Job Summary
The Track Lead (Support & Operations) plays a pivotal role in managing security event investigations and implementing technical solutions within the organization. This position focuses on enhancing operational efficiencies, ensuring client satisfaction, and fostering a culture of continuous improvement and innovation among teams. The Track Lead is instrumental in aligning operational goals with organizational objectives while empowering teams to meet client SLAs effectively.
Responsible for proactively identifying, investigating, and mitigating advanced cyber threats that evade traditional, alert‑driven security controls. The role focuses on hypothesis-driven and intelligence-led threat hunting across endpoint, network, identity, and cloud environments to reduce dwell time and enhance detection maturity.
Key Responsibilities
1. Implement And Optimize Soar Solutions To Automate Security Event Investigations, Ensuring Timely And Accurate Incident Response While Enhancing Overall Operational Efficiency.
2. Develop And Maintain Comprehensive Reporting Systems Using Siem Tools To Provide Insights Into Security Incidents And Operational Performance, Facilitating Informed Decision-Making.
3. Lead And Mentor The Support Team By Fostering Transparent Communication Of Project Goals And Encouraging The Adoption Of Best Practices In Security Operations.
4. Collaborate With Clients To Thoroughly Understand Their Security Needs, Ensuring The Support Team Delivers Tailored Solutions That Exceed Client Expectations.
5. Drive Innovation By Identifying Opportunities For Process Improvements And Implementing New Ideas That Enhance The Effectiveness Of Security Operations.
Conduct hypothesis-based and IOC-driven threat hunting across:
Endpoint (EDR/XDR)
SIEM / Log Management platforms
Network telemetry (NDR)
Identity logs (AD / Entra ID)
Cloud platforms (Azure, AWS, M365)
Identify stealthy and advanced threats, including:
Living‑off‑the‑Land (LotL) techniques
Advanced Persistent Threats (APTs)
Lateral movement and privilege escalation
Insider threat indicators
Develop and execute MITRE ATT&CK–aligned hunting hypotheses
Convert hunting findings into:
Security incidents
New detection rules (SIEM / EDR / XDR)
Change or service requests (misconfigurations, logging gaps)
Collaborate with SOC, Incident Response, and Threat Intelligence teams
Produce hunting reports and KPIs (dwell time reduction, hunts to detections, incidents generated)
Skill Requirements
1. Strong Proficiency In Security Event Investigation And Soar Technologies.
2. In-Depth Knowledge Of Siem Tools And Their Application In Operational Environments.
3. Excellent Problem-Solving Abilities And A Strong Understanding Of Client Relationship Management.
4. Proven Leadership Skills With The Ability To Mentor And Empower Teams Effectively.
Strong expertise in SIEM/SOAR platforms (Splunk, Microsoft Sentinel, Chronicle, Palo Alto XSIAM)
Hands-on experience with EDR/XDR tools (Microsoft XDR, CrowdStrike, SentinelOne, Palo Alto Cortex)
Proficiency in KQL / SPL / advanced hunting queries
Deep understanding of MITRE ATT&CK techniques and TTPs
Strong OS knowledge: Windows, Linux, macOS
Basic scripting skills (PowerShell / Python preferred)
Cloud security exposure (Azure, AWS, M365 Defender)