Global SOC Specialist - Cybersecurity
Enfinity Global
About Enfinity Global
Enfinity Global is a purpose-driven company focused on making a positive impact on the planet by helping companies, governments and individuals transition to a carbon-free and sustainable economy. As a leading Independent Power Producer (IPP), our role is to develop, finance, build, operate and own renewable energy assets over the long term across Europe, Asia and the Americas, through our offices in the USA, Spain, Italy, UK, Netherlands, India and Japan.
Our team of over 450 Enfiniters comprises seasoned finance professionals, as well as experienced project developers and operators with extensive industry experience across all stages of the project life cycle. We pride ourselves on being creative and innovative solution providers to our customers and partners.
Job Summary
Enfinity is establishing a modern, AI-driven Security Operations Center (SOC) to protect its converged IT and Operational Technology (OT) environment across a distributed portfolio of solar PV and battery energy storage (BESS) plants. The SOC is built around an AI-driven SOC automation platform operating over the Company's converged IT/OT XDR telemetry, which performs continuous, autonomous detection, triage and investigation at scale.
We are seeking a Global SOC Manager, based in Hyderabad, to act as the human-in-the-loop for this AI-driven SOC. This is a global role with end-to-end accountability for SOC monitoring and response across Enfinity's entire converged IT/OT portfolio. The implementation and automation of the platform itself is delivered separately but this role will contribute to its definition and implementation; once it is operational, this role is responsible for supervising day-to-day SOC operations — reviewing and validating the AI platform's findings, investigating escalations, and taking decisive action whenever human judgement and intervention are required.
The role reports to the Senior IT/OT Cybersecurity, Networking and SCADA Manager. Together, the SOC Manager and the Senior Manager provide broad coverage across time zones, so that any alert requiring human action is addressed in a timely manner — complementing the platform's continuous 24/7 automated detection.
The role reports to the Senior IT/OT Cybersecurity, Networking and SCADA Manager, within the Global IT & Cybersecurity (GICT) function.
Key Responsibilities
Human-in-the-loop SOC operations
• Supervise day-to-day SOC operations once the AI-driven platform is operational, owning the quality and outcomes of the SOC's detection and response.
• Review and validate the AI platform's alerts, verdicts and investigations; confirm true positives, dismiss false positives with rationale, and identify cases the automation has under- or over-weighted.
• Take decisive action when human judgement is required — initiating containment, response and remediation, or authorizing/overseeing automated response actions.
• Serve as the global point of accountability for the SOC's operational outcomes, maintaining situational awareness of the threat picture across the entire portfolio.
Incident response & escalation
• Lead investigation and response for escalated and high-severity incidents, coordinating with the USA-based Senior Manager, IT teams, plant O&M and external responders as needed.
• Drive incidents through the full lifecycle — triage, containment, eradication, recovery and post-incident review — with clear documentation and lessons learned.
• Manage handovers between the Global coverage windows so that no incident is dropped across time zones.
OT / ICS security monitoring
• Monitor and respond to security events affecting OT/SCADA and BESS environments across Enfinity's solar plants, applying OT-aware judgement (safety, availability and process impact, not just IT impact).
• Apply and uphold relevant standards and regulatory requirements, including IEC 62443 and NIS2, in monitoring and response decisions.
• Coordinate with the OT security specialist(s) and SCADA/engineering teams on OT-specific detections and response actions.
Platform supervision, tuning & threat hunting
• Oversee the steady-state health and effectiveness of the AI SOC platform — detection coverage, data-source/telemetry health, and integration with the XDR/SIEM and OT monitoring stack.
• Continuously tune detections and automation: feedback false positives/negatives, refine use cases and playbooks, and improve the platform's accuracy over time.
• Conduct proactive threat hunting using the platform's data, going beyond automated alerts to surface stealthy or emerging threats.
• Feed recurring issues and improvement needs to the implementation/automation workstream and to vendors.
Reporting, metrics & compliance
• Track and report SOC performance metrics (e.g. MTTD, MTTR, alert volumes, false-positive rates, incident outcomes) to the Senior Manager and GICT leadership.
• Produce incident and compliance reporting aligned to NIS2 and Enfinity's governance requirements, maintaining an auditable evidence trail.
• Contribute to the continuous improvement of SOC processes, runbooks and escalation procedures.
Requirements
• Bachelor's degree in Computer Science, Information Security, Engineering or a related field (or equivalent practical experience).
• Solid experience in security operations / blue-team roles — alert triage, incident detection and response — including time spent working in or leading a SOC.
• Hands-on experience with SIEM / XDR / SOAR tooling and a strong understanding of detection and response workflows; experience with AI-driven SOC automation platforms (e.g. AIStrike, Strike48, Stellar Cyber, Microsoft Sentinel) is highly valued.
• Strong incident-response skills: investigation, containment, eradication and recovery, with sound judgement on when to act and when to escalate.
• Working knowledge of OT/ICS security and relevant standards (IEC 62443, NIS2), and an appreciation of the safety and availability priorities of industrial/renewable environments.
• Comfort operating as the human-in-the-loop over an AI-driven system — able to trust automation for scale while critically validating its output and remaining accountable for outcomes.
• Willingness and ability to work within an extended / follow-the-sun coverage model (including shifted hours and on-call rotation) to complement the USA-based Senior Manager.
• Strong communication skills and professional working proficiency in English, for close coordination with the USA-based manager and global teams.
• Some supervisory or team-lead experience, with the ability to grow into managing SOC/OT analysts as the team scales.
• Relevant certifications (e.g. GCIA, GCIH, GMON, GCFA, GICSP, CISSP, or equivalent).
• Experience in energy, utilities or other critical-infrastructure environments.
• Familiarity with agentic AI SOC platforms.
• Experience with OT network detection and industrial protocols (e.g. Modbus, DNP3, IEC 61850).
• Experience defining or maintaining SOC playbooks, runbooks and automated response workflows.
Why Join us?
At Enfinity Global you will find a dynamic, multinational environment in one of the most exciting and impactful industries. This role puts you at the centre of a modern, AI-driven security operations capability protecting critical renewable energy infrastructure — combining cutting-edge automation with the judgement of an experienced security professional. We offer competitive compensation, opportunities for professional growth, and the chance to make a real impact on climate change.