24 Aug
|
Atyeti
|
Bengaluru
Role & responsibilities
1. Detection Engineering (Primary Focus)
- Design, develop, and maintain high-fidelity detection rules and analytics across CrowdStrike Falcon (NGSIEM/EDR) and integrated SIEM platforms.
- Translate threat intelligence and adversary behaviors (MITRE ATT&CK;) into scalable detection use cases.
- Continuously tune and optimize detections to improve alert fidelity and signal-to-noise ratio.
- Develop and maintain detection-as-code practices, including version control, testing, and documentation.
- Perform coverage gap analysis and proactively build current detections to address emerging threats.
- Partner with threat hunting teams to convert hypotheses into production-grade detections.
- Validate detection coverage through purple teaming, adversary simulation, and attack replay testing.
- Build detection strategies across
- Endpoint (EDR)
- Identity
- Network and OT telemetry
- Cloud environments
2. SOAR Engineering & Automation (Secondary Focus)
- Design and implement automated playbooks using CrowdStrike Falcon Fusion and/or SOAR platforms.
- Automate end-to-end incident response workflows, including:
- Alert triage and enrichment
- Threat intelligence correlation
- Endpoint containment and remediation
- Case management and escalation
- Integrate SOAR with SIEM, EDR (CrowdStrike), NDR, vulnerability management, and threat intelligence platforms.
- Develop and maintain API-based integrations and connectors across security tools.
- Ensure automation workflows are resilient, auditable, and governed.
- Continuously identify opportunities to reduce manual SOC effort through orchestration.
3. Operational Mentality and SOC Optimization
- Champion a detection-first SOC model supported by automation.
- Improve SOC workflows through automated enrichment, triage, and response actions.
- Collaborate with SOC analysts, threat hunters, and engineers across APAC.
- Enhance operational metrics such as:
- Mean Time to Detect (MTTD)
- Mean Time to Respond (MTTR)
- Alert fidelity and reduction of false positives
4. OT & R&D; Security Strategy
- Develop detection and response use cases tailored for OT/ICS, SCADA, and IIoT environments.
- Collaborate with engineering and R&D; teams to integrate detect-and-respond capabilities into product lifecycles.
- Align detection strategies with
- MITRE ATT&CK; (Enterprise & ICS)
- NIST CSF / NIST 800-82
- IEC 62443
- Ensure safe implementation of automation within sensitive OT environments.
Job Qualifications Required Qualifications & Experience
- 7+ years of experience in cybersecurity with a focus on detection engineering, SOC operations, or incident response.
- 3+ years of hands-on experience in:
- Detection engineering / SIEM content development
- SOAR platforms (CrowdStrike Falcon Fusion preferred)
- Strong experience with CrowdStrike Falcon (EDR + NGSIEM).
- Proven experience building detection rules, behavioral analytics, and correlation logic.
- Proficiency in scripting and automation (Python, PowerShell, or similar).
- Experience with detection-as-code and API integrations.
- Strong understanding of
- MITRE ATT&CK; (Enterprise & ICS)
- Threat detection methodologies
- Incident response lifecycle
- Hands-on experience with SIEM, EDR, NDR, and threat intelligence platforms.
- Foundational knowledge of IT and OT security (ICS/SCADA environments).
- Experience securing R&D; environments and intellectual property.
- Working knowledge of cloud security (AWS, Azure, GCP).
Desired Certifications
- GIAC Certified Incident Handler (GCIH)
- GIAC Security Operations Certified (GSOC)
- GIAC Security Essentials (GSEC)
- Certified Cloud Security Professional (CCSP)
- Certified Information Systems Security Professional (CISSP)
- CompTIA Security+
- CompTIA CySA+
- AWS Certified Security Specialty
- Microsoft SC-200
📌 Cybersecurity Lead Detection/SOAR Engineer (Bengaluru)
🏢 Atyeti
📍 Bengaluru