Skip to content

Open nowPosted 46 days ago

Global SOC Specialist - Cybersecurity

Workable (global search)108,016 open roles

Where
Hyderabad, TS, India
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowGlobal SOC Specialist - CybersecurityWorkable (global search) · Hyderabad, TS, India
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 46 days ago

Workable (global search) median: 7 days open

The posting

About Enfinity Global

Enfinity Global is a purpose-driven company focused on making a positive impact on the planet by helping companies, governments and individuals transition to a carbon-free and sustainable economy. As a leading Independent Power Producer (IPP), our role is to develop, finance, build, operate and own renewable energy assets over the long term across Europe, Asia and the Americas, through our offices in the USA, Spain, Italy, UK, Netherlands, India and Japan.

Our team of over 450 Enfiniters comprises seasoned finance professionals, as well as experienced project developers and operators with extensive industry experience across all stages of the project life cycle. We pride ourselves on being creative and innovative solution providers to our customers and partners.

Job Summary

Enfinity is establishing a modern, AI-driven Security Operations Center (SOC) to protect its converged IT and Operational Technology (OT) environment across a distributed portfolio of solar PV and battery energy storage (BESS) plants. The SOC is built around an AI-driven SOC automation platform operating over the Company's converged IT/OT XDR telemetry, which performs continuous, autonomous detection, triage and investigation at scale.

We are seeking a Global SOC Manager, based in Hyderabad, to act as the human-in-the-loop for this AI-driven SOC. This is a global role with end-to-end accountability for SOC monitoring and response across Enfinity's entire converged IT/OT portfolio. The implementation and automation of the platform itself is delivered separately but this role will contribute to its definition and implementation; once it is operational, this role is responsible for supervising day-to-day SOC operations — reviewing and validating the AI platform's findings, investigating escalations, and taking decisive action whenever human judgement and intervention are required.

The role reports to the Senior IT/OT Cybersecurity, Networking and SCADA Manager. Together, the SOC Manager and the Senior Manager provide broad coverage across time zones, so that any alert requiring human action is addressed in a timely manner — complementing the platform's continuous 24/7 automated detection.

The role reports to the Senior IT/OT Cybersecurity, Networking and SCADA Manager, within the Global IT & Cybersecurity (GICT) function.

Key Responsibilities

Human-in-the-loop SOC operations

• Supervise day-to-day SOC operations once the AI-driven platform is operational, owning the quality and outcomes of the SOC's detection and response.

• Review and validate the AI platform's alerts, verdicts and investigations; confirm true positives, dismiss false positives with rationale, and identify cases the automation has under- or over-weighted.

• Take decisive action when human judgement is required — initiating containment, response and remediation, or authorizing/overseeing automated response actions.

• Serve as the global point of accountability for the SOC's operational outcomes, maintaining situational awareness of the threat picture across the entire portfolio.

Incident response & escalation

• Lead investigation and response for escalated and high-severity incidents, coordinating with the USA-based Senior Manager, IT teams, plant O&M and external responders as needed.

• Drive incidents through the full lifecycle — triage, containment, eradication, recovery and post-incident review — with clear documentation and lessons learned.

• Manage handovers between the Global coverage windows so that no incident is dropped across time zones.

OT / ICS security monitoring

• Monitor and respond to security events affecting OT/SCADA and BESS environments across Enfinity's solar plants, applying OT-aware judgement (safety, availability and process impact, not just IT impact).

• Apply and uphold relevant standards and regulatory requirements, including IEC 62443 and NIS2, in monitoring and response decisions.

• Coordinate with the OT security specialist(s) and SCADA/engineering teams on OT-specific detections and response actions.

Platform supervision, tuning & threat hunting

• Oversee the steady-state health and effectiveness of the AI SOC platform — detection coverage, data-source/telemetry health, and integration with the XDR/SIEM and OT monitoring stack.

• Continuously tune detections and automation: feedback false positives/negatives, refine use cases and playbooks, and improve the platform's accuracy over time.

• Conduct proactive threat hunting using the platform's data, going beyond automated alerts to surface stealthy or emerging threats.

• Feed recurring issues and improvement needs to the implementation/automation workstream and to vendors.

Reporting, metrics & compliance

• Track and report SOC performance metrics (e.g. MTTD, MTTR, alert volumes, false-positive rates, incident outcomes) to the Senior Manager and GICT leadership.

• Produce incident and compliance reporting aligned to NIS2 and Enfinity's governance requirements, maintaining an auditable evidence trail.

• Contribute to the continuous improvement of SOC processes, runbooks and escalation procedures.

Requirements

• Bachelor's degree in Computer Science, Information Security, Engineering or a related field (or equivalent practical experience).

• Solid experience in security operations / blue-team roles — alert triage, incident detection and response — including time spent working in or leading a SOC.

• Hands-on experience with SIEM / XDR / SOAR tooling and a strong understanding of detection and response workflows; experience with AI-driven SOC automation platforms (e.g. AIStrike, Strike48, Stellar Cyber, Microsoft Sentinel) is highly valued.

• Strong incident-response skills: investigation, containment, eradication and recovery, with sound judgement on when to act and when to escalate.

• Working knowledge of OT/ICS security and relevant standards (IEC 62443, NIS2), and an appreciation of the safety and availability priorities of industrial/renewable environments.

• Comfort operating as the human-in-the-loop over an AI-driven system — able to trust automation for scale while critically validating its output and remaining accountable for outcomes.

• Willingness and ability to work within an extended / follow-the-sun coverage model (including shifted hours and on-call rotation) to complement the USA-based Senior Manager.

• Strong communication skills and professional working proficiency in English, for close coordination with the USA-based manager and global teams.

• Some supervisory or team-lead experience, with the ability to grow into managing SOC/OT analysts as the team scales.

• Relevant certifications (e.g. GCIA, GCIH, GMON, GCFA, GICSP, CISSP, or equivalent).

• Experience in energy, utilities or other critical-infrastructure environments.

• Familiarity with agentic AI SOC platforms.

• Experience with OT network detection and industrial protocols (e.g. Modbus, DNP3, IEC 61850).

• Experience defining or maintaining SOC playbooks, runbooks and automated response workflows.

Why Join us?

At Enfinity Global you will find a dynamic, multinational environment in one of the most exciting and impactful industries. This role puts you at the centre of a modern, AI-driven security operations capability protecting critical renewable energy infrastructure — combining cutting-edge automation with the judgement of an experienced security professional. We offer competitive compensation, opportunities for professional growth, and the chance to make a real impact on climate change.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.