Mattel

Retail

ITSecurityOpsSpecialist

Hyderabad, India FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for mid candidates.

The Brief

“IT Security Ops Specialist at Mattel. Skills: SOC Operations, Threat Hunting & Intelligence, Detection Engineering & Continuous Improvement, Incident Response. Provide technical leadership and direct oversight of SOC Analysts. Ensure 24x7 coverage, timely response to incidents, and adherence to operational procedures”

What You'll Achieve.

24x7 coverage; Timely response to incidents; Adherence to operational procedures; Rapid containment, eradication, and recovery of confirmed threats; Actionable detections and controls from hunt findings; Reduced manual processes through automation; Key SOC performance metrics (MTTD, MTTC, Threat Hunt Success Rate, Detection Rule Effectiveness, False Positive Reduction, Coverage of Critical Assets); Visibility across the environment; Alignment with security frameworks

Industry & Context.

Retail
Problems you'll solve

Ability to analyze large datasets and develop actionable security insights; Incident analysis; Threat containment, eradication, and recovery

Eligibility Requirements

Participate in after-hours rotations or on-call duties

What They're Looking For.

Must Have

10+ years of experience in cybersecurity operations, 5+ years in a SOC Tech Lead or senior SOC engineering role, Proven experience in incident response, including detection, investigation, containment, and remediation, expertise in SIEM, SOAR, EDR, Network Detection & Response (NDR), including ExtraHop, IDS/IPS and firewall technologies, Hands-on experience with threat hunting and detection engineering, understanding of MITRE ATT&CK, NIST 800-61, and incident response frameworks, Experience integrating threat intelligence (e.g. , Recorded Future) into detection workflows, knowledge of Windows, Linux, and network protocols, Ability to analyze large datasets and develop actionable security insights, Excellent leadership, communication, and cross-functional collaboration skills

Nice to Have

Bachelor’s degree in Cybersecurity, Information Technology, or related field, Certifications: GCIH, CISSP, CISM, CEH, or equivalent, Experience with CrowdStrike, SentinelOne, Microsoft Defender, Sumo Logic or other SIEM platforms, SOAR automation and API integrations, Scripting/automation (Python, PowerShell), Experience building threat hunting programs and detection pipelines

What You'll Do.

Provide technical leadership and direct oversight of SOC Analysts

timely response to incidents

and adherence to operational procedures

Lead daily SOC operations

including real-time monitoring

Serve as a key escalation point for complex or high-severity security incidents

Handle confirmed threats received from MDR SOC and drive remediation efforts

Participate in after-hours rotations or on-call duties

Define monthly and quarterly threat hunting themes

Develop hunt hypotheses using Recorded Future and internal telemetry

Lead proactive threat hunting using Recorded Future

Perform threat actor attribution and risk analysis

Track hunt outcomes and convert findings into actionable detections and controls

Drive detection improvements across tools (SIEM

Reduce manual processes through automation

and SOAR integrations

Oversee the configuration

and maintenance of SOC tools

Lead development and enhancement of SOC playbooks

and report key SOC performance metrics

Identify and report visibility gaps across the environment

Provide regular reporting on incident trends

Investigate high-severity incidents escalated by MDR

Coordinate with infrastructure

and application teams for investigation and remediation

Ensure alignment with security frameworks (MITRE ATT&CK

How You'll Work.

Team & Collaboration

Coordinate with infrastructure, network, identity, and application teams for investigation and remediation; Collaborate with shared values and common goals; Work closely together to bring better results; Partnership is our process

Communication Scope

Excellent communication skills; Provide regular reporting on incident trends, threat activity, and SOC performance

Full Job Description

CREATIVITY IS OUR SUPERPOWER. It’s our heritage and it’s also our future. Because we don’t just make toys. We create innovative products and experiences that inspire fans, entertain audiences and develop children through play. Mattel is at its best when every member of our team feels respected, included, and heard—when everyone can show up as themselves and do their best work every day. We value and share an infinite range of ideas and voices that evolve and broaden our perspectives with a reach that extends into all our brands, partners, and suppliers. SOC Operations * Provide technical leadership and direct oversight of SOC Analysts, ensuring 24x7 coverage, timely response to incidents, and adherence to operational procedures * Lead daily SOC operations, including real-time monitoring, alert triage, incident analysis, and escalation * Serve as a key escalation point for complex or high-severity security incidents, ensuring rapid containment, eradication, and recovery * Handle confirmed threats received from MDR SOC and drive remediation efforts * Participate in after-hours rotations or on-call duties to support critical incident response as needed. Threat Hunting & Intelligence * Define monthly and quarterly threat hunting themes aligned to business risk and threat landscape * Develop hunt hypotheses using Recorded Future and internal telemetry * Lead proactive threat hunting using Recorded Future, SIEM, EDR, and NDR telemetry * Perform threat actor attribution and risk analysis based on intelligence and observed activity * Track hunt outcomes and convert findings into actionable detections and controls Detection Engineering & Continuous Improvement * Drive detection improvements across tools (SIEM, EDR, NDR, Identity platforms) * Reduce manual processes through automation, scripting, and SOAR integrations * Oversee the configuration, tuning, and maintenance of SOC tools including: * SIEM (Sumo Logic, CrowdStrike Falcon Next-Gen SIEM) * EDR * IDS/IPS * NDR solutio

Free ATS check

Applying for this IT Security Ops Specialist role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on SmartRecruiters

  • SmartRecruiters often includes a video screening step — check camera and mic permissions.
  • Link your GitHub or portfolio directly in the profile section for technical roles.
  • Applications may be reviewed by AI scoring before reaching a recruiter — use keywords from the job description.

ANONYMOUS · UNFILTERED

What do employees actually say about Mattel?

Real rants from real employees. Read before you apply.

Read Company Rants →