Role Description
Security Engineer
Key Responsibilities
- Perform continuous, first-line monitoring of security s generated by security tools (SIEM, EDR, email security, DLP, etc.) as per defined shift roster.
- Triage and classify security s based on severity, perform initial validation, and filter out false positives as per defined criteria.
- Follow standard operating procedures (SOPs) and playbooks for common types — phishing, malware, brute-force attempts, suspicious logins, etc.
- Escalate validated/confirmed incidents to the L2 team with complete initial findings, evidence, and timeline, following the defined escalation matrix.
- Monitor and act on basic security tickets — user access requests, antivirus s, endpoint compliance flags — within defined SLAs.
- Track s and tickets through to closure; ensure accurate logging, categorization, and documentation in the ticketing/ITSM tool.
- Support vulnerability scanning activities — assist in scheduling scans, sharing reports, and tracking remediation status with respective teams.
- Coordinate with security tool owners (SIEM, EDR/XDR, DLP, email gateway, IAM/PAM) as and when required — for tuning inputs, false-positive feedback, log source issues, agent health, and access-related requests. (Note: tool configuration and policy changes remain with the respective tool owners.)
- Report recurring patterns, noisy rules,
and log source gaps to L2/tool owners for tuning and optimization.
- Provide first-level support during security incidents — evidence collection, notification, and execution of containment steps as directed by L2/L3 or the Incident Manager.
- Assist in evidence collection for security audits and compliance assessments (ISO 27001, SOC 2) as guided by the GRC/compliance team.
- Participate in table-top exercises, DR drills, and incident simulations as part of the SOC team.
- Maintain shift handover logs and contribute to keeping SOPs, playbooks, and runbooks up to date based on operational feedback.
- Prepare and share daily/weekly SOC operational reports — volumes, SLA adherence, open items.
Required Skills & Qualifications
- Bachelor’s degree in computer science, IT, or related field.
- Basic understanding of networking, operating systems, and common attack vectors; exposure to SIEM/EDR tools preferred.
- Working knowledge of security frameworks and standards (MITRE ATT&CK;, NIST, ISO 27001).
- Familiarity with scripting (Python/PowerShell) for automation of security tasks is an added advantage (preferred for L2).
- Relevant certifications preferred: CompTIA Security+, CEH, CySA
- Robust analytical, documentation, and communication skills.
Skills Email Security, Incident Response, Identity and Access Management, Python
📌 SOC & EDR Security Engineer (Pune)
🏢 UST
📍 Pune