04 Oct
|
Soffit Infrastructure Services (P
|
Chennai
04 Oct
Soffit Infrastructure Services (P
Chennai
Security Engineer – Breach & Attack Simulation (BAS)
Location: Chennai, Tamil Nadu
Work Mode: Work from Office
Experience: 2+ Years
Employment Type: Full time
Job Overview
We are hiring a Security Engineer – Breach & Attack Simulation (BAS)
The candidate will be responsible for validating security controls through threat-informed attack simulations, identifying prevention and detection gaps, and working closely with SOC, Threat Intelligence, Red Team and Blue Team functions.
Key Responsibilities
- Deploy, configure and administer BAS platforms such as SafeBreach, AttackIQ, Cymulate, Picus, XM Cyber or Pentera.
- Design and execute attack simulations mapped to the MITRE ATT&CK; framework.
- Simulate real-world threats including ransomware, phishing, BEC, credential theft, lateral movement and C2 activity.
- Validate controls including EDR/XDR, SIEM, NGFW, IDS/IPS, WAF, email security, proxy/SWG, DLP and NAC.
- Identify detection and prevention gaps and coordinate remediation.
- Perform re-testing to validate security improvements.
- Develop custom attack scenarios using Python, PowerShell or Bash.
- Prepare technical reports, dashboards and security metrics.
- Work with SOC, Threat Intelligence, Red Team and Blue Team teams.
Required Skills
- 2+ years of cybersecurity/SOC/offensive or defensive security experience.
- 1–2+ years of hands-on BAS experience with SafeBreach, AttackIQ, Cymulate, Picus, XM Cyber, Pentera or equivalent.
- Strong knowledge of MITRE ATT&CK;, Cyber Kill Chain and adversary emulation.
- Hands-on SIEM experience with Splunk, QRadar, Microsoft Sentinel, ArcSight or Securonix.
- Knowledge of SPL/KQL/AQL or equivalent query languages.
- Experience with EDR/XDR solutions such as CrowdStrike, Microsoft Defender, SentinelOne, Trellix or Carbon Black.
- Knowledge of network security, Windows/Linux, Active Directory and common attack techniques.
- Understanding of incident response, malware behavior and threat intelligence.
- Python and/or PowerShell scripting experience.
- Awareness of RBI Cyber Security Framework, CERT-In, PCI-DSS, ISO 27001 and NIST CSF.
Good to Have
- CEH / OSCP / Security+ / CySA+ / PenTest+ / GIAC or relevant BAS certifications.
- Atomic Red Team / MITRE Caldera / Infection Monkey.
- Cobalt Strike / Sliver / Mythic.
- SOAR experience.
- AWS/Azure security experience.
- Vulnerability/attack surface management experience.
- BFSI SOC/MSSP experience.
Education
B.E./B.Tech/B.Sc./BCA/MCA in Computer Science, IT, Electronics, Cybersecurity or a related field.
Pay: ₹400,000.00 - ₹850,000.00 per year
Application Question(s):
- How many years of cybersecurity/SOC /BAS experience do you have?
- Which BAS platform(s) have you worked with?
- Have you worked with MITRE ATT&CK; mapping and adversary emulation?
- Which SIEM /EDR/XDR tools have you worked with?
- Do you have hands-on experience with Python, PowerShell or Bash?
- Do you have experience in BFSI/banking cybersecurity?
- What is your current ctc & expected ctc?
- Are you an immediate joiner?
Work Location: In person
📌 Security Engineer – Breach & Attack Simulation (BAS) (Chennai)
🏢 Soffit Infrastructure Services (P
📍 Chennai