Companies/EXL/Vice President (E1) – CybersecurityOperations
EXL
Vice President (E1) – CybersecurityOperations
Pune, Maharashtra, India31 Jul 2026OA6F32
exl/vice-president-e1-cybersecurityoperations
Vice President (E1) – CybersecurityOperations
Job Description
Job Description
Position Title:
Vice President (E1) – Cybersecurity Operations
Function:
Cyber Security
Reports to:
SVP and CISO
Permanent/ Temporary:
Permanent
Span of Control:
Team of in-house subject matter experts and service providers
resources
Location:
Bangalore / Pune / Gurugram / Noida / Hyderabad / Chennai
Role Overview:
We are seeking a forward-thinking Cyber Security Operations Leader to lead and
transform EXL's global Cyber Defense Center capabilities across
mission-critical Security Operations, Threat Detection, Incident Response,
Threat Intelligence, Digital Forensics, Security Automation, AI Security
Monitoring, and Security Operations Assurance.
This role is responsible for evolving EXL's Cyber Defense Center (CDC) into an
intelligence-driven, automation-first, and AI-augmented security operations
capable of protecting a distributed enterprise comprising of cloud-native
systems, Domain Platforms, BPaaS environments, AI-powered solutions, and
critical business operations enabling our clients in regulated industries
including Insurance, Banking & Financial Services, Healthcare, Energy
& Utilities, Travel, and Transportation.
The successful candidate will strengthen modern detection and response
capabilities across traditional Technologies, Engineering Systems, COTs,
Cloud, SaaS, and AI ecosystems while strengthening cyber resilience,
operational robustness, and executive visibility into emerging cyber risks.
This leader will partner closely with Enterprise Security, Cloud Security
Engineering, and Application Security within the Cyber Security functions and
with cross-functions of Cloud Infrastructure, Data & AI teams, Analytics
& AI Services and business stakeholders to continuously improve EXL's
security posture and operational resilience while enabling secure innovation
and digital transformation.
Key Responsibilities:
Security Posture Monitoring, Incident Response, and Crisis Management
Drive established enterprise Incident Response capability, including a
dedicated Computer Incident Response Team (CIRT) with clearly defined roles,
escalation procedures, and communication protocols for both internal and
client-impacting incidents.
Develop, maintain, and regularly test comprehensive incident response
playbooks covering the full spectrum of attack scenarios: ransomware, BEC,
supply chain compromise, insider threats, DDoS, APT intrusions, data
breaches, cloud credential compromise, AI model tampering, and client data
exposure.
Serve as the executive incident commander during major security incidents
(P1/P2), coordinating cross-functional response across Technology, Legal,
Communications, HR, executive leadership, and Industry Security Business
Partners for client-impacting events.
Lead post-incident reviews (PIRs) and blameless retrospectives, ensuring
root cause analysis, lessons learned, and remediation actions are tracked to
closure and fed back into detection engineering, cloud security, and
application security (Pillar 6) improvement cycles.
Build and maintain a digital forensics capability for conducting
investigations across endpoints, servers, cloud workloads, email systems,
containers, and mobile devices.
Establish relationships with external incident response retainers, law
enforcement (FBI Cyber, CISA), and industry ISACs (FS-ISAC, H-ISAC, IT-ISAC)
for coordinated threat response and intelligence sharing.
Threat Intelligence & Proactive Threat Hunting
Build and operationalize a Cyber Threat Intelligence (CTI) program that
collects, analyzes, and disseminates actionable intelligence from OSINT,
commercial feeds (Google Mandiant, CrowdStrike Intel), dark web monitoring,
industry ISACs, and government advisories.
Establish a proactive threat hunting program with dedicated hunters who
develop hypotheses based on threat intelligence, MITRE ATT&CK TTPs, and
environmental anomalies to identify threats that evade automated detection —
including cloud-native and AI-specific hunting scenarios.
AI Security Operations and AI Threat Defense
Establish monitoring, detection, and response capabilities for AI-enabled
applications, LLM platforms, AI agents, RAG architectures, model
repositories, and AI runtime environments.
Develop detection coverage aligned to MITRE ATLAS, OWASP Top 10 for LLM
Applications, and emerging AI threat frameworks.
Lead operational readiness for AI-related incidents including prompt
injection, model abuse, model theft, data leakage, excessive agency,
privilege escalation, and AI supply-chain compromise.
Partner with Secure AI, Application Security, and Cloud Security teams to
continuously improve AI runtime visibility, monitoring, and protection
capabilities.
Managing Cyber Defense Center (CDC) Capability and Operational Leadership
Own and operate a 24x7x365 CDC with tiered analyst structure (L1/L2/L3) and
MSP augmentation, ensuring continuous monitoring, detection, and response
coverage across all enterprise and client-delivery environments globally.
Establish and enforce CDC performance standards including SLA targets for
MTTD.
Drive continuous CDC maturity improvement using SOC-CMM (SOC Capability
Maturity Model), MITRE ATT&CK-based coverage assessments, and formal
capability benchmarking against industry peers.
Manage CDC shift schedules, analyst burnout prevention programs, knowledge
management (runbooks, wiki, playbook library), and cultural initiatives to
sustain high-quality, 24x7 operations.
Detection Engineering and AI-Native Threat Detection
Lead the detection engineering to develop, test, tune, and maintain
detection rules, correlation logic, and behavioral analytics across Nextgen
SIEM (Microsoft Sentinel), EDR, and cloud-native platforms.
