13 Aug
|
Sopra Steria
|
Noida
13 Aug
Sopra Steria
Noida
Job Description
About the Role
We're looking for a Cloud Security Engineer with a robust incident response background to join our security team. You'll be on the front lines detecting, investigating, and remediating security events across our cloud infrastructure and endpoints.
What You'll Do
- Lead end-to-end incident response: triage, containment, investigation, and post-incident review
- Hunt for threats and investigate alerts using CrowdStrike Falcon (EDR, threat intelligence, and OverWatch)
- Build and tune detection logic in Splunk — write SPL queries, create dashboards, and maintain alert fidelity
- Audit and investigate events in AWS CloudTrail, CloudWatch, and native AWS security services (GuardDuty, Security Hub,
Config)
- Correlate signals across endpoint, network, and cloud layers to establish attack timelines
- Document findings and produce clear incident reports for both technical and non-technical audiences
- Contribute to runbooks, playbooks,
and continuous improvement of the IR program
What You Bring
- 3+ years in a security engineering, SOC, or incident response role
- Hands-on experience with CrowdStrike (investigation workflows, RTR, detections tuning)
- Proficiency in Splunk — SPL, data onboarding, and building actionable dashboards
- Solid understanding of AWS IAM, CloudTrail log structure, and cloud-native audit trails
- Familiarity with attacker TTPs (MITRE ATT&CK;) and how they map to cloud environments
- Ability to communicate technical findings clearly under pressure
Nice to Have
- GCIH, GCFE, AWS Security Specialty, or similar certifications
- Experience with IaC security tooling (Terraform, CloudFormation scanning)
- Scripting ability in Python or Bash for automation and log parsing
Total Experience Expected: 04-06 years
📌 Cloud Security Module Lead-Service Support (Noida)
🏢 Sopra Steria
📍 Noida