BAS Security Engineer (Chennai)

BAS Security Engineer (Chennai)

04 Oct
|
Quess IT Solutions
|
Chennai

04 Oct

Quess IT Solutions

Chennai

Role & responsibilities

We are hiring an experienced Security Engineer with strong hands-on expertise in Breach and Attack Simulation (BAS) and Security Operations Center (SOC) operations for a leading banking client in Chennai. The ideal candidate will continuously validate the bank's security posture through automated, threat-informed attack simulations mapped to the MITRE ATT&CK; framework, identify detection and prevention gaps across the security stack, and work with SOC, Threat Intelligence, Red Team and Blue Team functions to strengthen detection engineering, incident response and overall cyber resilience.

This is a high-impact role within a regulated BFSI environment, supporting Continuous Security Validation (CSV), Continuous Threat Exposure Management (CTEM) and compliance with the RBI Cyber Security Framework.

Key Responsibilities Breach & Attack Simulation (BAS)

- BAS Platform Ownership: Deploy, configure, administer and maintain BAS platforms such as SafeBreach, AttackIQ, Cymulate, Picus Security, XM Cyber or Pentera, including simulator/agent deployment across endpoints, servers, network segments and cloud workloads.
- Threat-Informed Simulations: Design, schedule and execute automated attack simulations mapped to MITRE ATT&CK; tactics, techniques and procedures (TTPs) across the full cyber kill chain initial access, execution, persistence, privilege escalation, defense evasion, credential access, lateral movement, command and control (C2) and data exfiltration.
- BFSI Threat Scenarios: Emulate real-world adversaries and threat actors targeting the banking sector, including ransomware operators, APT groups, banking trojans, phishing and business email compromise (BEC) campaigns, using current Cyber Threat Intelligence (CTI).
- Security Control Validation:



Measure the effectiveness of security controls including EDR/XDR, SIEM, NGFW, IPS/IDS, WAF, Secure Email Gateway, Web Proxy/SWG, DLP, NAC and Active Directory security.
- Gap Analysis & Remediation: Identify prevention and detection gaps, perform risk-based prioritization, and drive remediation with control owners and platform teams.
- Re-testing & Posture Tracking: Validate remediation through re-testing, track security control effectiveness and detection coverage trends over time, and support measurable security posture improvement.
- Custom Scenario Development: Build and maintain custom attack scenarios, assessment templates and simulation playbooks using Python, PowerShell or Bash.
- Reporting & Metrics: Produce executive dashboards, KPIs/KRIs and technical reports on control efficacy, MITRE ATT&CK; coverage and risk reduction for CISO, security leadership, internal audit and regulators.

Required Skills & Qualifications
- 3–4 years of experience in Cybersecurity, Security Operations or Offensive/Defensive Security, preferably in the BFSI domain.
- Minimum 1–2 years of hands-on experience with at least one BAS tool – SafeBreach, AttackIQ, Cymulate, Picus, XM Cyber or equivalent.
- Strong working knowledge of the MITRE ATT&CK; framework, Cyber Kill Chain, adversary emulation and TTP analysis.
- Hands-on experience with SIEM platforms – Splunk, IBM QRadar, Microsoft Sentinel,



ArcSight or Securonix – including query languages (SPL, KQL, AQL).
- Experience with EDR/XDR solutions – CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Trellix or Carbon Black.
- Solid understanding of network security, TCP/IP, firewalls, proxies, email security, Windows and Linux internals, and Active Directory attack techniques (Kerberoasting, Pass-the-Hash, DCSync).
- Valuable knowledge of incident response, log analysis, malware behavior and threat intelligence concepts (IOCs, IOAs, STIX/TAXII).
- Scripting and automation skills in Python and/or PowerShell.
- Awareness of banking security regulations – RBI Cyber Security Framework, CERT-In directions, PCI-DSS, ISO 27001, NIST CSF.
- Strong analytical, documentation and communication skills, with the ability to present technical findings to non-technical and executive stakeholders.

Good to Have
- Certifications: CEH, OSCP, eCPPT, CompTIA Security+ / CySA+ / PenTest+, GIAC (GCIH, GCIA, GCED), CRTP, or vendor BAS certifications (AttackIQ Academy, Picus, Cymulate).
- Experience with open-source adversary emulation tools – Atomic Red Team, MITRE Caldera, Infection Monkey – or C2 frameworks such as Cobalt Strike, Sliver or Mythic.
- Exposure to SOAR platforms (Splunk SOAR, Cortex XSOAR, IBM Resilient).
- Cloud security experience in AWS and/or Azure, including cloud attack simulation.
- Experience with vulnerability management tools (Tenable, Qualys, Rapid7) and attack surface management.
- Prior experience in a 24x7 BFSI SOC or Managed Security Services (MSSP) environment.

Education Bachelor's degree (B.E./B.Tech/B.Sc./BCA/MCA) in Computer Science, Information Technology, Electronics, Cybersecurity or a related field.

📌 BAS Security Engineer (Chennai)
🏢 Quess IT Solutions
📍 Chennai

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: bas security engineer (chennai) / chennai