Implement a detection-as-code methodology, version-controlling all detection
content in Git, integrating detection rule CI/CD pipelines, and enabling
peer review of detection logic before deployment to production.
Map detection coverage to both MITRE ATT&CK (cloud matrix, enterprise
matrix) and MITRE ATLAS (AI-specific techniques), identifying and closing
coverage gaps across all TTPs relevant to the organization’s data and AI
threat profile.
Drive adoption of AI/ML-powered detection capabilities, including anomaly
detection for cloud API behaviors, entity behavior analytics (UEBA) for
insider threats, LLM-assisted alert triage, and automated alert correlation
to reduce false positive rates by 30%+ year-over-year.
Oversee the deployment, integration, and optimization of the enterprise SIEM
platform (Microsoft Sentinel), EDR/XDR (CrowdStrike, Microsoft Defender).
Develop detection content specifically for AI/ML workload threats: anomalous
GPU utilization patterns, unauthorized model weight access, training data
exfiltration, inference API abuse, and agentic AI permission escalation.
Security Automation & Orchestration (SOAR)
Lead the design and maturity of repetitive CDC workflows using Microsoft
Sentinel and LogicApps to accelerate response times and improve analyst
efficiency across the global SOC operation.
Develop and maintain automated playbooks for common alert types: phishing
triage, malware detonation, account lockout, suspicious cloud API activity,
BPaaS tenant isolation alerts, and AI workload anomaly alerts.
Develop LLM-assisted automation capabilities, including natural language
alert summarization, automated runbook generation from incident patterns,
and AI-powered root cause analysis suggestions.
Measure and report on automation metrics including percentage of alerts
auto-triaged, mean time saved per automated playbook, analyst capacity
reclaimed through automation, and automation-driven false positive
reduction.
Metrics, Reporting & Executive Communication
Develop and maintain a comprehensive Cyber operations metrics and KPI
framework, providing real-time dashboards and monthly/quarterly executive
reports to the CISO, CIO, and board of directors.
Translate operational telemetry, threat data, and incident patterns into
strategic risk narratives that inform executive decision-making, board-level
risk discussions, and security investment prioritization.
Produce client-facing security posture reports demonstrating CDC
capabilities, incident response readiness, and compliance posture for client
due diligence, RFP responses, and contractual attestations.
Manage the security operations budget ($5M-$12M+), including SOC staffing,
MSSP contracts, SIEM/EDR/SOAR licensing, threat intelligence feeds, IR
retainers, and training programs, demonstrating ROI on automation and
tooling investments.
Team Leadership and Organizational Development
Recruit, develop, and retain a world-class security operations team of 20-35
professionals across CDC analysis, detection engineering, incident response,
threat intelligence, forensics, and automation functions, supplemented by
MSSP partners for L1 surge and off-hours coverage.
Establish a continuous training and certification program (SANS GIAC: GCIH,
GCFA, GCIA, GCTI, GSOM; OSCP; BTL1/BTL2; CySA+; cloud security certs) and
invest in hands-on training through cyber range exercises, CTF competitions,
and AI-specific threat simulations.
Primary Internal Interactions:
Works in a consultative fashion with cross-functions EXL teams (HR, Legal,
Global Technology, Compliance) and external partners, advising on technology
issues in a collaborative to improve information security efficiency and
effectiveness.
Primary External Interactions:
Interaction with vendors/OEMs during Design, Implementation and
Troubleshooting, and ongoing service management.
Skills
Technical Skills
Proven track record of managing major security incidents (ransomware, APT,
data breach, cloud credential compromise) from detection through recovery in
environments with 5,000+ employees or equivalent complexity.
Strong Understanding of Cyber Defense & Security Operations.
Security Operations
Incident Response
Threat Hunting
Threat Intelligence
Detection Engineering
Digital Forensics
SOAR
Cloud Security Operations
AWS Security
Azure Security
GCP Security
Container Security
SaaS Security
AI Security Operations
AI Runtime Security
LLM Security Monitoring
Agentic AI Security
AI Threat Detection
MITRE ATLAS
AI Attack Simulation
Frameworks & Standards
MITRE ATT&CK
MITRE ATLAS
NIST CSF
NIST AI RMF
ISO 27001
SOC-CMM
Soft Skills (Minimum)
Ability to handle senior management escalation
Vendor management Skills
Effective communication
Proficient team leader
Business Acumen
Decision making and communication
Risk management skills
Education Requirements
Engineering graduate with certification in CISSP / CCSP, ISO Lead Auditor,
etc.
Work Experience Requirements
15+ years of overall cybersecurity experience spanning Security Operations,
Incident Response, Threat Intelligence, Detection Engineering, Digital
Forensics, and Cyber Defense.
Experience in leading enterprise-scale Security Operations or Cyber Defense
functions.
Experience in operating security programs across large cloud-first enterprises
with global operations.
Demonstrated experience managing major cybersecurity incidents and executive
crisis response.
Experience operationalizing AI-powered security capabilities, threat
detection, automation platforms, and modern SOC transformation initiatives.
Experience securing AI-enabled environments and responding to emerging
AI-related threats.
Annexure:
Acknowledgement (acknowledge that the information contained in this document
is factual and complete).
___________________________________
___________________________________________ ____________________________
Candidate Supervisor/Manager Date
This document is confidential and intended for the use of the individual or
entity to which it is addressed. Any unauthorized review, use, disclosure,
or distribution is prohibited.