13 days ago
Bengaluru, IndiaStaff+

Responsibilities

  • Lead enterprise-wide architecture, design, implementation, and continuous improvement of email, endpoint, and data protection controls.
  • Serve as technical authority for Microsoft Defender for Office 365, Microsoft Defender for Endpoint, and Microsoft Purview.
  • Analyze threat trends, security telemetry, and control performance to tune and improve protection strategies.
  • Lead and participate in complex investigations, high-severity incident response, advanced hunting, and root-cause analysis.
  • Develop and maintain technical standards, reference architectures, playbooks, and design guidance.
  • Collaborate with security, IT, identity, business, response, intelligence, assurance, and services teams to embed protections into workflows.
  • Provide knowledge sharing and mentorship to engineers and practitioners.

Requirements

  • Bachelor’s degree in computer science, information technology, or a related field, or a minimum of 8 years of cybersecurity experience.
  • Expertise with Microsoft Defender for Office 365, including policy design, anti-phishing strategy, threat investigation, and enterprise-scale tuning.
  • Hands-on experience with Microsoft Defender for Endpoint, including EDR operations, Advanced Hunting using KQL, Attack Surface Reduction, and detection engineering.
  • Experience with Microsoft Purview, including Information Protection, Sensitivity Label architecture, DLP strategy, eDiscovery, and data lifecycle governance.
  • Ability to define and drive enterprise security strategies through technical credibility and thought leadership without direct managerial authority.
  • Demonstrated success operationalizing security controls while minimizing friction and enabling productivity.
  • Experience leading complex investigations, high-severity incident response, and root-cause analysis for email, endpoint, and data compromises.
  • Ability to author technical standards, playbooks, and design guidance for engineering and operational teams.
  • Strong communication skills for explaining technical risks, trade-offs, and recommendations to security leadership, IT stakeholders, and business partners.
  • Willingness to work weekends or off-shift hours as needed during cybersecurity incidents.
  • Preferred experience with SIEM, SOAR, threat intelligence platforms, and cloud security controls.
  • Ability to work independently, manage time effectively, drive results without direct supervision, and continue learning in the cybersecurity field.

Benefits

  • Hybrid work schedule combining on-site and remote work.
  • Relocation assistance availability is confirmed.
  • Equal employment opportunity and an inclusive workplace culture.
  • Accommodation support is available for individuals with disabilities or special needs.

Categories

Westinghouse Air Brake Technologies Corporation

About Westinghouse Air Brake Technologies Corporation

10,000+ employees
Contact me