Director of Cyber Security Operations
HCLSoftware · India
Job Description
Director of Cybersecurity Operations
Location : India - NCR/Bangalore/Remote
About the Role : HCL Software is seeking an accomplished security leader as Director of Cybersecurity Operations to head our cybersecurity operations organization. This role owns four pillars of our defensive and offensive security program: Function Scope Security Operations Center (SOC) 24×7 monitoring, detection, triage, and incident response SOC Engineering Detection engineering, SIEM/SOAR platform ownership, automation, and telemetry pipeline management Vulnerability Management (VM) CTEM, Enterprise-wide exposure identification, risk-based prioritization, and remediation governance Red Team Adversary emulation, offensive testing, and purple-team collaboration with defenders As Director, you will have full ownership of the cybersecurity operations charter: the people (four teams and their leaders, including hiring, development, and succession), the platforms (the SIEM/SOAR/EDR ecosystem and the vulnerability and offensive-security tooling stack), the budget (headcount, tooling, and vendor/MSSP contracts), and the outcomes (detection and response performance, exposure reduction, and validated resilience against real-world attack techniques). You own the operational results end to end and are the accountable voice for them to the CISO and executive leadership. You will lead the continuous maturation of the SOC from a reactive, alert-driven operation toward a proactive, intelligence-led, and engineering-driven function. Establish and execute a maturity roadmap benchmarked against recognized models (e.g., SOC-CMM, NIST CSF), with measurable milestones across people, process, and technology.
Key Responsibilities Strategy & Leadership
• Own the multi-year strategy, roadmap, budget, and SOC, SOC Engineering, Vulnerability Management, and Red Team functions.
• Lead the leadership transition: retain institutional knowledge, stabilize the team, and build succession depth across all four pillars. HCL Software – Internal 1
• Hire, develop, mentor, and retain senior security talent; manage managers and build career paths that reduce burnout and attrition.
• Report security posture, operational metrics, and incident status to the CISO, executive leadership, and (as needed) the board — translating technical risk into business terms. Security Operations & Detection
• Drive continuous improvement of detection and response: reduce mean time to detect/respond (MTTD/MTTR), dwell time, false-positive rates, and alert fatigue.
• Evaluate and govern the responsible adoption of AI/agentic capabilities in the SOC (AI-assisted triage, investigation summarization, automated enrichment) while maintaining human oversight for consequential decisions.
• Own major incident command: lead cross-functional response with IT, engineering, legal, communications, and customer-facing teams; run post-incident reviews and drive lessons learned to closure.
• Assess current-state SOC maturity and publish a multi-year target-state roadmap with quarterly milestones, reporting progress to the CISO.
• Advance detection maturity: move from vendor-default rules to a threat-informed detection engineering lifecycle with MITRE ATT&CK coverage mapping, detection-as-code, versioning, and automated testing.
• Mature triage and response through tiered playbook standardization, SOAR-driven automation of repeatable tasks, and progressive elimination of low-value manual work.
• Evolve metrics from activity-based (alert counts, tickets closed) to outcome-based (MTTD/MTTR, dwell time, detection coverage %, automation rate, true-positive ratio) and use them to drive investment decisions. SOC Engineering & Platform
• Own the SIEM/SOAR/EDR/NDR ecosystem strategy: telemetry coverage, log pipeline cost/quality optimization, use-case lifecycle management, and automation-first workflows.
• Set engineering standards for detections (testing, version control, CI/CD) and playbooks (idempotent, measurable, auditable).
Vulnerability & Exposure Management
• Evolve traditional scan-and-patch VM toward Continuous Threat Exposure Management (CTEM): attack-surface discovery, attack-path analysis, risk-based prioritization tied to exploitability and business impact, and validation of remediation.
• Establish and enforce remediation SLAs with asset and application owners; report exposure-reduction trends to leadership in business-risk language.
• Cover the full estate: cloud (multi-cloud/SaaS), on-prem, endpoints, identities, containers, and the software we ship (partnering with product security/AppSec).
Offensive Security / Red Team
• Set the annual adversary-emulation program: scenario selection informed by threat intelligence and business risk; rules of engagement; safety and legal guardrails.
• Institutionalize purple teaming so red-team findings directly improve detections, playbooks, and control validation. HCL Software – Internal 2
• Extend offensive testing scope to modern targets: cloud, identity/SSO, CI/CD supply chain, and AI/LLM systems.
• Translate findings into prioritized remediation roadmaps with accountable owners — not just reports. Governance & Stakeholder Management
• Align operations to relevant frameworks and obligations (e.g., NIST CSF, ISO 27001, SOC 2, customer contractual commitments) in partnership with GRC.
• Manage key vendor and MSSP/MDR relationships, contracts, and performance. • Partner with product, engineering, IT, and customer success on security matters affecting HCL Software's products and customers.
Required Qualifications
• 12+ years in cybersecurity with 5+ years leading security operations functions (SOC, IR, VM, or offensive security), including experience managing managers and teams of 20+.
• Demonstrated track record maturing a SOC through at least one full transformation cycle — e.g., moving from tiered reactive operations to threat-informed detection engineering, automation, and hunting — with before/after metrics to show for it.
• Demonstrated ownership of each of the four pillars (SOC, detection/SOC engineering, VM, red team) at enterprise scale.
• Proven incident commander for major/severity-1 incidents, including executive and external communications.
• Deep technical grounding: SIEM/SOAR platforms, EDR/NDR, detection engineering practices, MITRE ATT&CK, threat intelligence integration, cloud security operations (AWS/Azure/GCP), and identity-centric attack patterns.
• Track record modernizing vulnerability management toward risk-based/exposure-driven models (CTEM or equivalent) with measurable exposure reduction.
• Experience commissioning, governing, or leading red-team/adversary-emulation programs and converting findings into defensive improvements.
• Executive communication: able to brief C-suite and board audiences, defend budgets, and translate technical risk into business impact.
• Budget ownership experience (tooling, headcount, MSSP/vendor contracts). Preferred Qualifications
• Experience in a software/product development company, understanding the interplay between enterprise security operations and product/customer trust.
• Hands-on familiarity with AI-augmented security operations (agentic triage, LLM-assisted investigation) and with securing/red-teaming AI systems (OWASP LLM Top 10, MITRE ATLAS).
• Experience leading globally distributed teams.
• Familiarity with regulatory/customer assurance contexts common to enterprise software (SOC 2, ISO 27001; FedRAMP exposure a plus). HCL Software – Internal 3
• Certifications valued (not required): CISSP, CISM, GIAC leadership/ops tracks (GSOM, GSOC, GCIH), OSCP/CRTO or equivalent offensive credentials, cloud security certifications. HCL Software – Internal 4
