Security Engineer III
Job description
About the role
This role focuses on designing, building, and enhancing security operations capabilities for a global SaaS platform that serves Fortune 50 customers. The position bridges engineering and security operations to create scalable, automated defenses. Success in this role supports the company's mission of optimizing business decision-making through its AI-infused scenario planning and analysis platform. Security professionals protect systems, data, and users by reviewing code, running tests, monitoring threats, and responding to incidents. The field spans application security, infrastructure security, and governance, requiring careful, evidence-based work that constantly evolves. Security teams operate in a landscape of constant change, facing new threats and new rules every year, where most companies invest heavily in training and tooling. This position demands a high level of ownership and judgment to advance the security posture of a mission-critical SaaS platform.
Key facts
What you'll do
Design, build, and enhance detection capabilities by managing the SIEM platform, normalizing log sources, and improving data quality to broaden coverage and performance.
Create and maintain SOAR playbooks to automate alert triage, enrichment, and response, and identify manual security operations processes for automation to improve scalability.
Provide engineering support during security incidents by aiding investigation, containment, and recovery, and contribute to post-incident reviews to translate lessons into improved detections and playbooks.
Bring extensive hands-on security engineering experience, particularly in cloud-native environments and modern application stacks, within complex organizations.
Demonstrate practical skills in developing and tuning SIEM detections, writing threat hunting queries, and participating in incident response in SecOps environments.
Administer and operate core security tools such as SIEM platforms (for example, Splunk or Microsoft Sentinel), EDR/XDR solutions, and vulnerability scanners, with experience integrating these tools for detection and response workflows.
Show familiarity with threat intelligence platforms and feeds (for example, MISP, Recorded Future, VirusTotal), and the ability to integrate intelligence into security tooling and detection logic, with knowledge of threat hunting methodologies being highly desirable.
Write scripts and programs in languages such as Python, Go, or Bash to build security tools and automate workflows.
Understand secure development practices, OWASP top risks, and have experience collaborating with developers on security findings in code reviews.
Apply knowledge of security frameworks such as NIST CSF, CIS Benchmarks, and MITRE ATT&CK, and familiarity with compliance standards like SOC 2 or ISO 27001.
Communicate technical security risks and recommendations clearly to diverse stakeholders and work cross-functionally to achieve security objectives.
Lead or support security incident investigations, including evidence preservation, log analysis, timeline reconstruction, and root cause identification, with familiarity of forensic tools and methodologies highly valued.
Requirements
Bring extensive hands-on security engineering experience, particularly in cloud-native environments and modern application stacks, within complex organizations.
Demonstrate practical skills in developing and tuning SIEM detections, writing threat hunting queries, and participating in incident response in SecOps environments.
Administer and operate core security tools such as SIEM platforms (for example, Splunk or Microsoft Sentinel), EDR/XDR solutions, and vulnerability scanners, with experience integrating these tools for detection and response workflows.
Show familiarity with threat intelligence platforms and feeds (for example, MISP, Recorded Future, VirusTotal), and the ability to integrate intelligence into security tooling and detection logic, with knowledge of threat hunting methodologies being highly desirable.
Write scripts and programs in languages such as Python, Go, or Bash to build security tools and automate workflows.
Understand secure development practices, OWASP top risks, and have experience collaborating with developers on security findings in code reviews.
Apply knowledge of security frameworks such as NIST CSF, CIS Benchmarks, and MITRE ATT&CK, and familiarity with compliance standards like SOC 2 or ISO 27001.
Communicate technical security risks and recommendations clearly to diverse stakeholders and work cross-functionally to achieve security objectives.
Lead or support security incident investigations, including evidence preservation, log analysis, timeline reconstruction, and root cause identification, with familiarity of forensic tools and methodologies highly valued.
Practical notes
This position is based in Gurugram, India, and requires eligibility to work in the country without company-sponsored visa assistance.
The role may involve periodic travel within assigned regions as required by operational needs.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.
Good to know
Security engineers in this role commonly work with SIEM, SOAR, EDR/XDR, and threat intelligence platforms on enterprise cloud and SaaS environments.
Detection as code, automated playbooks, and AI-augmented workflows are modern practices for scaling security operations in fast-growing technology companies.
Threat hunting, incident response, and security automation are central to reducing risk and improving resilience for organizations that handle large volumes of sensitive data.
Understanding security frameworks, compliance standards, and secure development practices helps integrate security into delivery pipelines and stakeholder communications.