Job Description
Position Title, Responsibility Level
| Position Title |
Vice President (E1) – Cybersecurity Operations / Application
security
|
| Function |
Cyber Security / Application security |
| Reports to |
SVP and CISO |
| Permanent/ Temporary |
Permanent |
| Span of Control |
Team of in-house subject matter experts and service providers
resources
|
| Location |
National Capital Region |
Role Overview:
We are seeking a forward-thinking Cyber Security Operations Leader to lead
and transform EXL's global Cyber Defense Center capabilities across
mission-critical Security Operations, Threat Detection, Incident Response,
Threat Intelligence, Digital Forensics, Security Automation, AI Security
Monitoring, and Security Operations Assurance.
This role is responsible for evolving EXL's Cyber Defense Center (CDC) into
an intelligence-driven, automation-first, and AI-augmented security
operations capable of protecting a distributed enterprise comprising of
cloud-native systems, Domain Platforms, BPaaS environments, AI-powered
solutions, and critical business operations enabling our clients in
regulated industries including Insurance, Banking & Financial Services,
Healthcare, Energy & Utilities, Travel and Transportation.
The successful candidate will strengthen modern detection and response
capabilities across traditional Technologies, Engineering Systems, COTs,
Cloud, SaaS, and AI ecosystems while strengthening cyber resilience,
operational robustness, and executive visibility into emerging cyber risks.
This leader will partner closely with Enterprise Security, Cloud Security
Engineering, and Application Security within the Cyber Security functions
and with cross-functions of Cloud Infrastructure, Data & AI teams,
Analytics & AI Services and business stakeholders to continuously
improve EXL's security posture and operational resilience while enabling
secure innovation and digital transformation.
Key Responsibilities:
Security Posture Monitoring, Incident Response and Crisis Management
-
Drive established enterprise Incident Response capability, including a
dedicated Computer Incident Response Team (CIRT) with clearly defined
roles, escalation procedures, and communication protocols for both
internal and client-impacting incidents.
-
Develop, maintain, and regularly test comprehensive incident response
playbooks covering the full spectrum of attack scenarios: ransomware, BEC,
supply chain compromise, insider threats, DDoS, APT intrusions, data
breaches, cloud credential compromise, AI model tampering, and client data
exposure.
-
Serve as the executive incident commander during major security incidents
(P1/P2), coordinating cross-functional response across Technology, Legal,
Communications, HR, executive leadership, and Industry Security Business
Partners for client-impacting events.
-
Lead post-incident reviews (PIRs) and blameless retrospectives, ensuring
root cause analysis, lessons learned, and remediation actions are tracked
to closure and fed back into detection engineering, cloud security, and
application security (Pillar 6) improvement cycles.
-
Build and maintain a digital forensics capability for conducting
investigations across endpoints, servers, cloud workloads, email systems,
containers, and mobile devices.
-
Establish relationships with external incident response retainers, law
enforcement (FBI Cyber, CISA), and industry ISACs (FS-ISAC, H-ISAC,
IT-ISAC) for coordinated threat response and intelligence sharing.
Threat Intelligence & Proactive Threat Hunting
-
Build and operationalize a Cyber Threat Intelligence (CTI) program that
collects, analyzes, and disseminates actionable intelligence from OSINT,
commercial feeds (Google Mandiant, CrowdStrike Intel), dark web
monitoring, industry ISACs, and government advisories.
-
Establish a proactive threat hunting program with dedicated hunters who
develop hypotheses based on threat intelligence, MITRE ATT&CK TTPs,
and environmental anomalies to identify threats that evade automated
detection — including cloud-native and AI-specific hunting scenarios.
AI Security Operations and AI Threat Defense
-
Establish monitoring, detection, and response capabilities for AI-enabled
applications, LLM platforms, AI agents, RAG architectures, model
repositories, and AI runtime environments.
-
Develop detection coverage aligned to MITRE ATLAS, OWASP Top 10 for LLM
Applications, and emerging AI threat frameworks.
-
Lead operational readiness for AI-related incidents including prompt
injection, model abuse, model theft, data leakage, excessive agency,
privilege escalation, and AI supply-chain compromise.
-
Partner with Secure AI, Application Security, and Cloud Security teams to
continuously improve AI runtime visibility, monitoring, and protection
capabilities.
Managing Cyber Defense Center (CDC) Capability and Operational Leadership
-
Own and operate a 24x7x365 CDC with tiered analyst structure (L1/L2/L3)
and MSP augmentation, ensuring continuous monitoring, detection, and
response coverage across all enterprise and client-delivery environments
globally.
-
Establish and enforce CDC performance standards including SLA targets for
MTTD.
-
Drive continuous CDC maturity improvement using SOC-CMM (SOC Capability
Maturity Model), MITRE ATT&CK-based coverage assessments, and formal
capability benchmarking against industry peers.
-
Manage CDC shift schedules, analyst burnout prevention programs, knowledge
management (runbooks, wiki, playbook library), and cultural initiatives to
sustain high-quality, 24x7 operations.
Detection Engineering and AI-Native Threat Detection
-
Lead the detection engineering to develop, testing, tuning, and
maintaining detection rules, correlation logic, and behavioral analytics
across Nextgen SIEM (Microsoft Sentinel), EDR, and cloud-native platforms.
-
Implement a detection-as-code methodology, version-controlling all
detection content in Git, integrating detection rule CI/CD pipelines, and
enabling peer review of detection logic before deployment to production.
