Endpoint Security Engineer (Hyderabad)

Endpoint Security Engineer (Hyderabad)

24 Sep
|
CloudAI Technologies
|
Hyderabad

24 Sep

CloudAI Technologies

Hyderabad

Position Summary The Endpoint Security Engineer owns the security of CloudAIs endpoint, identity, and application estate, running on top of our Microsoft 365, Azure, and AWS cloud platforms. This endpoint-anchored role keeps our devices, identities, and business applications hardened and monitored day to day, while progressively deepening into security-as-code and cloud security engineering. It reports to the Platform Engineering lead and partners with our Cloud Platform, Data, and Dev teams to weave security into their daily operations and every release cycle.

Key Responsibilities

- Endpoint &
- Identity Security:

Define and maintain Microsoft Intune baselines (CIS Benchmarks) for Windows and macOS; configure Microsoft Defender for Endpoint, Identity, and Office; enforce least-privilege, MFA, and Conditional Access through Entra ID and Privileged Identity Management (PIM).

- Vulnerability Management: Own vulnerability management across the endpoint estate using Microsoft Defender Vulnerability Management; discover, prioritize, and drive remediation to closure against defined SLAs.

- Application Control: Implement application control (allowlisting and blocklisting via App Control for Business / WDAC) and manage application deployment and protection policies in Intune.

- Enterprise &

- Third-Party App Management:

Own the application lifecycle in Entra ID, including app registrations, enterprise app onboarding, OAuth consent governance, and SSO and SCIM provisioning for business applications (e.g., GitHub, Atlassian, Google Workspace, HubSpot); inventory and score SaaS apps via CASB or SSPM tooling.

- Data &

- Access Protection:

Encrypt and monitor OneDrive, SharePoint, and shared storage; implement Data Loss Prevention (DLP) and sensitivity labels; conduct periodic access reviews and support third-party risk assessments.

- Security Operations &

- Monitoring:

Roll out Microsoft Entra Global Secure Access (SSE / ZTNA) policies for remote users; correlate logs across Sentinel, AWS Security Hub,



and SaaS APIs; tune alerts and playbooks to spot and escalate issues.

- Incident Response: Develop and test Incident Response (IRP) plans and playbooks; own containment and eradication; lead post-incident retrospectives.

- Compliance &

- Enablement:

Map controls to frameworks (CIS Controls, SOC 2) and drive evidence collection; deliver quarterly security awareness training and phishing simulations.

- Security Automation (desired): Build and maintain security IaC modules (Terraform / CloudFormation) for GuardDuty, Security Hub, IAM SCPs, and CloudTrail lake; integrate security findings into CI/CD (e.g., GitHub Actions) with automated ticketing; deepen ownership of AWS security services and cloud guardrail engineering over time.

Technical Competencies

- Microsoft endpoint and identity stack: Intune, Defender (Endpoint / Identity / Office), Defender Vulnerability Management, Entra ID, Conditional Access, and PIM.

- Application control and management: App Control for Business / WDAC, plus Intune application deployment and protection policies.

- Enterprise and third-party application management: app registrations, enterprise apps, OAuth consent governance, and SSO / SCIM (SAML / OIDC).

- Microsoft Entra Global Secure Access (SSE / ZTNA), DLP, and sensitivity labels.

- SIEM / SOAR (Microsoft Sentinel) and SaaS Security Posture Management (SSPM).

- Working understanding of security engineering: infrastructure-as-code (Terraform / CloudFormation), CI/CD pipelines, and AWS security services (GuardDuty, Security Hub, IAM, CloudTrail, KMS).

- Scripting and automation in PowerShell, Python, or Bash.





- Security frameworks: CIS Controls, SOC 2, ISO 27001, and NIST CSF.

Core Competencies

- Ownership and Delivery: Takes ownership, honors commitments, moves with urgency, and delivers their best work

- Curiosity and Growth: Goes deep to understand the 'why,' stays open to new ideas, and challenges the status quo

- Candor and Collaboration: Leads with transparency, welcomes thoughtful disagreement, and chooses the path based on the merit of ideas

- Empathy and Respect: Listens to understand, respects others' perspectives, and acts as a team player

- Customer and Business Focus: Starts with the customer, works efficiently, and delivers lasting value through continuous improvement

Education &

Experience Requirements

- 4 to 5 years in endpoint administration or security operations, with hands-on ownership of the Microsoft 365 security stack (Intune, Defender, Entra ID).

- Demonstrated experience with vulnerability management and application control (e.g., Defender Vulnerability Management, App Control for Business / WDAC, allowlisting).

- Working knowledge of identity and access management, including enterprise and third-party application management and SSO / SCIM provisioning.

- A working understanding of security engineering (infrastructure-as-code, CI/CD pipelines, and AWS security services), with the appetite to deepen it into full ownership.

- Bachelor’s degree in Computer Science, Computer Engineering, or a related field (or equivalent practical experience).

- Desired: production experience writing security IaC, hands-on AWS security depth in a multi-cloud workplace, and exposure to SIEM / SOAR and SSE / ZTNA products.

Certifications

- Microsoft SC-200 (Security Operations Analyst) or SC-300 (Identity and Access Administrator)

- Microsoft MD-102 (Endpoint Administrator)

- CompTIA Security+

- Preferred: Microsoft AZ-500 (Azure Security Engineer Associate)
- AWS Certified Security – Specialty

📌 Endpoint Security Engineer (Hyderabad)
🏢 CloudAI Technologies
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: endpoint security engineer (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: endpoint security engineer (hyderabad) / hyderabad