ingrid.fyi India's software hiring trends, explained.
Sign in to ingrid.fyi with Google
Your Google account
name@gmail.com
Continue with Google
Home / Product companies / I · Networking, infrastructure and security / Cybersecurity / SIEM and security operations (SOC)
On this page
SIEM and security operations (SOC) Running the defence yourself, from the security operations centre Every product in the eight Market Segments before this one sends out a stream of alerts:
  • the email gateway
  • the login system
  • the endpoint agent
  • the firewall
  • the cloud posture tool
  • the code scanner
  • the data-loss rules

A large company can receive tens of thousands of alerts a day, and almost all of them are noise. Somebody has to collect them in one place, and work out which few are a real attack in progress. Then they have to act before the attacker finishes. That somebody is the security operations centre, or SOC: a room of security analysts working in shifts, around the clock.

Every alert ends up in one room. The email gateway, the login system, the endpoint agent, the firewall, the cloud posture tool, the code scanner and the data-loss rules all send alerts to the security operations centre. The SIEM keeps one searchable log of everything, with rules and behaviour analytics on top, to find the one real attack among the noise.Every alert ends up in one room. The email gateway, the login system, the endpoint agent, the firewall, the cloud posture tool, the code scanner and the data-loss rules all send alerts to the security operations centre. The SIEM keeps one searchable log of everything, with rules and behaviour analytics on top, to find the one real attack among the noise.

Picture a large bank in Chennai. At 3 a.m., a payroll clerk's account starts downloading the customer database. Among the night's thousands of alerts, this is the one that matters. The SOC has to spot it, stop it, and later work out what happened.

This Market Segment is about the companies that build the software the SOC works on. Their buyers are companies that run their own SOC. The oldest product is the SIEM, short for security information and event management. At bottom, a SIEM is a very large, searchable log of everything that happened, with rules on top that fire when a pattern looks wrong.

It is a small Market Segment, and the largest names in this category are not in it, as the first sub-segment explains. The same job done by an outside company is covered in Market Segment 4.10, Managed security services (MDR and MSSP).

Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.

This Market Segment has three sub-segments:

The record and what feeds it: the SIEM, the behaviour analytics that decide what is abnormal, and the sources that feed them. The playbook: the automation and case tools that turn an alert into a response. After the breach: the forensics that reconstruct what happened. Spot it, stop it, work out what happened. When a payroll clerk's account starts downloading the customer database at 3 a.m., the SIEM and behaviour analytics flag it (Securonix, Gurucul), the playbook stops it automatically (Swimlane, Cyware, AiStrike), and forensics reconstructs the attack afterwards (Oxygen Forensics).Spot it, stop it, work out what happened. When a payroll clerk's account starts downloading the customer database at 3 a.m., the SIEM and behaviour analytics flag it (Securonix, Gurucul), the playbook stops it automatically (Swimlane, Cyware, AiStrike), and forensics reconstructs the attack afterwards (Oxygen Forensics).

Keep reading, free

Three more sections are on this page: The record and what feeds it, The playbook, and After the breach. Sign in to read them here, in full.

Continue with Google
  • The record and what feeds it
  • The playbook
  • After the breach
The record and what feeds it Security information and event management (SIEM), user and entity behaviour analytics (UEBA), the sources that report in

A SIEM takes in logs from every system. It converts them into one common format, and lets an analyst search across years of them in seconds. The modern version adds behaviour analytics, called user and entity behaviour analytics, or UEBA. It learns what each user or server normally does, and flags anything that departs from it.

Take the bank from the start of this Market Segment. Nobody wrote a rule saying "alert when the payroll clerk downloads the customer database at 3 a.m." UEBA flags it anyway, because the clerk has never done anything like it before.

Two companies here build exactly this pairing of SIEM and UEBA. They also have the most job postings in this Market Segment.

Securonixsells Unified Defense SIEM, which combines the log store, the behaviour analytics and the automation layer. It has engineers in Bengaluru and Pune. Since 2025 it has also owned ThreatQuotient, a threat-intelligence platform. Guruculwith engineers in Pune, sells the same combination under the name REVEAL. It started from behaviour analytics, and later built a SIEM around it.

The record is only as good as what reports into it. One company covered mainly in another Market Segment stands for these feeds:

Veherebuilds network detection and response and full packet capture, in Kolkata. Its product produces the network half of the evidence that a SIEM brings together. (More on it in Market Segment 4.5, Network security, firewalls and SASE.)

