Lead - SOC Analyst
- Full-time
Company Description
Organizations everywhere struggle under the crushing costs and complexities of “solutions” that promise to simplify their lives. To create a better experience for their customers and employees. To help them grow. Software is a choice that can make or break a business. Create better or worse experiences. Propel or throttle growth. Business software has become a blocker instead of ways to get work done.
There’s another option. Freshworks. With a fresh vision for how the world works.
At Freshworks, we build uncomplicated service software that delivers exceptional customer and employee experiences. Our enterprise-grade solutions are powerful, yet easy to use, and quick to deliver results. Our people-first approach to AI eliminates friction, making employees more effective and organizations more productive. Over 72,000 companies, including Bridgestone, New Balance, Nucor, S&P Global, and Sony Music, trust Freshworks’ customer experience (CX) and employee experience (EX) software to fuel customer loyalty and service efficiency. And, over 4,500 Freshworks employees make this possible, all around the world.
Fresh vision. Real impact. Come build it with us.
Job Description
We are seeking a highly experienced and forward-thinking Lead SOC Engineer to help drive the next generation of SOC capabilities. This role requires a strong foundation in cloud security, detection engineering, and SOC operations, along with a working knowledge or hands-on experience in AI/ML to support both advanced detection use cases and agentic analyst automation. You will also be responsible for SOAR engineering, particularly with Palo Alto XSOAR, and for ensuring high-quality delivery of SOC BAU (Business-as-Usual) functions.
Key Responsibilities:
Lead SOC engineering efforts, providing technical mentorship and guidance to analysts and junior engineers.
Design and implement cloud-native detection use cases leveraging logs and telemetry from AWS, Azure, and SaaS platforms.
Develop and optimize detection content using SIEM and cloud-native security tools, aligned with frameworks such as MITRE ATT&CK.
Build and apply AI/ML models not only for advanced threat detection but also to automate analyst workflows (agentic analyst automation), such as:
Intelligent alert triage and enrichment
Decision support for incident classification
Contextual correlation across incidents
Summarization and automated reporting
Engineer and automate response workflows using Palo Alto XSOAR, including the development of scalable, reusable playbooks.
Maintain and continuously improve SOC BAU processes — including alert handling, incident response, documentation, and metrics/reporting.
Stay current with evolving threat landscapes, emerging technologies, and innovative applications of AI/ML in cybersecurity.
Qualifications
5+ years of experience in cybersecurity, with at least 2+ years in a senior or lead SOC engineering role.
Hands-on experience in cloud environments (AWS, Azure) with a focus on security monitoring and log analysis.
Proven expertise with SIEM platforms (e.g., Splunk, Sentinel, QRadar) and developing custom detection rules.
Working knowledge or hands-on experience with AI/ML concepts, such as:
Supervised and unsupervised learning
Natural Language Processing (NLP)
Large Language Models (LLMs)
Model evaluation and deployment pipelines
Demonstrated interest or experience in agentic automation — using AI to replicate or augment analyst decision-making.
Strong experience with SOAR tools (preferably Palo Alto XSOAR), including playbook development and automation logic.
Proficiency in scripting languages (e.g., Python, Bash, PowerShell) for automation and integration tasks.
Strong understanding of SOC processes, including incident detection, triage, response, threat hunting, and reporting.
Excellent communication, collaboration, and documentation skills.
Preferred Certifications:
Security certifications: GCIH, GCIA, GCFA, CISSP, CCSP
Cloud certifications: AWS Certified Security Specialty, Azure Security Engineer Associate, or equivalent
SOAR/Automation: Palo Alto XSOAR Certified Engineer (or equivalent)
AI/ML: Certifications or coursework in AI/ML, NLP, or Data Science (Coursera, Google, Microsoft, etc.)
Additional Information
At Freshworks, we have fostered an environment that enables everyone to find their true potential, purpose, and passion, welcoming colleagues of all backgrounds, genders, sexual orientations, religions, and ethnicities. We are committed to providing equal opportunity and believe that diversity in the workplace creates a more vibrant, richer environment that boosts the goals of our employees, communities, and business. Fresh vision. Real impact. Come build it with us.