9 days ago
Chennai, IndiaMid Level
Responsibilities
- Develop, test, maintain, and improve detection rules across SIEM, EDR, NDR, and cloud-native platforms.
- Automate detection deployment, quality assurance, and version control using scripting and CI/CD pipelines.
- Conduct root-cause analysis of missed detections, delayed responses, and high-severity incidents.
- Maintain a continuous security improvement backlog covering detection gaps, telemetry blind spots, and false positives.
- Analyze detection performance metrics and align improvement priorities with business risk and the SOC transformation roadmap.
- Collaborate with SOC, incident response, threat hunting, threat intelligence, and engineering teams to operationalize detection improvements.
- Contribute to purple team exercises by validating detection logic against simulated attack paths.
- Document detection logic and root-cause analysis outcomes.
Requirements
- Strong knowledge of SIEM, SOAR, EDR, and cloud security platforms.
- Proficiency in Python and PowerShell scripting and automation.
- Familiarity with detection-as-code principles and CI/CD pipelines.
- Understanding of the MITRE ATT&CK framework and threat-informed defense.
- Ability to collaborate with SOC analysts, threat hunters, and engineers.
- Strong analytical, problem-solving, communication, documentation, and teamwork skills.
- An automation-first mindset focused on scalability and resilience.
- GIAC GCTI, GCFA, or an equivalent advanced security certification is preferred.
Benefits
- Inclusive, collaborative culture with opportunities for continuous learning and knowledge sharing.
- Opportunity to work on challenging, stimulating projects at significant scale.
- Hybrid work arrangement with teams generally in the office around four days per week.
- Accommodations or flexibility may be discussed with the hiring team.
