Project Role : Security Architect
Project Role Description : Define the cloud security framework and architecture, ensuring it meets the business requirements and performance goals. Document the implementation of the cloud security controls and transition to cloud security-managed operations.
Must have skills : Security Information and Event Management (SIEM)
Good to have skills : NA
Minimum
5 year(s) of experience is required
Educational Qualification : 15 years full time education
Summary:
We are seeking a SOC Expert (L3) / Senior Incident Responder to lead advanced incident detection, investigation, containment, and remediation efforts across enterprise environments. This role is responsible for handling high-severity security incidents, coordinating cross-functional response activities, performing deep forensic and threat analysis, and improving incident response capabilities across the SOC.
The ideal candidate brings expert-level domain knowledge in SOC operations and incident response, strong hands-on experience with Red Canary xDR, Microsoft Defender for Endpoint (MDE), and Microsoft Defender for Office 365 (MDO), Firewall (Palo Alto & Cisco) and the ability to translate technical findings into clear risk and remediation guidance for business and technical stakeholders.
Roles & Responsibilities:
-Expected to be an SME for incident response and advanced SOC investigations.
-Lead end-to-end response for high-severity and complex security incidents, including ransomware, credential compromise, APT activity, insider threats, and data exfiltration.
-Perform advanced incident triage, scoping, containment, eradication, and recovery actions across endpoint, identity, email, and cloud environments.
-Conduct deep investigations using Red Canary, MDE, and MDO telemetry.
-Develop, maintain, and execute incident response playbooks and runbooks.
-Perform root cause analysis and produce detailed incident reports and executive summaries.
-Drive threat hunting activities using endpoint, email, and identity telemetry.
-Collaborate with engineering, IT, cloud, and identity teams during incident response activities.
-Provide technical leadership and decision support during active incidents.
-Drive SOC maturity and continuous improvement programs
-Mentor L1 and L2 SOC analysts and guide investigations.
-Facilitate training sessions to enhance team knowledge and SOC maturity.
-Identify detection gaps and recommend improvements in monitoring and response workflows.
-Evaluate and recommend security technologies, detection strategies, and automation opportunities to improve SOC
Professional & Technical Skills:
-Must Have Skills: Expert proficiency in SOC operations and Incident Response
-Strong hands-on experience with:
Red Canary (xDR / MDR platform)
-Microsoft Defender for Endpoint (MDE)
-Microsoft Defender for Office 365 (MDO)
-Strong experience in endpoint, email, identity, cloud, Firewall (Palo Alto & Cisco) incident investigations
-Experience handling enterprise-scale security incidents
-Strong knowledge of Windows security internals and attack techniques
-Experience in threat hunting and detection engineering
-Ability to analyze incidents, determine root causes, and develop mitigation strategies
-Experience implementing SOC playbooks, detection rules, and post-incident reviews
Good to Have: Knowledge of MITRE ATT&CK framework, Experience with SIEM platforms and log analysis, Familiarity with forensic investigation techniques
Additional Information:
- The candidate should have minimum 5 years of experience in Security Information and Event Management (SIEM).
- This position is based at our Bengaluru office.
- A 15 years full time education is required.
15 years full time education
About Accenture
Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.
Visit us at www.accenture.com
Equal Employment Opportunity Statement
We believe that no one should be discriminated against because of their differences. All employment decisions shall be made without regard to age, race, creed, color, religion, sex, national origin, ancestry, disability status, military veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship status or any other basis as protected by applicable law. Our rich diversity makes us more innovative, more competitive, and more creative, which helps us better serve our clients and our communities.