
Security Operations Analyst- APAC Blue Team Leader
- Bangalore, Karnataka
- Permanent
- Full-time
- Lead a regional team of cybersecurity professionals focused on threat detection, monitoring, and incident response for IT, OT, and R&D environments.
- Develop and enhance Security Operations Center (SOC) processes, including playbooks, automation, and alert triage.
- Lead and coordinate regional cyber incident response efforts, ensuring timely containment, eradication, and recovery.
- Limited experience in security controls and frameworks tailored for ICS/SCADA, industrial IoT (IIoT), and embedded systems in OT environments.
- Ability to work closely with regional engineering and R&D teams to integrate security into product development lifecycles.
- Ensure compliance with industry regulations and frameworks such as NIST CSF, IEC 62443, and MITRE ATT&CK for ICS.
- Oversee regional vulnerability assessments and risk management programs across IT, OT, and R&D.
- Guide patch management and compensating controls for systems where direct patching is not feasible.
- Work with asset owners to implement segmentation, access controls, and Zero Trust strategies.
- Work closely with regional security and risk leaders to foresee and mitigate risks, ensuring ethical operations and compliance with upcoming regulations.
- Build, mentor, and develop a high-performing regional information security operations team.
- Foster cross-functional collaboration between regional IT, OT, R&D, and security engineering teams.
- Provide executive-level briefings on regional information security risks, incidents, and program improvements.
- Partner with risk management, compliance, and legal teams to align cybersecurity with business objectives.
- 6+ years of experience in cybersecurity with a focus on blue teaming, security operations, and cyber defense.
- Foundational expertise in both IT and OT security, with knowledge of ICS, SCADA, and industrial cyber threats.
- Experience securing R&D environments, including embedded systems, proprietary technologies, and intellectual property.
- Hands-on experience with SIEM, EDR, NDR, threat intelligence platforms, and security automation.
- Knowledge of MITRE ATT&CK (Enterprise & ICS), NIST 800-82, IEC 62443, and Zero Trust principles.
- Experience leading a team of cybersecurity professionals and developing operational security teams.
- Fundamental understanding of cloud security (AWS, Azure, GCP) and hybrid security architectures.
- GIAC Associate Certified Incident Handler
- GIAC Associate Security Operations Certified
- Associate Certified Cloud Security Professional (CCSP)
- AWS Certified Security
- Microsoft SC - 200