, and continuous improvement of enterprise cyber defense capabilities. The role owns the roadmap and service direction for security monitoring, threat detection, incident investigation, forensic capabilities, e-discovery support, attack surface management, and managed security services. The Service Owner ensures effective detection, investigation, response, and continuous improvement of cybersecurity threats across the enterprise. The role partners with cybersecurity teams, infrastructure teams, application teams, legal, privacy, risk, compliance, and managed security service providers to strengthen enterprise cyber resilience and support regulatory obligations. Key Responsibilities • Define and maintain the cyber defense and security operations strategy, roadmap, and future-state capability model. • Own the lifecycle management and continuous improvement of security operations capabilities. • Govern enterprise SOC services, including: o Security alert monitoring and triage o Threat detection and analysis o Incident investigation and response o Security event escalation and coordination • Establish and improve incident response processes, playbooks, operating procedures, and lessons-learned practices. • Oversee digital forensic capabilities, including investigation support, evidence handling, and post-incident analysis. • Support e-discovery activities related to cybersecurity incidents, investigations, and legal or regulatory requirements. • Own attack surface management capabilities, including: o External attack surface scanning o Vulnerability exposure identification o Security posture monitoring o Risk-based remediation coordination • Manage MSP/MSSP relationships, service delivery, performance, and continuous improvement initiatives. • Define service KPIs, SLAs, operational metrics, and maturity objectives for security operations capabilities. • Evaluate security operations technologies and recommend improvements to detection, investigation, and response capabilities. • Partner with threat intelligence, vulnerability management, infrastructure, application, and identity teams to improve cyber defense effectiveness. • Ensure security operations capabilities support regulatory, privacy, and healthcare requirements, including HIPAA-related security and incident response obligations where applicable. Required Skills & Experience • 10+ years of experience in cybersecurity operations, cyber defense, incident response, or security engineering. • Experience owning enterprise security operations or managed security capabilities. • Strong understanding of: o SOC operating models o Security monitoring and alert management o Incident investigation and response o Digital forensics concepts o E-discovery processes o Attack surface management and exposure management o Threat detection and analysis • Experience managing MSSP/MSP relationships and security service providers. • Experience defining security operations roadmaps, governance models, and service improvements. • Strong stakeholder management skills across security, technology, legal, privacy, and business teams. • Experience working in regulated environments; healthcare experience and familiarity with HIPAA/security controls is preferred.

Other Requirements

Service Owner – Security Operations, Incident Response & Cyber Defense Role Purpose The Service Owner – Security Operations, Incident Response & Cyber Defense is accountable for the strategy, governance, operational effectiveness, and continuous improvement of enterprise cyber defense capabilities. The role owns the roadmap and service direction for security monitoring, threat detection, incident investigation, forensic capabilities, e-discovery support, attack surface management, and managed security services. The Service Owner ensures effective detection, investigation, response, and continuous improvement of cybersecurity threats across the enterprise. The role partners with cybersecurity teams, infrastructure teams, application teams, legal, privacy, risk, compliance, and managed security service providers to strengthen enterprise cyber resilience and support regulatory obligations. Key Responsibilities • Define and maintain the cyber defense and security operations strategy, roadmap, and future-state capability model. • Own the lifecycle management and continuous improvement of security operations capabilities. • Govern enterprise SOC services, including: o Security alert monitoring and triage o Threat detection and analysis o Incident investigation and response o Security event escalation and coordination • Establish and improve incident response processes, playbooks, operating procedures, and lessons-learned practices. • Oversee digital forensic capabilities, including investigation support, evidence handling, and post-incident analysis. • Support e-discovery activities related to cybersecurity incidents, investigations, and legal or regulatory requirements. • Own attack surface management capabilities, including: o External attack surface scanning o Vulnerability exposure identification o Security posture monitoring o Risk-based remediation coordination • Manage MSP/MSSP relationships, service delivery, performance, and continuous improvement initiatives. • Define service KPIs, SLAs, operational metrics, and maturity objectives for security operations capabilities. • Evaluate security operations technologies and recommend improvements to detection, investigation, and response capabilities. • Partner with threat intelligence, vulnerability management, infrastructure, application, and identity teams to improve cyber defense effectiveness. • Ensure security operations capabilities support regulatory, privacy, and healthcare requirements, including HIPAA-related security and incident response obligations where applicable. Required Skills & Experience • 10+ years of experience in cybersecurity operations, cyber defense, incident response, or security engineering. • Experience owning enterprise security operations or managed security capabilities. • Strong understanding of: o SOC operating models o Security monitoring and alert management o Incident investigation and response o Digital forensics concepts o E-discovery processes o Attack surface management and exposure management o Threat detection and analysis • Experience managing MSSP/MSP relationships and security service providers. • Experience defining security operations roadmaps, governance models, and service improvements. • Strong stakeholder management skills across security, technology, legal, privacy, and business teams. • Experience working in regulated environments; healthcare experience and familiarity with HIPAA/security controls is preferred.

Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 223,000 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending June 2026 totaled $14.8 billion.