17 Sep
|
Cybervahak Consultants Private
|
Mumbai
17 Sep
Cybervahak Consultants Private
Mumbai
SENIOR SECURITY ENGINEER - DETECTION AND RESPONSE PLATFORM
Company: Cybervahak Consultants Private Limited
Level: Senior Security Engineer
Location: Mumbai, full-time in office
Employment: Full time
Experience: 3 to 6 years in security operations or security engineering, including 2+ years building detection, response or SIEM capability
ABOUT CYBERVAHAK AND GUARDIAN
Cybervahak Consultants is a cybersecurity firm serving banks, payment companies, asset managers and government organisations in India. Guardian is our own security operations platform. It brings SIEM, endpoint detection and response, SOAR, user and entity behaviour analytics, threat intelligence, data loss prevention, vulnerability management and malware sandboxing into one product, with a first-party endpoint agent and connectors for the major XDR and SIEM platforms.
Guardian runs as a standalone appliance, in connected deployments, and in fully air-gapped networks.
ABOUT THE ROLE
We are hiring a senior security engineer who understands security operations at the level of someone who has designed detection and response capability, and who can turn that understanding into the software that delivers it. You will join the Guardian engineering team as a senior security voice, take ownership of the areas of the platform you are best placed to advance, and build them with real discretion.
You will work with senior management on what the platform needs to do for our customers, and with the existing engineering team on how it gets built. You will write code, review code, design subsystems, and be accountable for the quality and correctness of what ships in your areas.
WHAT YOU WILL DO
- Shape the technical direction of Guardian with senior management and the engineering team, and own delivery of the areas you take on, from design through release and operation.
- Design and build detection capability: rule content and the engine that evaluates it, correlation and behavioural analytics, threat intelligence matching, and MITRE ATT&CK; coverage.
- Design and build response capability across the endpoint agent and integrated EDR and XDR platforms, with authorisation and audit trails for every action.
- Build and improve the ingestion path for logs and alerts: intake from endpoints, network devices and third-party platforms, normalisation to a common schema, enrichment and search.
- Develop the SOAR layer: playbook automation, case management, SLAs, escalation and reporting.
- Contribute to the endpoint agent for Linux and Windows: telemetry collection, local detection, content updates and packaging.
- Raise the security of the platform itself, so that it meets the standard our customers apply to their own systems.
- Set the bar on engineering quality in your areas: automated tests, integration and load testing, CI/CD and reproducible releases.
- Review designs and code from other engineers, and bring security operations context to their work.
- Represent the platform technically with customers when needed: proofs of concept, deployment questions and incident-driven feature requests.
WHAT YOU WILL NEED
SECURITY OPERATIONS EXPERTISE
This is the core requirement. You should have built or operated the capabilities Guardian provides, not only used them.
- Detection engineering in depth: Sigma rules, logsource taxonomy, selection and condition logic, aggregation and timeframes, and translating rules onto a normalised schema.
- Log normalisation with Elastic Common Schema or OCSF across Windows event logs and Sysmon, auditd, syslog (RFC 3164 and 5424), CEF and LEEF, firewall, proxy, DNS, VPN and cloud audit logs.
- MITRE ATT&CK; as a working tool for tagging, coverage measurement and prioritising detection work.
- Correlation and behavioural detection: kill-chain sequencing, beaconing analysis, baselining, peer-group comparison, impossible travel, and stateful detection of low-and-slow activity.
- What an EDR sensor must capture and how response actions work: process lineage, file, registry and network telemetry, host isolation, process termination, quarantine and restore, and the operational risk of each.
- Attacker techniques on Windows and Linux, including living-off-the-land, process injection, credential dumping, persistence and ransomware behaviour, at the depth needed to write and test detections for them.
- Threat intelligence and malware analysis: IOC lifecycle, STIX and TAXII, MISP, enrichment services, YARA, and sandbox-based dynamic analysis.
- Incident and case management: triage, severity models, SLAs, escalation, evidence handling and CERT-In reporting obligations.
- Working knowledge of leading EDR, XDR and SIEM platforms and their APIs, such as CrowdStrike Falcon, SentinelOne, Microsoft Sentinel and Defender, Elastic Security, Splunk, IBM QRadar, Google Chronicle and Wazuh.
ENGINEERING ABILITY
- Professional software development experience in TypeScript or Go, ideally both, on production systems, with the habit of testing what you build.
- System design for security platforms: ingestion pipelines, event streaming, durable processing,
tenant data isolation and search indexing, and the trade-offs between them.
- Comfort with relational databases, message streaming and search engines, and with agent software on Linux and Windows.
- Security engineering fundamentals: applied cryptography, secrets management, identity and access control, and secure service-to-service and agent communication.
- Deployment and operations: Docker, Kubernetes and Helm, appliance and air-gapped installation, observability, and release management.
- The ability to write a specification another engineer can build from, and to review their result critically.
EXPERIENCE AND QUALIFICATIONS
- 3 to 6 years in security operations or security engineering, with at least 2 years building detection, response, SIEM, SOAR or UEBA capability at a security product company or in a mature SOC.
- A record of shipping security software or detection content that others rely on: rules, integrations, pipelines or analytics.
- Experience influencing the technical direction of a product as a senior engineer.
- Clear written and spoken communication with engineers, security teams and senior management.
- Experience with eBPF or ETW telemetry, or with kernel-level sensors.
BONUS POINTS (not mandatory)
- GCIA, GCFA, GCDA, OSCP or CISSP.
- Public contributions to Sigma, YARA, Wazuh, Elastic, OCSF or similar projects.
- Prior work with Indian banking, payments or government customers.
WHAT WE LOOK FOR IN YOU Cybervahak is a young and growing company. The person in this role will shape how we build, so we care as much about how you work as what you know.
- Ownership of outcomes: you treat a commitment as yours to deliver, follow problems through to the root cause, and do not wait to be told what to do next.
- Bias for action with sound judgement: you ship working increments, measure them, and correct course quickly rather than waiting for perfect information.
- Comfort with ambiguity: requirements will often arrive as customer conversations and compliance clauses, and you can turn them into a clear technical plan.
- A team player at senior level: you take direction from the business, give direction on the technology, and make the engineers around you better.
- Honesty about status: you report what works, what does not and what it will take, with evidence.
WHAT WE OFFER
- A senior role on a full security platform, with real discretion over how your areas are built.
- A product used by regulated enterprises where your detection and response work matters in real incidents.
- Competitive compensation aligned to experience, with performance-linked increments.
- Equity in the company, offered on the basis of performance.
📌 Senior Security Engineer - Detection and Response Platform (Mumbai)
🏢 Cybervahak Consultants Private
📍 Mumbai