Overview
Own and improve security operations across corporate IT, cloud, and Kubernetes environments, covering monitoring, detection, incident response, security tooling, integrations, automation, and IT security.
What you'll do
- Lead monitoring, triage, investigation, and incident response across endpoint, identity, email, network, SaaS, GCP, and GKE environments.
- Operate and improve SIEM, EDR, DLP, cloud security, network security, and identity security capabilities.
- Build detections, correlation rules, alerts, dashboards, and monitoring use cases.
- Automate alert enrichment, triage, investigation, containment, escalation, and response workflows.
- Investigate incidents through evidence collection, root-cause analysis, containment, remediation, and post-incident actions.
- Monitor GCP and GKE activity and identify cloud IAM, Kubernetes, workload, container, secrets, network, logging, and configuration gaps.
- Maintain incident-response playbooks, detection documentation, and investigation procedures.
What you'll need
- 5–7 years of hands-on cybersecurity experience in security operations, security engineering, or incident response.
- Hands-on SIEM and EDR experience covering log analysis, detection development, alert tuning, investigation, and response.
- Experience integrating security technologies and telemetry using APIs, webhooks, scripts, or automation platforms.
- Hands-on experience securing and monitoring GCP and Kubernetes/GKE environments.
- Strong knowledge of GCP IAM, audit logging, VPC networking, storage, KMS, Kubernetes RBAC, secrets, network policies, and audit logging.
- Strong networking fundamentals and experience investigating phishing, credential compromise, endpoint, cloud, network, and container security events.
- Python, shell scripting, or similar automation experience, plus working knowledge of MITRE ATT&CK.
Nice to have
- Experience building or maturing a SOC in a cloud-first environment.
- Experience with security orchestration and automated response.
- Experience with cloud security posture, vulnerability, and container/workload security.
- Familiarity with Infrastructure-as-Code and CI/CD security.
Details
- Location: Bangalore, India.
- Work mode: Hybrid.
Read the full description and apply on the company’s own careers page.