Responsibilities
Responsibilities
- Design, develop, and maintain automated security workflows that ingest, enrich, deduplicate, prioritize, and respond to alerts generated by SIEM platforms and related detection technologies.
- Engineer automated triage and response logic that reduces manual analyst effort, improves alert quality, and accelerates incident response across Security Operations.
- Build integrations between security platforms and ticketing / case management systems to enable consistent case creation, enrichment, evidence capture, escalation, documentation, and stakeholder communication.
- Integrate threat intelligence, asset context, identity signals, vulnerability data, and other enrichment sources into automated detection and response pipelines to support risk-based decision-making.
- Lead automation for detection and rule lifecycle management, including tuning, validation, deployment, rollback planning, measurement, and continuous improvement of security use cases.
- Partner with Security Services subject matter experts to translate operational pain points, incident response requirements, and detection engineering needs into scalable automation.
- Develop and maintain reusable scripts, API integrations, workflow components, libraries, and runbook patterns that improve automation consistency and reduce duplicate engineering effort.
- Define and apply automation standards for code quality, peer review, version control, testing, documentation, change management, and operational supportability.
- Monitor production automation health, investigate failed or degraded workflows, and improve resiliency, observability, exception handling, and alerting for mission-critical automation services.
- Evaluate emerging cyber threats and operational trends, then implement or improve automated coverage through new detections, enrichments, response actions, or reporting capabilities.
- Lead smaller automation projects or defined phases of broader Security Operations initiatives, coordinating tasks, dependencies, testing, implementation, and handoff with cross-functional partners.
- Mentor junior engineers or analysts on automation patterns, troubleshooting, secure coding practices, workflow design, and platform best practices.
- Maintain accurate runbooks, workflow documentation, architecture notes, operational handoff materials, and evidence required for audits, change reviews, or leadership reporting.
- Participate in on-call or critical incident support for high-impact automation services as required by the Security Operations support model.
Required Skills
- Strong programming and scripting capability in Python, PowerShell, JavaScript, or similar languages, with experience building reliable automation for security operations use cases.
- Hands-on experience with SIEM and SOAR platforms, detection logic, alert enrichment, automated playbooks, workflow orchestration, and downstream response integrations.
- Strong understanding of SOC operations, incident response workflows, detection engineering, security telemetry, alert lifecycle, triage patterns, and case handling processes.
- Experience designing and consuming REST APIs, webhooks, event-driven integrations, and data exchange patterns across security tools, cloud services, and internal platforms.
- Working knowledge of threat frameworks such as MITRE ATT&CK;, Cyber Kill Chain, or similar models, with the ability to operationalize them through automation and detection use cases.
- Understanding of network protocols, endpoint telemetry, identity signals, cloud security controls, vulnerability data, and other security context used for enrichment and response.
- Familiarity with CI/CD pipelines, version control, code review, test automation, release documentation, and configuration management practices for production automation.
- Ability to independently analyze complex technical problems, evaluate trade-offs, and choose practical methods for reliable, supportable security automation.
- Strong written and verbal communication skills with the ability to explain technical automation design, operational impact, limitations, and risk-based recommendations to security and IT stakeholders.
Qualifications
- 10–12 years of experience in cybersecurity, security operations, security engineering, detection engineering, incident response, or security automation roles.
- At least 10 years of experience operating within a SOC or enterprise security environment, with direct exposure to detection engineering, incident response workflows, and security tooling automation.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent work experience.
- Demonstrated experience creating or significantly improving automation workflows, security integrations, rule lifecycle processes, response playbooks, or operational tools in a production environment.
- Demonstrated ability to work independently with minimal guidance on complex assignments and act as a technical resource for less experienced engineers or analysts.
- Experience collaborating across security, engineering, IT, cloud, platform, and vendor teams in a global or distributed enterprise environment.
- Proficient in written and spoken English.
Preferred Qualifications
- Hands-on experience with SOAR platforms and workflow orchestration tools, including development of automated playbooks, integrations, enrichment workflows, and response actions.
- Experience automating security controls and response actions across AWS, Azure, GCP, or hybrid cloud environments.
