- the email gateway
- the login system
- the endpoint agent
- the firewall
- the cloud posture tool
- the code scanner
- the data-loss rules
A large company can receive tens of thousands of alerts a day, and almost all of them are noise. Somebody has to collect them in one place, and work out which few are a real attack in progress. Then they have to act before the attacker finishes. That somebody is the security operations centre, or SOC: a room of security analysts working in shifts, around the clock.

Picture a large bank in Chennai. At 3 a.m., a payroll clerk's account starts downloading the customer database. Among the night's thousands of alerts, this is the one that matters. The SOC has to spot it, stop it, and later work out what happened.
This Market Segment is about the companies that build the software the SOC works on. Their buyers are companies that run their own SOC. The oldest product is the SIEM, short for security information and event management. At bottom, a SIEM is a very large, searchable log of everything that happened, with rules on top that fire when a pattern looks wrong.
It is a small Market Segment, and the largest names in this category are not in it, as the first sub-segment explains. The same job done by an outside company is covered in Market Segment 4.10, Managed security services (MDR and MSSP).
Every company named here has posted software engineering jobs in India. Famous companies that don't actively hire software engineers in India are left out.
This Market Segment has three sub-segments:

Keep reading, free
Three more sections are on this page: The record and what feeds it, The playbook, and After the breach. Sign in to read them here, in full.
Continue with Google- The record and what feeds it
- The playbook
- After the breach
A SIEM takes in logs from every system. It converts them into one common format, and lets an analyst search across years of them in seconds. The modern version adds behaviour analytics, called user and entity behaviour analytics, or UEBA. It learns what each user or server normally does, and flags anything that departs from it.
Take the bank from the start of this Market Segment. Nobody wrote a rule saying "alert when the payroll clerk downloads the customer database at 3 a.m." UEBA flags it anyway, because the clerk has never done anything like it before.
Two companies here build exactly this pairing of SIEM and UEBA. They also have the most job postings in this Market Segment.
The record is only as good as what reports into it. One company covered mainly in another Market Segment stands for these feeds:
The physical world also reports into the record, through the door reader and the camera.
The largest names in this sub-segment are not here:
- Splunk, Elastic, Exabeam, LogRhythm and Devo are not covered in this Market Segment.
- Microsoft Sentinel and Google's security operations products are covered elsewhere.
(More on them in Microsoft and Google, in the big-tech collection.) - Palo Alto Networks, whose Cortex products compete directly, is covered mainly in Market Segment 4.5, Network security, firewalls and SASE. It also appears in Market Segment 4.6, Cloud and SaaS security.
- Sumo Logic sells a security version of its log product. Its Indian team works on its observability product, the tools that watch software as it runs.
(More on it in Market Segment 6.3, Observability and monitoring platforms, in Industry Vertical 6, Devtools companies.)
Back to the bank from the start of this Market Segment. The SIEM has fired, and now the analyst has to act:
- look up where the download is going
- cut the clerk's laptop off from the network
- disable the account
- open a ticket to track the incident
- tell the right people
Done by hand, this takes an hour. The companies in this sub-segment write the steps down as a playbook, and run it automatically. The industry calls this security orchestration, automation and response, or SOAR.

The scarce resource in a SOC is not the log store, but the person reading it. The newest products in this Market Segment use an AI model to triage every alert first. The human is left with the handful that survive.
Back to the bank from the start of this Market Segment. Suppose the attacker got the data out before anyone stopped it. Now the job changes from stopping the attack to reconstructing it:
- Which machine did the attacker enter first?
- What was taken?
- Are the backups clean?
This work is called digital forensics and incident response.
One company here works earlier instead, on investigating alerts:
Ransomware recovery is now the incident most companies rehearse for. Its other half is the backup that has to be restored.
So the bank from the start of this Market Segment runs its defence in three steps. The SIEM spots the 3 a.m. download among thousands of alerts. The playbook stops it within minutes. And if the attacker still got through, forensics works out what happened.
Who these companies hire, and for what, is on What cybersecurity hires for.