17 Sep
|
hotsourced
|
India
About the job
Security Integration Engineer
Remote | Full-Time | Permanent | Cybersecurity / Technology
Placed by Hotsourced – connecting top Indian talent with world-class global companies
This is an exciting opportunity to join a technology company operating in the cybersecurity space, helping customers connect, understand, and act on security data from a diverse range of tools and platforms.
Our client is looking for a hands-on Security Integration Engineer to join their platform engineering team. Reporting to the CTO, you will own the full lifecycle of security technology integrations—from researching a new vendor's API and designing data pipelines through to launching and supporting integrations in production.
The role combines integration engineering, security data operations, and incident investigation. You'll build new integrations, ensure existing deployments continue to run reliably, and use your understanding of security tools and complex data flows to investigate customer security incidents.
Company Description
Our client is a technology company operating within the cybersecurity space, bringing together data from multiple security vendors and platforms to give customers greater visibility into their security posture.
The platform works across endpoint protection, email security, vulnerability management, browser security, device management, identity, cloud security, and data loss prevention technologies.
With a strong focus on practical engineering and technical depth, the team values people who can take ownership of complex problems, work methodically across multiple systems, and deliver reliable solutions from initial investigation through to production.
About The Role
We are looking for a Security Integration Engineer who is equally comfortable building new integrations, troubleshooting production systems, and investigating complex security events.
You will take ownership of integrations from the first API call through to production support. This includes evaluating vendor APIs, building collectors and data pipelines using Cribl, normalising security data, and ensuring it can reliably power dashboards and reports within Splunk or OpenSearch.
Alongside integration development, you will support existing customer deployments and investigate situations where data or a customer's security posture does not look right. You'll need to trace problems across multiple services, vendors, and datasets to identify root causes and communicate your findings clearly.
This role will suit someone who enjoys technical ownership, values data quality, and can move confidently between planned engineering work and urgent customer investigations.
Responsibilities - What you'll be doing:
New Integrations
- Researching and evaluating security vendor APIs and data sources to understand technical feasibility and scope before committing to a build.
- Designing and building collectors, pipelines, and data routes using Cribl to ingest security data from new vendors.
- Parsing, enriching, and normalising raw security data so that it can power downstream dashboards and reports within Splunk or OpenSearch.
- Testing integrations end-to-end and validating data correctness before release.
- Taking ownership of integrations throughout their lifecycle, from the first API call through to ongoing production support.
Supporting Existing Integrations and Customers
- Monitoring, maintaining, and continuously improving integrations already running in production.
- Diagnosing and resolving data correctness issues, including missing fields, duplicate records, and other data-quality problems.
- Improving data pipelines to reduce noise, optimise storage costs, and improve query performance.
- Troubleshooting customer-facing issues relating to security tools and data availability.
- Keeping integrations aligned with changes, updates, and deprecations to vendor APIs.
Security Investigations
- Working with customers and support teams to investigate suspicious activity within customer environments.
- Correlating data across multiple security vendors and systems to develop a complete picture of security events.
- Leading root cause analysis when an incident touches multiple tools, services, or data sources.
- Querying and analysing large datasets from endpoint, email, network, identity, and cloud security sources.
- Documenting investigation findings and providing clear recommendations.
Requirements - What we're looking for:
We think the right candidate will tick most of the following boxes:
- Strong working knowledge of Splunk or OpenSearch, including experience writing and maintaining searches, dashboards, and knowledge objects.
- Ability to optimise Splunk or OpenSearch queries for large datasets.
- Hands-on experience with Cribl, including building pipelines, transforms, routes, and processing logic.
- Backend development experience, including building APIs, Lambda functions, or similar serverless solutions.
- Practical knowledge of security technologies such as endpoint protection, email security, vulnerability scanning, browser security, device management, identity products, cloud security,
or data loss prevention.
- Confidence reading vendor API documentation, evaluating technical capabilities, and determining what is feasible to integrate.
- Experience debugging complex systems and tracing problems across multiple services and data sources to identify the root cause.
- Experience working with AWS APIs and services, particularly technologies such as Lambda and S3.
- Strong written and verbal communication skills, with the ability to explain technical findings and decisions to both technical and non-technical audiences.
- A methodical approach to debugging combined with the ability to make pragmatic technical decisions.
- A solid sense of ownership and accountability for both the functionality and quality of the systems you build.
Valuable Experience - Nice to Have:
- Previous experience in incident response or threat investigation.
- Knowledge of identity and access management, particularly SAML and enterprise SSO.
- Experience with data enrichment techniques and Redis.
- Familiarity with threat intelligence and detection engineering.
- Experience building Slack integrations or working with the Slack API.
- Practical experience integrating security platforms such as CrowdStrike, SentinelOne, Proofpoint, Trellix, Nessus, DefensX, Microsoft Intune, Auth0, or comparable technologies.
What You'll Work With
Core tools include:
- Cribl – pipeline development and security data routing.
- Splunk or OpenSearch – analytics, searches, and dashboards.
- AWS services – including Lambda, APIs, and S3.
- Slack – team communication, alerts, and integrations.
Typical security integrations include:
- Endpoint protection and EDR.
- Email security.
- Vulnerability scanning.
- Browser security.
- Mobile and device management.
- Identity platforms.
- Cloud security.
- Data loss prevention.
Work Schedule
This is a full-time, remote position.
Specific working hours and required time-zone coverage have not been provided and should be confirmed with the client before publication.
Pay & Benefits - What we offer:
- Annual Compensation : 14,00,000 to 20,00,000 per annum
- A fully remote working environment.
- A hands-on engineering role with significant technical scope and ownership.
- The opportunity to work across a diverse range of cybersecurity technologies, platforms, and vendors.
- A team environment that values deep technical knowledge and practical problem-solving.
- Flexibility to work across both strategic integration projects and urgent customer issues.
- The opportunity to own projects end-to-end rather than handing work between teams at each stage.
- Exposure to complex security datasets and real-world customer security investigations.
📌 Security Integration Engineer (India)
🏢 hotsourced
📍 India