Sr Subject Matter Expert (Support&Ops)
India
Job Description
Sr Subject Matter Expert (Support&Ops)
Delhi, Delhi

Job Summary

Job Description – SOC L3 - SOC Lead
Role Overview
The SOC L3  is responsible for advanced threat detection, incident investigation, and response, handling major security incidents, performing root cause analysis (RCA), and driving security posture improvement. This role also focuses on SIEM use case optimization, threat hunting, and mentoring L1/L2 analysts.

Major Incident Management
Act as Incident Commander for P1/P2 security incidents
Coordinate with cross-functional teams (WinTel, AD, Network, Cloud, Application owners)
Drive war rooms, communication, and stakeholder updates (CISO level)
Ensure timely resolution and service restoration

Key Responsibilities

Key Responsibilities
Incident Investigation & Response

Lead end-to-end investigation of complex security incidents across endpoints, identity, email, and cloud
Perform deep forensic analysis using Microsoft Sentinel, Defender XDR, and other security tools
Execute and coordinate incident containment, eradication, and recovery actions
Validate alerts and reduce false positives through advanced correlation

Skill Requirements

3. Root Cause Analysis (RCA)

Conduct detailed post-incident RCA
Identify attack vectors, gaps, and control failures
Provide actionable recommendations and preventive controls
Prepare executive summaries and technical RCA reports

 

SIEM (Microsoft Sentinel) Engineering

fine-tune detection use cases and analytics rules
Optimize log ingestion, correlation, and alerting logic
Improve signal-to-noise ratio by reducing false positives

 

 

Perform proactive threat hunting using KQL and telemetry data
Map threats using MITRE ATT&CK framework
Identify hidden threats, lateral movement, persistence techniques
Develop and operationalize hunting queries into detections

 

 

MITRE ATT&CK Framework

Apply deep understanding of MITRE ATT&CK techniques (TTPs)
Map incidents and use cases to ATT&CK tactics (Initial Access, Lateral Movement, etc.)
Improve coverage by identifying detection gaps

 

Mentoring & Leadership

Provide guidance and mentoring to L1/L2 analysts
Review investigations and improve team capabilities
Conduct knowledge sharing sessions and training workshops

 

Documentation & Process Improvement

 

Develop and maintain:

 

SOPs (Standard Operating Procedures)
Runbooks / Playbooks
Knowledge Base (KB) articles

Drive SOC maturity and process standardization
Support audits and compliance requirements

 

Technical Skills Required

Strong expertise in:

 

Microsoft Sentinel (SIEM)
Microsoft Defender XDR (MDE, MDO, Identity, Cloud Apps)

Advanced KQL (Kusto Query Language)
Incident handling tools & EDR platforms
Understanding of:

 

Windows internals & logs
Identity (AD, Azure AD)
Email security (phishing, spoofing)
Network security concepts

 

 

Soft Skills

Strong analytical and problem-solving skills
Excellent communication (technical + executive level)
Ability to handle high-pressure incident scenarios
Strong coordination and stakeholder management

Other Requirements

null
Information at a Glance

Why HCLTech?

At HCLTech, you'll supercharge your potential. You'll find your career. And you'll find your spark. All at a place that knows that helping its customers stay on top starts by putting its people first.

HCLTech is a global technology company, home to more than 226,300 people across 60 countries, delivering industry-leading capabilities centered around digital, engineering, cloud and AI, powered by a broad portfolio of technology services and products. We work with clients across all major verticals, providing industry solutions for Financial Services, Manufacturing, Life Sciences and Healthcare, Technology and Services, Telecom and Media, Retail and CPG, and Public Services. Consolidated revenues as of 12 months ending December 2025 totaled $14.5 billion.

23 Benefits At HCLTech, we believe in empowering our employees with comprehensive benefits that support their professional growth and enhance their well-being. When you sign up for a career with us, you gain access to: https://rmkcdn.successfactors.com/147eb21f/a701dca9-f32d-4fc9-9447-6.svg Industry-benchmarked compensation https://rmkcdn.successfactors.com/147eb21f/b0c54381-ddcc-4a33-9b35-9.svg Best-in-class healthcare benefits https://rmkcdn.successfactors.com/147eb21f/b73027be-7aae-4d36-a090-4.svg Personal time off https://rmkcdn.successfactors.com/147eb21f/d5b4fdfd-2e99-4e26-9878-9.svg Maternity and paternity benefits https://rmkcdn.successfactors.com/147eb21f/3d42b0fc-4652-435a-9ece-c.svg Access to skills / higher education programs/resources https://rmkcdn.successfactors.com/147eb21f/aeddeaf2-9e25-4584-ad11-d.svg Discounts on products and services via Benefit Box https://rmkcdn.successfactors.com/147eb21f/a9609a3b-2700-4b3c-9d90-a.svg Participate in CSR programs and live life with a purpose https://rmkcdn.successfactors.com/147eb21f/c6e33851-710f-4634-bd69-f.svg Opportunities to grow and advance your career Note: The benefits listed above vary depending on the nature of your employment and the country where you work. Some benefits may be available in some countries but not in all.