22 Aug
|
Happiest Minds Technologies
|
Bengaluru
22 Aug
Happiest Minds Technologies
Bengaluru
Cyber Defence Analyst
At PropertyGuru, we strive to ?Build Southeast Asia?s Trust Platform? and security is at the centre of building that trust with our customers, agents, and partners across Singapore, Vietnam, Malaysia, Thailand & India.
Role
- The Cyber Defence Analyst monitors, detects, and responds to security threats across cloud (AWS & • GCP), endpoint, and network environments. Leveraging the SentinelOne Singularity XDR platform (EDR, XDR, CNAPP, ITDR, and AI SIEM), cloud-native tools, and modern security technologies, the analyst plays a key role in threat detection, incident response, and continuous improvement of PropertyGuru?s security posture.
- Operating as a Tier-2 / Tier-3 Cyber Defence Analyst, they are expected to independently investigate complex alerts and incidents, drive incidents end-to-end with minimal supervision, contribute to detection engineering, and support the continuous maturity of the SOC while collaborating closely with SOC, engineering, and infrastructure teams to ensure rapid response and resilience against evolving threats.
Responsibilities1.
Threat
Monitoring &
• Detection (Cloud, Endpoint &
- Network)
- Monitor logs and telemetry from cloud-native sources (CloudTrail, GCP Audit), endpoint EDR/EPP solutions, and network security tools (NDR, firewalls, IDS/IPS).
- Develop, tune, and manage detection rules and use cases in SIEM/SOAR/XDR platforms.
- Identify and investigate anomalies, TTPs, and attack vectors spanning cloud, endpoint, and network layers.
- Monitor and investigate identity-based threats (suspicious logins, privilege escalation, service account abuse) using SentinelOne ITDR capabilities.
- Monitor cloud workload runtime threats, container activity, and misconfigurations using SentinelOne CNAPP signals.
- Leverage SentinelOne behavioral AI detections and cross-domain correlations for early threat identification.
2.
Incident
Response
- Investigate and triage alerts across cloud, endpoint, and network environments collect logs, perform forensic analysis, and document findings.
- Execute playbooks for a variety of scenarios: cloud key compromise, endpoint malware/ransomware, phishing, insider misuse, and lateral movement on networks.
- Work with SOC, IT, DevOps, and engineering teams for containment, remediation, and recovery.
- Act as primary incident owner for assigned incidents, driving investigation to closure within defined SLAs.
- Execute SentinelOne response actions such as endpoint isolation, kill/rollback, identity containment, and cloud workload response.
- Perform XDR-level incident correlation across endpoint, cloud, identity,
and network telemetry to determine blast radius.
3.
Threat
Hunting
- Conduct proactive hunts across multi-environment telemetry to uncover hidden threats or suspicious behavior.
- Identify patterns such as credential abuse, anomalous lateral movement, and data exfiltration across hybrid infrastructure.
- Build advanced dashboards and detection mechanisms across cloud, endpoint, and network.
- Perform hypothesis-driven threat hunts using SentinelOne XDR across endpoint, identity, and cloud datasets.
- Map hunt findings to MITRE ATT&CK; (Enterprise & • Cloud) and feed learnings back into detection engineering.
4.
Security
Analytics &
• Reporting
- Produce actionable incident reports and threat summaries for stakeholders.
- Correlate threat activity across domains (cloud, endpoint, network) to build holistic risk views.
- Share insights into emerging attack trends and propose security control improvements.
- Build and maintain SentinelOne dashboards for threat trends, attack paths, and detection coverage.
- Provide executive-ready summaries highlighting risk, impact, and recommended remediation.
5. Collaboration, Tuning & • Knowledge Sharing
- Provide SME input on log integration, audit coverage, and SOC process improvements.
- Mentor team members on detection, triage, and investigation best practices.
- Maintain updated playbooks, runbooks, and investigation procedures.
- Tune and optimize SentinelOne detection rules, AI alerts, and correlation logic to reduce noise and improve fidelity.
- Collaborate with security engineering to onboard new log sources into SentinelOne SIEM/XDR.
6.
Continuous
Improvement
- Stay current on adversary techniques across cloud, endpoint, and network.
- Work with platform/infra/security engineering teams to close detection gaps.
- Support purple team exercises, tabletop drills, and continuous validation of detection/response capabilities.
- Leverage scripting (Python, Shell, or similar) for automation, log parsing, enrichment, and detection engineering to enhance SOC efficiency as added advantage.
- Design and improve SOAR workflows and automated response playbooks within SentinelOne.
- Identify repeatable investigations and drive automation-first approaches.
Who you are Qualifications
- Bachelor?s or Master?s degree in cybersecurity, information technology, computer science, or a related discipline.
- 3-5+ years of experience in Security Operations, Incident Response, or Cloud Security, with significant exposure to AWS and GCP platforms.
- Hands-on experience with SentinelOne Singularity platform, including EDR, XDR, AI SIEM, CNAPP, and ITDR capabilities.
- Proven track record investigating incidents across multiple domains (cloud, endpoint, network).
- Scripting/automation knowledge (Python, Bash, or similar) for investigation and detection enrichment.
- Certifications such as GCIH, GCFR, GCIA or equivalent are preferred.
- Experience collaborating with cross-functional teams in time-sensitive, operational contexts.
- Strong documentation and root cause analysis skills, with an ability to translate findings into actionable playbooks or recommendations.
Knowledge
- Strong understanding of log sources: AWS CloudTrail/CloudWatch, GCP Audit, EDR telemetry, Windows/Linux syslogs, network IDS/IPS.
- Familiarity with MITRE ATT&CK; framework (Enterprise & • Cloud).
- Solid understanding of identity attack paths and IAM abuse techniques in cloud environments.
- Knowledge of cloud runtime threats, container escape techniques, and workload lateral movement.
- Knowledge of cloud, endpoint, and network attack vectors and associated defense techniques.
- Awareness of compliance frameworks (SOC 2, ISO 27001, PCI DSS) relevant to multi-environment infrastructure.
- Ability to apply threat intelligence for improving detection and hunting strategies.
Essential Personal Skills
- Highly collaborative works seamlessly within a SOC and across cloud, engineering, and incident response teams.
- Calm and decisive under pressure, able to manage multiple ongoing investigations and incidents simultaneously.
- Proactive mindset, with a strong drive for continuous learning and keeping skills sharp in the evolving cloud security landscape.
- Exceptional attention to detail and a methodical approach to investigation and documentation.
- Integrity, sound judgment, and a commitment to protecting sensitive information and maintaining confidentiality.
- Strong communication skills able to clearly document findings, communicate incident status, and share knowledge with both technical and non-technical audiences.
- Resourceful and self-motivated, able to adapt quickly to shifting priorities.
- Willingness to mentor team members and share best practices for effective cloud incident handling.
- Demonstrates curiosity and an investigative mindset able to dig deep and identify root causes rather than symptoms.
📌 TECHNICAL LEAD - Cybersecurity (Bengaluru)
🏢 Happiest Minds Technologies
📍 Bengaluru