RESPONSIBILITIES
RESPONSIBILITIES
* Design, develop, and maintain automated security workflows that ingest,
enrich, deduplicate, prioritize, and respond to alerts generated by SIEM
platforms and related detection technologies.
* Engineer automated triage and response logic that reduces manual analyst
effort, improves alert quality, and accelerates incident response across
Security Operations.
* Build integrations between security platforms and ticketing / case management
systems to enable consistent case creation, enrichment, evidence capture,
escalation, documentation, and stakeholder communication.
* Integrate threat intelligence, asset context, identity signals, vulnerability
data, and other enrichment sources into automated detection and response
pipelines to support risk-based decision-making.
* Lead automation for detection and rule lifecycle management, including
tuning, validation, deployment, rollback planning, measurement, and
continuous improvement of security use cases.
* Partner with Security Services subject matter experts to translate
operational pain points, incident response requirements, and detection
engineering needs into scalable automation.
* Develop and maintain reusable scripts, API integrations, workflow components,
libraries, and runbook patterns that improve automation consistency and
reduce duplicate engineering effort.
* Define and apply automation standards for code quality, peer review, version
control, testing, documentation, change management, and operational
supportability.
* Monitor production automation health, investigate failed or degraded
workflows, and improve resiliency, observability, exception handling, and
alerting for mission-critical automation services.
* Evaluate emerging cyber threats and operational trends, then implement or
improve automated coverage through recent detections, enrichments, response
actions, or reporting capabilities.
* Lead smaller automation projects or defined phases of broader Security
O
📌 Assoc. Manager, IT Security (India)
🏢 Yum
📍 India