MDR Security Analyst/Engineer – (Chennai)

MDR Security Analyst/Engineer – (Chennai)

30 Sep
|
Santan Intellect
|
Chennai

30 Sep

Santan Intellect

Chennai

We're Hiring: MDR Security Engineer – L3 | Chennai (On-site) | 5+ Yrs | Full-Time

Security Monitoring, Detection Engineering and Automation for a Microsoft-Centric MDR/SOC Environment

Experience: 5+ Years

Employment Type: Full-Time, Permanent (Santan Infotech Pvt Ltd)

Location: Chennai, Tamil Nadu, India

Reports To SOC Manager – MDR Operations, Santan Intellect

Domain: Managed Detection and Response (MDR) | Security Operations | Microsoft Security

:

This position is responsible for operating and enhancing a Microsoft-centric MDR/SOC environment built on Microsoft Sentinel, delivered through Microsoft's unified security operations platform in the Defender portal, together with SOAR, security automation, API-based integrations and emerging agentic AI capabilities.

Within Santan

Intellect's Managed Detection and Response (MDR) practice, this position creates direct value by closing the gap between a raw security alert and a resolved incident, protecting client environments from real operational and financial impact.

This position is responsible for security monitoring, L3 alert investigation, incident triage, threat detection and continuous improvement of the MDR services Santan Intellect delivers to its clients. Strong Sentinel and KQL depth matters here, and so does the judgment to correlate signals across endpoint, identity, email, network, cloud and application telemetry to determine real incident scope and impact quickly.

This position combines a robust foundation in cyber security and SOC operations with hands-on scripting, API integration and automation skills, developing and tuning detection content, building API-based integrations between Sentinel and the broader security technology stack and applying automation and agentic AI capabilities to reduce manual, repetitive SOC work. The result is a faster, more consistent MDR service and more analyst time available for genuine investigative work.

Key Responsibilities

MDR/SOC Operations

- Monitor security alerts and perform L2/L3 triage, investigation, correlation and escalation across the MDR platform.
- Analyze security incidents across endpoint, identity, email, network, cloud and application environments, using SIEM, EDR/XDR, identity and cloud telemetry.
- Investigate suspicious activity to determine incident severity, impact and scope, and support threat hunting and detection engineering activities.
- Maintain accurate incident documentation and investigation timelines, and follow defined MDR playbooks, SOPs, SLAs and escalation procedures.

Microsoft Sentinel, SIEM & Connector Engineering

- Use Microsoft Sentinel for day-to-day security monitoring, incident investigation and threat hunting.
- Develop and tune KQL queries, analytics rules and detection use cases, and perform alert tuning to reduce false positives and improve detection quality.
- Configure, troubleshoot and maintain Microsoft Sentinel data connectors, integrating security products and customer technologies using REST APIs, Syslog, CEF, webhooks, Azure Functions, Logic Apps and the Microsoft Graph API.
- Build workbooks and dashboards for SOC/MDR monitoring,



monitor data ingestion for telemetry gaps and support onboarding of new log sources into Microsoft Sentinel.

SOAR, Security Automation & Scripting

- Develop and maintain Microsoft Sentinel automation rules and playbooks, using Microsoft Logic Apps for security orchestration and automation.
- Automate repetitive SOC activities such as alert enrichment, IOC lookup, IP and domain reputation checks, threat intelligence enrichment, user and account investigation, ticket creation and automated containment or blocking.
- Develop scripts in Python, PowerShell or Bash to consume REST APIs, parse JSON and XML responses and automate repetitive operational activities.
- Integrate security tools using APIs, applying Python and PowerShell experience specifically to Microsoft security technologies.

Microsoft Security Ecosystem & Cloud Security

- Understand how telemetry from Microsoft Sentinel, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity and Microsoft Defender for Office 365 integrates into a centralized MDR/SOC platform.
- Work with Microsoft Entra ID and Microsoft Entra ID Protection signals as part of identity-centric investigation and detection.
- Support Microsoft Intune and Microsoft Purview telemetry and control points where they intersect with security monitoring and investigation.
- Apply cloud security fundamentals, including awareness of container and Kubernetes security and infrastructure-as-code security, when investigating cloud-hosted workloads.