-
Map detection coverage to both MITRE ATT&CK (cloud matrix, enterprise
matrix) and MITRE ATLAS (AI-specific techniques), identifying and closing
coverage gaps across all TTPs relevant to the organization’s data and AI
threat profile.
-
Drive adoption of AI/ML-powered detection capabilities, including anomaly
detection for cloud API behaviors, entity behavior analytics (UEBA) for
insider threats, LLM-assisted alert triage, and automated alert
correlation to reduce false positive rates by 30%+ year-over-year.
-
Oversee the deployment, integration, and optimization of the enterprise
SIEM platform (Microsoft Sentinel), EDR/XDR (CrowdStrike, Microsoft
Defender).
-
Develop detection content specifically for AI/ML workload threats:
anomalous GPU utilization patterns, unauthorized model weight access,
training data exfiltration, inference API abuse, and agentic AI permission
escalation.
Security Automation & Orchestration (SOAR)
-
Lead the design and maturity of repetitive CDC workflows using Microsoft
Sentinel and LogicApps to accelerate response times and improve analyst
efficiency across the global SOC operation.
-
Develop and maintain automated playbooks for common alert types: phishing
triage, malware detonation, account lockout, suspicious cloud API
activity, BPaaS tenant isolation alerts, and AI workload anomaly alerts.
-
Develop LLM-assisted automation capabilities, including natural language
alert summarization, automated runbook generation from incident patterns,
and AI-powered root cause analysis suggestions.
-
Measure and report on automation metrics including percentage of alerts
auto-triaged, mean time saved per automated playbook, analyst capacity
reclaimed through automation, and automation-driven false positive
reduction.
Metrics, Reporting & Executive Communication
-
Develop and maintain a comprehensive Cyber operations metrics and KPI
framework, providing real-time dashboards and monthly/quarterly executive
reports to the CISO, CIO, and board of directors.
-
Translate operational telemetry, threat data, and incident patterns into
strategic risk narratives that inform executive decision-making,
board-level risk discussions, and security investment prioritization.
-
Produce client-facing security posture reports demonstrating CDC
capabilities, incident response readiness, and compliance posture for
client due diligence, RFP responses, and contractual attestations.
-
Manage the security operations budget ($5M-$12M+), including SOC staffing,
MSSP contracts, SIEM/EDR/SOAR licensing, threat intelligence feeds, IR
retainers, and training programs, demonstrating ROI on automation and
tooling investments.
Team Leadership and Organizational Development
-
Recruit, develop, and retain a world-class security operations team of
20-35 professionals across CDC analysis, detection engineering, incident
response, threat intelligence, forensics, and automation functions,
supplemented by MSSP partners for L1 surge and off-hours coverage.
-
Establish a continuous training and certification program (SANS GIAC:
GCIH, GCFA, GCIA, GCTI, GSOM; OSCP; BTL1/BTL2; CySA+; cloud security
certs) and invest in hands-on training through cyber range exercises, CTF
competitions, and AI-specific threat simulations.
Primary Internal Interactions:
Works in a consultative fashion with cross-functions EXL teams (HR, Legal,
Global Technology, Compliance) and external partners, advising on technology
issues in a collaborative to improve information security efficiency and
effectiveness.
Primary External Interactions:
Interaction with vendors/ OEMs during Design, Implementation and
Troubleshooting and ongoing service management.
Skills
Technical Skills
-
Proven track record of managing major security incidents (ransomware, APT,
data breach, cloud credential compromise) from detection through recovery
in environments with 5,000+ employees or equivalent complexity.
-
Strong Understanding of Cyber Defense & Security Operations.
-
Security Operations.
-
Incident Response.
-
Threat Hunting.
-
Threat Intelligence.
-
Detection Engineering.
-
Digital Forensics.
- SOAR.
-
Cloud Security Operations.
- AWS Security.
-
Azure Security.
- GCP Security.
-
Container Security.
-
SaaS Security.
-
AI Security Operations.
-
AI Runtime Security.
-
LLM Security Monitoring.
-
Agentic AI Security.
-
AI Threat Detection.
- MITRE ATLAS.
-
AI Attack Simulation.
-
Frameworks & Standards.
-
MITRE ATT&CK.
- MITRE ATLAS.
- NIST CSF.
- NIST AI RMF.
- ISO 27001.
- SOC-CMM.
Soft skills (Minimum)
-
Ability to handle senior management escalation.
-
Vendor management Skills.
-
Effective communication.
-
Proficient team leader.
-
Business Acumen.
-
Decision making and communication.
-
Risk management skill.
Education Requirements
Engineering graduate with certification in CISSP / CCSP, ISO Lead Auditor,
etc.
Work Experience Requirements
15+ years of overall cybersecurity experience spanning Security Operations,
Incident Response, Threat Intelligence, Detection Engineering, Digital
Forensics, and Cyber Defense.
Experience in leading enterprise-scale Security Operations or Cyber Defense
functions.
Experience in operating security programs across large cloud-first
enterprises with global operations.
Demonstrated experience managing major cybersecurity incidents and executive
crisis response.
Experience operationalizing AI-powered security capabilities, threat
detection, automation platforms, and modern SOC transformation initiatives.
Experience securing AI-enabled environments and responding to emerging
AI-related threats.
Annexure:
Acknowledgement (acknowledge that the information contained in this document
is factual and complete)
| Candidate |
Supervisor/Manager |
Date |
| ___________________________________ |
___________________________________ |
____________________________ |
© 2023 EXL | All Rights Reserved