Shift - 24x7x365 (Rotational, On-Call Support Required)
Interview Process - Virtual
Role Objective
The L2 Security Engineer is responsible for incident response, containment, and recovery for confirmed perimeter security incidents. This role acts as the primary owner of security incidents,
ensuring timely mitigation while coordinating with internal teams, ISPs, and OEMs.
Key Responsibilities
Incident Response & Containment
• Take ownership of validated incidents escalated from L1
• Execute containment actions in line with approved SOPs:
o Malicious IP blocking
o Policy enforcement
o Traffic mitigation
• Coordinate real-time response during active attacks
• Ensure service restoration and post-incident stability
Perimeter Security Operations
• Firewalls (Cisco / Palo Alto / Check Point / Fortinet)
o Implement temporary security rules (approved scope)
o Support emergency access control changes
• IDS / IPS (Trend Micro / Cisco)
o Validate exploit attempts
o Apply temporary signature tuning during incidents
• DDoS (ISP / Radware)
o Activate mitigation techniques
o Liaise with ISP / SOC partners during attacks
• Web Application Firewall (F5)
o Enforce blocking actions
o Apply temporary mitigation rules
• Proxy & Internet Security
o Contain infected endpoints / suspicious traffic
• Micro Segmentation (Guard iCore)
o Apply containment policies for lateral movement threats
RCA, Reporting & Coordination
• Perform root cause analysis (RCA)
• Prepare incident reports (technical + executive summary)
• Support audit and compliance evidence
• Engage OEM TAC and internal SMEs as required
Skills & Qualifications
Technical Skills
• Strong hands-on experience in perimeter security platforms
• Incident response and traffic analysis expertise
• Good understanding of network protocols and attack patterns
Soft Skills
• Incident ownership mindset
• Robust coordination and communication skills
• Ability to perform under pressure