The physical world also reports into the record, through the door reader and the camera. (More on those in Market Segment 4.15, Physical security, surveillance and trust and safety.)

The largest names in this sub-segment are not here:

  • Splunk, Elastic, Exabeam, LogRhythm and Devo are not covered in this Market Segment.
  • Microsoft Sentinel and Google's security operations products are covered elsewhere. (More on them in Microsoft and Google, in the big-tech collection.)
  • Palo Alto Networks, whose Cortex products compete directly, is covered mainly in Market Segment 4.5, Network security, firewalls and SASE. It also appears in Market Segment 4.6, Cloud and SaaS security.
  • Sumo Logic sells a security version of its log product. Its Indian team works on its observability product, the tools that watch software as it runs. (More on it in Market Segment 6.3, Observability and monitoring platforms, in Industry Vertical 6, Devtools companies.)
The playbook Security orchestration, automation and response (SOAR), threat-intelligence fusion, incident response management

Back to the bank from the start of this Market Segment. The SIEM has fired, and now the analyst has to act:

  • look up where the download is going
  • cut the clerk's laptop off from the network
  • disable the account
  • open a ticket to track the incident
  • tell the right people

Done by hand, this takes an hour. The companies in this sub-segment write the steps down as a playbook, and run it automatically. The industry calls this security orchestration, automation and response, or SOAR.

The playbook, run automatically: look up where the download is going, cut the laptop off from the network, disable the account, open a ticket and tell the right people. Done by hand, this takes an hour.The playbook, run automatically: look up where the download is going, cut the laptop off from the network, disable the account, open a ticket and tell the right people. Done by hand, this takes an hour. Swimlanesells Turbine, a general-purpose automation engine for security operations. It has engineers in Hyderabad. Cywarefrom New York with engineers in Bengaluru, sells a broad version of the idea. It combines three products. A threat-intelligence platform pulls in feeds about known attackers. An orchestration engine runs the playbooks. And a case-management tool tracks the incident itself. Cyware calls this bundle cyber fusion. (More on threat intelligence in Market Segment 4.12, Threat intelligence and attack surface management.) FlexibleIRis a small company that started in Bengaluru and is now headquartered in Singapore. It sells only the playbooks and the war room, the shared space where a team handles an incident. It also runs tabletop exercises, in which a team rehearses a breach before it happens. AiStrikea young company that builds its platform in Pune, shows where this market is going. Its platform uses AI models to do the first sorting of alerts that an analyst used to do, called triage. It decides which alerts matter and drafts the response. It also sells the same capability as a managed service, which puts it with one foot in Market Segment 4.10, Managed security services (MDR and MSSP). The analyst's first pass done by a model.

The scarce resource in a SOC is not the log store, but the person reading it. The newest products in this Market Segment use an AI model to triage every alert first. The human is left with the handful that survive. AiStrike is the example here, along with the automation layers inside Securonix and Gurucul.

You're reading as a guest. Sign in free to follow links for five minutes, once an hour. After the breach Digital forensics and incident response

Back to the bank from the start of this Market Segment. Suppose the attacker got the data out before anyone stopped it. Now the job changes from stopping the attack to reconstructing it:

  • Which machine did the attacker enter first?
  • What was taken?
  • Are the backups clean?

This work is called digital forensics and incident response.

Oxygen Forensicsbuilds the tools for this work. It has engineers in Hyderabad. Its tools extract and analyse data from phones, computers, cloud accounts and backups. It also sells a product that collects data remotely from machines that cannot be brought to the lab, and a tool to examine a live system quickly.

One company here works earlier instead, on investigating alerts:

ThreatLensa small New York company with engineers in Bengaluru, sells a product for investigating alerts. It pairs this with a control over how staff use AI tools.

Ransomware recovery is now the incident most companies rehearse for. Its other half is the backup that has to be restored. (More on backups in Market Segment 7.2, Enterprise storage and backup, in Industry Vertical 7, Database and storage companies.)

So the bank from the start of this Market Segment runs its defence in three steps. The SIEM spots the 3 a.m. download among thousands of alerts. The playbook stops it within minutes. And if the attacker still got through, forensics works out what happened.

Who they hire

Who these companies hire, and for what, is on What cybersecurity hires for.

Privacy Terms Refunds and cancellation Shipping and delivery © 2026 ingrid.fyi · Payments by Razorpay
You're browsing as a guest. Sign in free to follow links for five minutes, once an hour.