Threat Detection, Threat Intelligence & Agentic AI

- Develop and maintain security detection use cases, and apply the MITRE ATT&CK; framework to understand common attacker techniques.
- Perform indicator-based investigation and enrichment across IP addresses, domains, URLs, file hashes, user accounts and hostnames, and integrate threat intelligence feeds into the MDR/SIEM environment.
- Apply generative and agentic AI capabilities, including Microsoft Security Copilot's built-in agents such as the Phishing Triage Agent and Security Alert Triage Agent, to alert triage, investigation summarization, threat intelligence enrichment and security knowledge retrieval.
- Identify additional opportunities to apply AI to detection engineering, threat hunting and automated response as agentic SOC capabilities mature.

MDR Engineering & Continuous Improvement

- Participate in customer onboarding and security log-source integration, and identify telemetry and detection gaps across onboarded environments.
- Develop new detection rules and use cases, and tune existing detection rules based on observed incident trends.
- Develop automation that measurably improves mean time to detect and mean time to respond.
- Maintain technical documentation, playbooks and runbooks so MDR service delivery is not dependent on a single analyst's institutional knowledge.





Required Experience

- 2–5 years of experience in cyber security, SOC, MDR, SIEM or security operations, including hands-on L2/L3 alert triage and investigation.
- Hands-on experience with Microsoft Sentinel for security monitoring, incident investigation and detection engineering, including KQL query development.
- Working knowledge of SIEM and SOAR concepts, REST API and JSON fundamentals and API-based security tool integration.
- Scripting experience in Python, PowerShell or Bash, applied to security automation and operational tasks.
- Working understanding of the MITRE ATT&CK; framework and cloud security fundamentals, including container, Kubernetes and infrastructure-as-code security.
- Ability to work effectively in a 24x7 SOC environment, under incident-response timelines and SLA requirements.

Required Technical Expertise

Category Technologies

MDR/SOC Operations

L2/L3 alert triage and investigation, incident severity and scope determination, MDR playbooks, SOPs and SLA-driven escalation

Microsoft Sentinel, SIEM & Connectors:

Microsoft Sentinel and the unified security operations platform (Defender portal), KQL, analytics rules, data connectors, workbooks and dashboards

SOAR & Automation

Microsoft Sentinel automation rules and playbooks, Microsoft Logic Apps, Python, PowerShell or Bash scripting, REST API integration

Microsoft Security Ecosystem

Microsoft Defender XDR, Defender for Endpoint, Defender for Identity, Defender for Office 365, Microsoft Entra ID, Microsoft Intune, Microsoft Purview

Threat Detection & Intelligence

MITRE ATT&CK;, IOC-based investigation, threat intelligence feed integration, Microsoft Security Copilot agents

Cloud & Platform Security

Cloud security fundamentals, container and Kubernetes security, infrastructure-as-code security

Familiarity with additional ecosystem tools (for example, Microsoft Security Copilot, Microsoft Agent 365 or SOAR platforms outside the Microsoft stack) is a plus, not a requirement. Training is provided on Santan Intellect's specific configuration and toolset.

Preferred Certifications

- One or more of the following certifications is an advantage: Microsoft Certified: Security Operations Analyst Associate (SC-200), Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Microsoft Certified: Cloud and AI Security Engineer Associate (SC-500).
- An equivalent SOC, SIEM or cloud security certification is also acceptable in place of the certifications above.

Education

- Bachelor's or master's degree in cyber security, information security, computer science or information technology or related field
- A cyber security-focused degree combined with strong practical SOC or MDR skills is preferred.

Soft Skills

- Strong analytical and problem-solving skills, applied under real incident-response timelines and SLA pressure.
- Good written and verbal communication, including clear incident documentation and escalation.
- Willingness and ability to work in a 24x7 SOC setting, including rotational shifts, when required.
- Ability to work collaboratively across SOC, engineering, threat intelligence and incident response teams.

📌 MDR Security Analyst/Engineer – (Chennai)
🏢 Santan Intellect
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: mdr security analyst/engineer – (chennai) / chennai

Subscribe to this job alert:

Get the latest job offers by email for: mdr security analyst/engineer – (chennai) / chennai