ingrid.fyi India's software hiring trends, explained.
Sign in to ingrid.fyi with Google
Your Google account
name@gmail.com
Continue with Google
Home / Product companies / I · Networking, infrastructure and security / Cybersecurity / Managed security services (MDR and MSSP)
On this page
Managed security services (MDR and MSSP) Having someone else run the defence, around the clock Market Segment 4.9, SIEM and security operations (SOC), described the room: a security operations centre (SOC), with analysts working in shifts, a log store and a playbook. Most companies cannot staff that room. Even the large ones struggle to hire enough analysts to keep up.

Picture a 400-person logistics company in Ahmedabad with two security people. At 3 a.m., an alert fires on a warehouse laptop. Nobody at the company is awake to read it.

This Market Segment is about the companies that rent out the room. They plug into a customer's endpoint agents, firewalls and cloud accounts. They watch the alerts around the clock from their own centre. When something is real, they call the customer, or act for it. Their buyers are companies like the logistics company, which cannot run a SOC of their own.

Renting the room. The logistics company's endpoint agents, firewalls and cloud accounts send their alerts to a contractor's security operations centre, such as Arctic Wolf, Deepwatch, Critical Start or eSentire, whose analysts watch around the clock and call the customer or act for it.Renting the room. The logistics company's endpoint agents, firewalls and cloud accounts send their alerts to a contractor's security operations centre, such as Arctic Wolf, Deepwatch, Critical Start or eSentire, whose analysts watch around the clock and call the customer or act for it.

The business has two names, an older one and a newer one:

Managed security service provider (MSSP)the older model, which mostly forwarded alerts to the customer. Managed detection and response (MDR)the current model, which promises to investigate the incident and contain it, not just report it.

Every company here is headquartered outside India, and is in India for its engineering and its analysts. Indian services firms also run the same business for their clients. (More on them in the services-world collection.)

Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.

This Market Segment has two sub-segments:

The contractor's SOC: the companies whose product is the watching itself. The platform between you and the contractor: one company whose product is a layer over a customer's existing tools, which either side can run.

Keep reading, free

Two more sections are on this page: The contractor's SOC and The platform between you and the contractor. Sign in to read them here, in full.

Continue with Google
  • The contractor's SOC
  • The platform between you and the contractor
The contractor's SOC Managed detection and response, managed endpoint detection, managed SIEM

Back to the logistics company from the start of this Market Segment. Its contractor's analysts see the 3 a.m. alert, check it, and act. Four companies here sell this watching as a service.

Arctic Wolfis by far the largest of them, and has engineers in Bengaluru. It began as a managed detection provider. It has grown into a bundle that adds vulnerability and risk management, cloud posture management and security-awareness training. A named team of its own analysts is assigned to each customer. Deepwatchalso with engineers in Bengaluru, is the purer version of the same idea. It sells managed detection and response, managed endpoint detection, and a vulnerability service. Critical Startfrom Texas with engineers in Pune, promises to check every alert before it reaches the customer. So the customer sees only the alerts that matter. It also sells a managed SIEM, for customers who own the log store but not the people to read it. eSentirethe oldest of them, runs its service on its own platform, called Atlas. It offers Atlas as a way for the customer to avoid owning a SIEM at all.

All four sell a contract, not a software licence. The customer keeps its endpoint agent and its firewall, and the contractor reads what those produce. (More on them in Market Segment 4.4, Endpoint security and device management, and Market Segment 4.5, Network security, firewalls and SASE.)

One question decides this market: who acts? The older service told the customer about the alert. The newer one cuts the laptop off from the network itself. The companies here compete on how far they will go without asking the customer first.

Who acts? The older managed security service forwards the alert to the customer. Managed detection and response investigates it and contains it, for example by cutting the laptop off from the network. The companies compete on how far they will go without asking the customer first.Who acts? The older managed security service forwards the alert to the customer. Managed detection and response investigates it and contains it, for example by cutting the laptop off from the network. The companies compete on how far they will go without asking the customer first.
The platform between you and the contractor Unified security operations platform, threat detection, investigation and response, exposure management

Back to the logistics company from the start of this Market Segment. Suppose its two security people want to handle the day shift themselves, and hand the nights to a contractor. One company here sells what that needs.

ReliaQuestfrom Tampa with engineers in Pune, sells something the other four do not. Its GreyMatter platform sits above whatever tools a customer already owns, whoever made them. It pulls their alerts together and automates the triage, the first sorting of alerts. A customer can run its own SOC on it, hire ReliaQuest to run it, or do a bit of each. One platform, two shifts. ReliaQuest's GreyMatter sits above the endpoint agent, the firewall and the cloud tools a customer already owns, pulls their alerts together and automates the triage. The company's own team can run the day shift on it while ReliaQuest runs the nights.One platform, two shifts. ReliaQuest's GreyMatter sits above the endpoint agent, the firewall and the cloud tools a customer already owns, pulls their alerts together and automates the triage. The company's own team can run the day shift on it while ReliaQuest runs the nights.

The industry calls a layer like this a unified security operations platform. It covers the whole path from spotting a threat to investigating it and responding. It often also covers exposure management: finding and ranking the weak spots an attacker could use. (More on exposure management in Market Segment 4.11, Vulnerability management and penetration testing.)

ReliaQuest is the answer for a customer who does not want to choose between Market Segment 4.9 and this one. It also shows where this whole Market Segment is heading. The difference between a product and a service is becoming a line in the contract, not a difference in the software.

The model as the first analyst.

Every company in this Market Segment sells human attention. Every one of them is now building AI models to do the first read of each alert, so the humans handle fewer. The contractors' business depends on it. A contractor sees more alerts than any single customer does. So this Market Segment will show what AI models can do in a SOC before Market Segment 4.9 does.

So the logistics company from the start of this Market Segment does not need a SOC of its own. It can rent the whole room from a contractor, or run part of it itself on a shared platform.
Who they hire

Who these companies hire, and for what, is on What cybersecurity hires for.

Privacy Terms Refunds and cancellation Shipping and delivery © 2026 ingrid.fyi · Payments by Razorpay
You're browsing as a guest. Sign in free to follow links for five minutes, once an hour.