About the job
As the SOC Shift Lead at talworx, you will spearhead our shift operations, driving the management of escalated security incidents while ensuring prompt and precise incident resolution in alignment with defined SLAs. This pivotal role demands a robust technical foundation in SIEM, incident response leadership, and seamless collaboration with cross-functional teams to boost detection capabilities, automation processes, and operational efficiency.
Key Responsibilities
- Conduct comprehensive deep-dive analyses of SIEM alerts escalated by Senior Engineers, ensuring the final resolution of incidents within SLA.
- Correlate data from various log sources to achieve comprehensive threat visibility and guarantee accurate incident resolution.
- Oversee shift operations as the Shift Lead, facilitating effective handovers, task delegation, and ensuring seamless SOC operations.
- Engage in use-case tuning (both production and testing), offering enhancement recommendations based on Business As Usual (BAU) findings.
- Participate actively in playbook design workshops alongside SOAR teams, contributing scenario-based testing and automation recommendations.
- Collaborate closely with developers during requirement-gathering sessions to identify automation and orchestration needs.
- Prepare, review, and maintain critical documentation including Root Cause Analysis (RCA) reports, Incident Response Checklists (IRC), and escalation matrices.
- Ensure audit preparedness by organizing submissions for internal and external regulatory and non-regulatory audits.
- Propose improvements to the Content Management Team aimed at reducing false positives and enhancing detection accuracy.
- Support during major security incidents, including investigations and root cause analysis (RCA).
- Maintain compliance with Mean Time to Resolve (MTTR) metrics and uphold the accuracy and completeness of alert closures.