- Exposure to infrastructure as code or configuration management tools such as Terraform, Ansible, or similar technologies for repeatable security automation.
- Knowledge of modern detection engineering practices, including use case development, false positive reduction, enrichment strategies, coverage mapping, and telemetry quality improvement.
- Experience with security automation reliability practices, including monitoring, retry logic, queue handling, error handling, performance tuning, and failure analysis.
- Advanced industry certifications such as CISSP, GIAC, cloud security certifications, or security automation-related credentials are a plus.
Key Performance Indicators (KPIs)
KPIs are intended to guide measurable performance expectations and may be refined based on platform ownership, automation maturity, Security Operations priorities, and business-critical use cases.
Short-Term Outcomes (3–6 Months)
- Onboarding and setting fluency: Complete onboarding to Yum!’s Security Operations platforms, priority workflows, critical integrations, change processes, and stakeholder map within 90 days.
- Automation baseline: Establish or update an inventory of assigned automations, dependencies, owners, health status, runbooks, and known gaps within the first 90 days.
- Workflow delivery: Deliver at least 2–3 approved automation enhancements,
playbooks, integrations, or workflow improvements in the first 3–6 months, with documented acceptance criteria and operational handoff.
- Change quality: Ensure at least 95% of assigned automation changes include version control, peer review, testing evidence, rollback guidance, and runbook updates.
- Operational responsiveness: Triage high-priority automation failures, degraded workflows, or production support requests within agreed SLAs and communicate impact, workaround, and remediation status clearly.
- Efficiency improvement: Reduce manual steps or average enrichment time by 10–15% for at least one prioritized alert, triage, or response workflow.
Long-Term Outcomes (6–12+ Months)
- MTTA / MTTR improvement: Improve mean time to acknowledge, enrich, or respond for targeted security use cases by at least 20% through validated automation.
- Manual effort reduction: Reduce repeatable manual Security Operations effort by 25–30% across prioritized workflows through automation, enrichment, auto-ticketing, or response orchestration.
- Detection and response quality: Improve false positive handling, enrichment quality, or alert disposition accuracy by 15–20% for selected high-volume or high-risk use cases.
- Automation reliability: Maintain at least 99% availability or successful execution for business-critical automation workflows, excluding approved maintenance windows or dependent-platform outages.
- Lifecycle maturity: Implement or materially improve rule lifecycle, playbook lifecycle, code review, deployment, monitoring, and rollback practices for assigned automation services.
- Knowledge transfer: Mentor junior analysts or engineers through documented patterns, code reviews, troubleshooting sessions, and reusable automation templates.
Functional KPI Categories
Technical Delivery
- Number of production-ready playbooks, integrations, scripts, or reusable workflow components delivered against agreed backlog priorities.
- Percentage of delivered automations with documented acceptance criteria, test evidence, error handling, rollback instructions, and operational handoff.
- Adherence to coding, change management, peer review, version control, and documentation standards.
Operational Efficiency
- Reduction in manual analyst steps, duplicate ticket handling, repetitive enrichment tasks, and avoidable escalations.
- Increase in percentage of alerts that are automatically enriched, routed, ticketed, suppressed, or escalated according to approved logic.
- Improvement in analyst feedback scores or stakeholder satisfaction for automated workflows and runbooks.
Detection, Response & Risk Reduction
- Improvement in coverage for prioritized threat scenarios, MITRE ATT&CK; techniques, or high-risk detection use cases through automation.
- Speed of deploying validated automation updates for urgent threats, new detections, or critical operational gaps.
- Measured improvement in quality of evidence, severity assignment, ownership, and remediation tracking for automation-generated tickets.
Reliability, Governance & Leadership
- Production automation success rate, failure rate, recovery time, and repeat-incident trend for assigned workflows.
- Number and quality of code reviews, design reviews, runbook reviews, and knowledge-sharing sessions delivered for peers or junior team members.
- Timely reporting of automation outcomes, risks, technical debt, dependencies, and roadmap recommendations to Security Operations leadership.
Qualifications
• Bachelor’s degree in computer science, Cybersecurity, Information Technology, or related field with 8-10 years of relevant experience
📌 Assoc. Manager, IT Security (India)
🏢 KFC
📍 India