Security Engineer (Bengaluru)

Security Engineer (Bengaluru)

27 Aug
|
appviewx
|
Bengaluru

27 Aug

appviewx

Bengaluru

We are hiring a Security Engineer who lives at the intersection of SOC alerting and vulnerability remediation - the work that connects 'something looks wrong' to 'something is fixed'. You will own the close-the-loop motion: triage SOC alerts and vulnerability findings, prioritise against business context and threat intel, assign and chase down remediation owners, and measure what actually got fixed.

AI leverage: AI SAST AppSec triage, CSPM findings, and prioritising AISOC for L1/L2 alert handling and intel agents for the repetitive parts owners' remediation loop.

Responsibilities

- SOC alert triage and response. Operate primarily as a SOC engineer and analyst. Triage alerts. Calibrate severity. Route or escalate. Be the human in the loop with AI and agents operating under your authority.
- Vulnerability alert handling and remediation coordination. Take the daily dose of vulnerability findings (SAST/SCA/secrets, CSPM, container/infra, and endpoint via EDR) and turn it into a managed remediation pipeline. Apply CTEM/risk-context prioritisation: CVSS + EPSS + KEV + business context.
- Close-the-loop ownership. Open the ticket; assign the right owner (engineering / SRE / Corp IT / AppSec); ensure the SLA (runAppSec) can rescan/retest; SLA-manage the rescan/retest platform; and close the GRC Platform - 'open and forgotten' is a thing of the past.
- SLA enforcement and metrics. Operate the SLA dashboard. Watch for ageing items at 75% of the SLA window and escalate. Run the WeAgeingLA compliance report on the SLA. Own the monthly CISO view of open vulnerabilities, MTTR trends, and ageing by owner.
- Threat hunting partnership. Support the senior SOC/detection engineer's senior detection engineer accounts. Bring vulnerability and remediating context into hunts (e. g., a known unpatched asset-focused hunt).
- AI agents for the loop.



Build agents where the work is repetitive (e. g., alert deduplication and enrichment, vuln-to-owner routing, SLA-vulnerability-to-owner references, evidence collection for closures, and post-mortem disclosures) and decide where the human stays in the loop.
- Incident response support. During Severity 1/2 events, serve as a SOC technical contributor for investigation, event contribution, timeline documentation, customer advice documentation, and content (with CSIRT/PSIRT/CISO oversight).
- Customer reports. Be the SOC partner for customer-reported security issues, initial triage, severity calibration, and handoff to the right internal owner with proper escalation.

You May Work On

- MDR partnership runbook authorship and detection content engineering.
- Code-level vulnerability fixes (owned by engineering; you coordinate, prioritise, and verify and may even help provide or author the code patches).
- Ensure production patching execution SLAs are completed by SRE/DevOps.
- Endpoint patching execution (owned by Corporate IT; you set SLA expectations and ensure compliance).
- Incident command for Severity 1 events (owned by the Sr SOC engineer, escalating to CISO).

First 90 Days

- SOC triage shift coverage is operational with the SOC lead-defined handoff cadence, escalation paths, and on-call rotation seat.
- Vulnerability remediation pipeline measured end-to-end: time-to-triage, time-to-assignment, time-to-fix,



and SLA compliance baseline established.
- First AI agent shipped for the remediation loop (e. g., alert enrichment, vuln-to-owner routing, or SLA chase cadence).
- Top 10 highest-ageing vulnerabilities triaged and either closed, exception-approved, or escalated with documented compensating controls.
- A weekly SLA compliance dashboard is live for the CISO and director of security engineering review.

Requirements

- Four or more years in SOC, security operations, vulnerability management, or incident response with hands-on alert triage and remediation coordination experience.
- Hands-on with SIEM/EDR/XDR tooling (CrowdStrike, Splunk, Sentinel, Chronicle, Sumo, or equivalent).
- Hands-on with at least one vulnerability scanner or AppSec platform (Endor, Snyk, Tenable, Qualys, Rapid7 Wiz, Aqua, AWS Inspector, or comparable).
- Fluency with CVSS v3.1/v4.0 EPSS, CISA KEV, and risk-context prioritisation frameworks (CTEM or similar).
- Robust written and verbal communication: you can write a remediation ticket an engineer will actually act on, and you can escalate to the CISO when needed.
- Demonstrated comfort with MITRE ATT& CK and threat-actor TTPs at the conversational level.

Preferred

- Hands-on building AI agents or automations for SOC, vulnerability management, or IT operations work.
- Operational experience with an MDR partner (Expel, Arctic Wolf, Rapid7 Red Canary, or comparable).
- Experience with AISOC platforms.
- GIAC certifications (GCIA, GCFA, GCIH) or equivalent.
- Cloud-native security experience (AWS, Azure, GCP): You understand cloud findings and can route them to the right owner.
- Familiarity with PKI / certificate management / machine identity relevant to AppViewX's product domain.

This job was posted by Sai Amrith from AppViewX.

📌 Security Engineer (Bengaluru)
🏢 appviewx
📍 Bengaluru

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security engineer (bengaluru) / bengaluru

Subscribe to this job alert:

Get the latest job offers by email for: security engineer (bengaluru) / bengaluru