22 Aug
|
Neurealm
|
Chennai
We are seeking a highly skilled and experienced Lead Cybersecurity Engineer to lead the design, engineering, deployment, optimization, and ongoing improvement of enterprise security controls and platforms. The role requires strong hands-on expertise across EDR, SIEM, IDS/IPS, MDM, Microsoft 365 Security, identity security, vulnerability management, and security automation. The successful candidate will drive technical implementation initiatives, strengthen detection and response capabilities, support SOC operations, and ensure security controls align with organizational strategy, risk posture, and compliance requirements.
Work Location: Chennai
Shift: EST Hours
Key Responsibilities:
- Lead the design, engineering, deployment, and continuous improvement of enterprise security tools and platforms, including EDR, SIEM, IDS/IPS, MDM, and Microsoft 365 security solutions.
- Architect and implement scalable security controls to protect endpoints, networks, cloud workloads, identity systems, and business-critical infrastructure.
- Manage and optimize integrations across security platforms, including EDR, SIEM, SOAR, MDM, IAM, and related monitoring tools.
- Drive incident detection and response engineering through alert tuning, detection use case development, correlation logic, and automation playbooks.
- Oversee deployment and enforcement of endpoint security controls, including DLP, USB/device control, device compliance policies, and endpoint hardening standards.
- Collaborate with SOC, Infrastructure, IAM, Cloud, and application teams to ensure security controls are implemented, monitored, and operationalized effectively.
- Lead troubleshooting and root cause analysis for security events, tool failures, policy issues, log ingestion gaps, and control effectiveness concerns.
- Establish and maintain SIEM use cases, correlation rules, dashboards, reports, and operational metrics to improve monitoring and executive visibility.
- Conduct vulnerability assessments, validate scan results, support remediation planning, and track risk reduction activities through closure.
- Participate in change management processes to assess security impact, define control requirements, and ensure security tooling remains aligned with approved changes.
- Drive automation initiatives using PowerShell, Python, SOAR workflows, and other scripting methods to reduce manual effort and improve response consistency.
- Develop and maintain security baselines, hardening standards, deployment playbooks, operational guides, and technical documentation.
- Monitor emerging threats, threat intelligence,
and adversary techniques to adapt detections and controls based on current attack trends.
- Provide technical leadership, coaching, and mentorship to junior engineers, SOC analysts, and cross-functional teams.
Technical Responsibilities:
- Engineer, deploy, and administer EDR platforms such as CrowdStrike and Microsoft Defender for Endpoint, including policy tuning, threat detection, response actions, and control validation.
- Implement and manage SIEM platforms such as CrowdStrike NG SIEM or Splunk, including log onboarding, parsing, normalization, dashboarding, and advanced correlation logic.
- Design, implement, and support IDS/IPS and network security monitoring solutions to improve threat visibility, prevention, and investigation capability.
- Administer and optimize Microsoft 365 Security capabilities, including Microsoft Defender Suite, Entra ID, Conditional Access, Secure Score improvements, and identity protection controls.
- Manage MDM platforms such as Microsoft Intune or equivalent solutions for device compliance, device posture, policy enforcement, and access control.
- Implement of identity security controls, including MFA, Conditional Access, privileged access controls, least privilege, and Zero Trust principles.
- Build and maintain SOC automation and SOAR workflows for incident triage, evidence collection, containment actions, enrichment, notification, and reporting.
- Integrate and manage threat intelligence feeds across security tools to support proactive detection, enrichment, and threat hunting.
- Perform log source integration across servers, endpoints, network devices, cloud platforms, firewalls, identity systems, and business-critical applications.
- Support compliance and audit activities, including HIPAA, NIST, ISO 27001, and CIS-aligned evidence gathering, configuration review, reporting, and technical control validation.
Required Skills and Experience:
- Strong hands-on experience in security engineering, control implementation, and enterprise security tool deployment.
- Proven expertise in incident detection, incident response, alert tuning, threat hunting, and SOC enablement.
- Experience with firewalls, endpoint protection,
cloud security controls, identity controls, and Microsoft security ecosystems.
- Working knowledge of scripting and automation using PowerShell, Python, or similar languages.
- Ability to troubleshoot complex multi-layer security issues across endpoint, network, identity, cloud, and application environments.
- Strong understanding of modern attack techniques, adversary behaviors, MITRE ATT&CK; framework, and detection engineering principles.
- Experience working in fast-paced SOC, security engineering, or enterprise security operations environments.
- Strong documentation, stakeholder communication, technical leadership, prioritization, and project execution skills.
Required Qualifications:
- Bachelors or Master’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
- 10+ years of experience in IT Security, including at least 5+ years in security engineering, implementation, or platform administration roles.
- Hands-on experience with EDR, SIEM, IDS/IPS, MDM, Microsoft 365 Security, IAM/PAM, vulnerability management, and cloud security controls.
- Strong understanding of security frameworks and benchmarks, including NIST, ISO 27001, CIS Controls, and CIS Benchmarks.
- Demonstrated ability to lead technical implementations, manage security projects end-to-end, and deliver measurable control improvements.
- Ability and willingness to support night shift coverage or a 24x7 SOC operating model when required by business needs.
Preferred Qualifications:
- Relevant certifications such as CISSP, CISM, CCSP, GCIH, GCIA, GCFA, CEH, Microsoft Security certifications, CrowdStrike certifications, Splunk certifications, or equivalent practical experience.
- Experience in regulated environments such as healthcare, financial services, or other compliance-driven industries.
- Experience building executive dashboards, KPI reporting, operational metrics, and compliance evidence packages.
Success Measures:
- Improved security control coverage across endpoint, network, identity, cloud, and Microsoft 365 environments.
- Reduced alert noise and stronger detection quality through tuning, correlation improvements, and validated use cases.
- Reliable operationalization of security tools with explicit playbooks, dashboards, reporting, and ownership.
- Improved audit readiness through documented configurations, evidence collection, baselines, and control validation.
- Increased automation and reduced manual effort in SOC triage, investigation, and response activities.
📌 Cybersecurity Engineer - Lead/Manager (Chennai)
🏢 Neurealm
📍 Chennai