IG
Cyber Security Engineer
Accepting applicationsInsight Global · India
Full-Time Mid_senior PythonSOC
Posted
1d ago
Category
Design
Experience
Mid_senior
Country
India
Key Responsibilities:
Lead the investigation and response of major cybersecurity incidents, including ransomware, phishing, insider threats, malware, credential compromise, and data breaches.
Perform incident triage, analysis, containment, eradication, recovery, and post-incident activities.
Conduct root cause and impact analysis to identify attack vectors, affected systems, and business impact.
Analyze security alerts, logs, network traffic, endpoint telemetry, cloud activity, and threat intelligence to determine the scope of incidents.
Utilize SIEM, EDR, NDR, cloud security, email security, and identity security tools to investigate and respond to security events.
Correlate data from multiple security technologies to identify malicious activity, reconstruct attack timelines, and uncover threat actor behavior.
Perform threat hunting activities and identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs).
Serve as the technical lead during major incidents and coordinate response efforts across cybersecurity, infrastructure, cloud, application, legal, privacy, compliance, and business teams.
Provide clear incident communications, status updates, executive briefings, and ensure proper documentation and regulatory reporting.
Develop, maintain, and optimize incident response playbooks, runbooks, and standard operating procedures.
Design and implement automation and SOAR workflows to improve investigation efficiency, response consistency, and SOC effectiveness.
Create and improve detection rules, use cases, and response processes while driving continuous improvements through lessons learned, threat intelligence, and incident trend analysis.
Minimum Qualifications:
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
10+ years of experience in cybersecurity, including significant experience in Security Operations Center (SOC) and Incident Response functions.
Proven experience leading investigations of major cybersecurity incidents and security breaches.
Strong understanding of incident response methodologies, attacker tactics, and forensic investigation techniques.
Experience working in enterprise or global environments with complex security infrastructures.
Ability to coordinate technical and non-technical stakeholders during high-pressure incident situations.
Experience working in one of the SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, LogRhythm, etc.)
Experience working in one of the Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, etc.)
Experience with query languages and scripting (KQL, SPL, Python, PowerShell, Bash/Shell scripting)
Experience with API integrations and workflow automations
Preferred Certifications:
GIAC Certified Incident Handler (GCIH)
GIAC Certified Forensic Analyst (GCFA)
GIAC Certified Enterprise Defender (GCED)
CISSP
Certified SOC Analyst (CSA)
Microsoft Security Operations Analyst Associate
SANS Incident Response training or equivalent
NOTE : This role is a NIGHT SHIFT.
Show more Show less
Lead the investigation and response of major cybersecurity incidents, including ransomware, phishing, insider threats, malware, credential compromise, and data breaches.
Perform incident triage, analysis, containment, eradication, recovery, and post-incident activities.
Conduct root cause and impact analysis to identify attack vectors, affected systems, and business impact.
Analyze security alerts, logs, network traffic, endpoint telemetry, cloud activity, and threat intelligence to determine the scope of incidents.
Utilize SIEM, EDR, NDR, cloud security, email security, and identity security tools to investigate and respond to security events.
Correlate data from multiple security technologies to identify malicious activity, reconstruct attack timelines, and uncover threat actor behavior.
Perform threat hunting activities and identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs).
Serve as the technical lead during major incidents and coordinate response efforts across cybersecurity, infrastructure, cloud, application, legal, privacy, compliance, and business teams.
Provide clear incident communications, status updates, executive briefings, and ensure proper documentation and regulatory reporting.
Develop, maintain, and optimize incident response playbooks, runbooks, and standard operating procedures.
Design and implement automation and SOAR workflows to improve investigation efficiency, response consistency, and SOC effectiveness.
Create and improve detection rules, use cases, and response processes while driving continuous improvements through lessons learned, threat intelligence, and incident trend analysis.
Minimum Qualifications:
Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
10+ years of experience in cybersecurity, including significant experience in Security Operations Center (SOC) and Incident Response functions.
Proven experience leading investigations of major cybersecurity incidents and security breaches.
Strong understanding of incident response methodologies, attacker tactics, and forensic investigation techniques.
Experience working in enterprise or global environments with complex security infrastructures.
Ability to coordinate technical and non-technical stakeholders during high-pressure incident situations.
Experience working in one of the SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, LogRhythm, etc.)
Experience working in one of the Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, etc.)
Experience with query languages and scripting (KQL, SPL, Python, PowerShell, Bash/Shell scripting)
Experience with API integrations and workflow automations
Preferred Certifications:
GIAC Certified Incident Handler (GCIH)
GIAC Certified Forensic Analyst (GCFA)
GIAC Certified Enterprise Defender (GCED)
CISSP
Certified SOC Analyst (CSA)
Microsoft Security Operations Analyst Associate
SANS Incident Response training or equivalent
NOTE : This role is a NIGHT SHIFT.
Show more Show less
Similar Jobs
D
Digital ASIC Implementation Engineer
Draper · Greater Boston
AW
AI SoC Modeling Engineer, Annapurna Labs Machine Learning Accelerators, AWS
Amazon Web Services (AWS) · Cupertino, CA
KI
Senior Hardware Design Engineer (Hybrid)
Kforce Inc · Tempe, AZ
AW
AI SoC Modeling Engineer, Annapurna Labs Machine Learning Accelerators, AWS
Amazon Web Services (AWS) · Austin, TX