27 Aug
|
appviewx
|
Bengaluru
27 Aug
appviewx
Bengaluru
We are hiring a Security Engineer who lives at the intersection of SOC alerting and vulnerability remediation - the work that connects 'something looks wrong' to 'something is fixed'. You will own the close-the-loop motion: triage SOC alerts and vulnerability findings, prioritise against business context and threat intel, assign and chase down remediation owners, and measure what actually got fixed.
AI leverage: AI SAST AppSec triage, CSPM findings, and prioritising AISOC for L1/L2 alert handling and intel agents for the repetitive parts owners' remediation loop.
Responsibilities
- SOC alert triage and response. Operate primarily as a SOC engineer and analyst. Triage alerts. Calibrate severity. Route or escalate. Be the human in the loop with AI and agents operating under your authority.
- Vulnerability alert handling and remediation coordination. Take the daily dose of vulnerability findings (SAST/SCA/secrets, CSPM, container/infra, and endpoint via EDR) and turn it into a managed remediation pipeline. Apply CTEM/risk-context prioritisation: CVSS + EPSS + KEV + business context.
- Close-the-loop ownership. Open the ticket; assign the right owner (engineering / SRE / Corp IT / AppSec); ensure the SLA (runAppSec) can rescan/retest; SLA-manage the rescan/retest platform; and close the GRC Platform - 'open and forgotten' is a thing of the past.
- SLA enforcement and metrics. Operate the SLA dashboard. Watch for ageing items at 75% of the SLA window and escalate. Run the WeAgeingLA compliance report on the SLA. Own the monthly CISO view of open vulnerabilities, MTTR trends, and ageing by owner.
- Threat hunting partnership. Support the senior SOC/detection engineer's senior detection engineer accounts. Bring vulnerability and remediating context into hunts (e. g., a known unpatched asset-focused hunt).
- AI agents for the loop.
Build agents where the work is repetitive (e. g., alert deduplication and enrichment, vuln-to-owner routing, SLA-vulnerability-to-owner references, evidence collection for closures, and post-mortem disclosures) and decide where the human stays in the loop.
- Incident response support. During Severity 1/2 events, serve as a SOC technical contributor for investigation, event contribution, timeline documentation, customer advice documentation, and content (with CSIRT/PSIRT/CISO oversight).
- Customer reports. Be the SOC partner for customer-reported security issues, initial triage, severity calibration, and handoff to the right internal owner with proper escalation.
You May Work On
- MDR partnership runbook authorship and detection content engineering.
- Code-level vulnerability fixes (owned by engineering; you coordinate, prioritise, and verify and may even help provide or author the code patches).
- Ensure production patching execution SLAs are completed by SRE/DevOps.
- Endpoint patching execution (owned by Corporate IT; you set SLA expectations and ensure compliance).
- Incident command for Severity 1 events (owned by the Sr SOC engineer, escalating to CISO).
First 90 Days
- SOC triage shift coverage is operational with the SOC lead-defined handoff cadence, escalation paths, and on-call rotation seat.
- Vulnerability remediation pipeline measured end-to-end: time-to-triage, time-to-assignment, time-to-fix,
and SLA compliance baseline established.
- First AI agent shipped for the remediation loop (e. g., alert enrichment, vuln-to-owner routing, or SLA chase cadence).
- Top 10 highest-ageing vulnerabilities triaged and either closed, exception-approved, or escalated with documented compensating controls.
- A weekly SLA compliance dashboard is live for the CISO and director of security engineering review.
Requirements
- Four or more years in SOC, security operations, vulnerability management, or incident response with hands-on alert triage and remediation coordination experience.
- Hands-on with SIEM/EDR/XDR tooling (CrowdStrike, Splunk, Sentinel, Chronicle, Sumo, or equivalent).
- Hands-on with at least one vulnerability scanner or AppSec platform (Endor, Snyk, Tenable, Qualys, Rapid7 Wiz, Aqua, AWS Inspector, or comparable).
- Fluency with CVSS v3.1/v4.0 EPSS, CISA KEV, and risk-context prioritisation frameworks (CTEM or similar).
- Robust written and verbal communication: you can write a remediation ticket an engineer will actually act on, and you can escalate to the CISO when needed.
- Demonstrated comfort with MITRE ATT& CK and threat-actor TTPs at the conversational level.
Preferred
- Hands-on building AI agents or automations for SOC, vulnerability management, or IT operations work.
- Operational experience with an MDR partner (Expel, Arctic Wolf, Rapid7 Red Canary, or comparable).
- Experience with AISOC platforms.
- GIAC certifications (GCIA, GCFA, GCIH) or equivalent.
- Cloud-native security experience (AWS, Azure, GCP): You understand cloud findings and can route them to the right owner.
- Familiarity with PKI / certificate management / machine identity relevant to AppViewX's product domain.
This job was posted by Sai Amrith from AppViewX.
📌 Security Engineer (Bengaluru)
🏢 appviewx
📍 Bengaluru