SOC Lead
ChargePoint · Gurgaon
- Experience6–7 yrs
- SalaryNot disclosed
- Work moderemote
- Posted1 Oct 2026
About ChargePoint
ChargePoint is hiring in Gurgaon in automotive mobility. This role looks for around 6+ years of experience.
Skills
- Incident response
- Threat hunting
- MITRE ATT&CK
- EDR
- SIEM
- SOAR
- DLP
- Cloud security
- Python
- PowerShell
- KQL
- Kill chain methodology
- Adversary emulation
The role
A SOC lead at an electric vehicle charging company coordinates incident response and threat hunting using MITRE ATT&CK, then engineers SIEM/SOAR detections and playbooks. The role also applies cloud security and Python automation to strengthen defenses.
Full job description
About Us
With electric vehicles expected to be nearly 30% of new vehicle sales by 2025 and more than 50% by 2040, electric mobility is becoming a reality. ChargePoint (NYSE: CHPT) is at the center of this revolution, powering one of the world's leading EV charging networks and a comprehensive set of hardware, software and mobile solutions for every charging need across North America and Europe. We bring together drivers, businesses, automakers, policymakers, utilities and other stakeholders to make e-mobility a global reality.
Since our founding in 2007, ChargePoint has focused solely on making the transition to electric easy for businesses, fleets and drivers. ChargePoint offers a once-in-a-lifetime opportunity to create an all-electric future and a trillion-dollar market.
At ChargePoint, we foster a positive and productive work environment by committing to live our values of Be Courageous, Charge Together, Love our Customers, Operate with Openness, and Relentlessly Pursue Awesome. These values guide how we show up every day, align, and work together to build a brighter future for all of us.
Join the team that is building the EV charging industry and make your mark on how people and goods will get everywhere they need to go, in any context, for generations to come.
Reports To
Staff, Security Operations
What You Will Be Doing
As the SOC Lead, you will be a critical defender of ChargePoint's global infrastructure, acting as the primary escalation point for advanced security incidents. Operating as a high-level individual contributor, you will lead incident response efforts, drive proactive threat hunting, and mature our detection engineering capabilities. You will play a vital role in protecting ChargePoint against advanced threats while mentoring a team of SOC analysts, optimizing our automated playbooks, and collaborating with cross-functional stakeholders and external MDR partners to ensure a robust security posture.
What You Will Bring to ChargePoint
Manage and coordinate incident response from detection through containment, eradication, and post-incident review. Own P1/P2 escalations, drive root cause analysis, and ensure timely stakeholder communication.
Design and execute proactive threat hunting campaigns using endpoint, network, and cloud telemetry. Consume and operationalize threat intelligence (MITRE ATT&CK, OSINT, vendor feeds) to stay ahead of adversary TTPs.
Own the SIEM content lifecycle: build, tune, and maintain detection rules, correlation logic, and dashboards. Reduce alert fatigue through continuous tuning and signal-to-noise improvement.
Develop and automate SOC playbooks and runbooks using SOAR capabilities. Drive measurable improvements in mean time to detect (MTTD) and mean time to respond (MTTR).
Oversee data exfiltration monitoring across USB, cloud uploads, email, and AI tools. Lead weekly review cycles and coordinate with PeopleOps/ER on escalation cases.
Mentor and develop SOC analysts. Conduct regular skill-building sessions, tabletop exercises, and purple team engagements. Foster a culture of curiosity, ownership, and continuous improvement.
Manage the relationship with MDR providers and security tool vendors. Validate escalations, provide feedback on detection quality, and drive SLA accountability.
Requirements
6+ years of experience in a SOC, Incident Response, or Threat Hunting role, with at least 2 years in a lead or senior analyst capacity.
Deep hands-on experience with EDR, SIEM/SOAR platforms, DLP tools, and cloud security.
Strong understanding of the MITRE ATT&CK framework, kill chain methodology, and adversary emulation techniques.
Experience investigating nation-state threats, business email compromise, insider threats, and supply chain attacks.
Proficiency in scripting/automation (Python, PowerShell, KQL, or similar) for detection engineering and workflow automation.
Excellent communication skills for cross-functional coordination with Legal, PeopleOps, and IT stakeholders.
Bachelor's degree or equivalent experience.
Certifications: Relevant certifications preferred, such as GCIH, GCFA, GCIA, OSCP, CySA+, or equivalent hands-on certifications.
Location
Gurgaon/Remote
We are committed to an inclusive and diverse team. ChargePoint is an equal opportunity employer. We do not discriminate based on race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status or any legally protected status.
If there is a match between your experiences/skills and the Company needs, we will contact you directly.
ChargePoint is committed to fostering an inclusive workplace that welcomes and supports all qualified individuals. In alignment with this commitment, we ensure that persons with disabilities are provided with reasonable accommodations throughout the employment process.
If you need a reasonable accommodation to participate in the application or interview process, to perform essential job functions, or to access any other benefits and privileges of employment, please contact us at accommodations@chargepoint.com.
ChargePoint is an equal opportunity employer.
Applicants only - Recruiting agencies do not contact.