Security Engineer III -SOC
Job description
About the role
This role is centered on the design of detection logic and the construction of automation for security workflows. The hire will exercise strong engineering judgment to create scalable and repeatable security operations. You will translate ambiguous threats into guarded systems and clearly defined processes. The position demands ownership of complex security challenges and the delivery of robust operational solutions. Success in this role is measured by the effectiveness and efficiency of the security operations you build. You will work closely with cross-functional partners to ensure security controls align with business objectives. The role requires a proactive mindset and a commitment to continuous improvement in security posture.
Key facts
What you'll do
- Design intake pipelines that normalize diverse telemetry into structured security datasets to ensure all relevant data is available for analysis and investigation.
- Build parsers and detection content using version control workflows for SIEM platforms to support consistency and enable peer review.
- Review alert quality and tune playbooks with the specific goal to reduce noise while preserving true positives and minimizing false alerts.
- Ship automated response playbooks through SOAR systems to accelerate triage cycles and reduce manual effort during security events.
- Partner with threat intelligence teams to integrate adversary context into detection logic and playbooks to improve relevance and accuracy.
- Operate threat hunting hypotheses to uncover hidden attacker behaviors by investigating across endpoints, networks, and cloud environments.
- Support incident response with engineering depth during active security events, participating in containment and recovery activities.
- Validate log coverage and data fidelity to ensure platform reliability and consistency over time.
- Analyze telemetry sources to identify gaps in visibility and drive improvements in data collection.
- Collaborate with engineers to enhance the integrity and performance of security data pipelines.
Requirements
- Hands on experience with SIEM engineering and log normalization is mandatory, and you must have worked in complex environments.
- Practical skills in detection engineering and threat hunting using ATT&CK frameworks are essential, and you should be able to create and refine rules effectively.
- Expertise in SOAR automation and security orchestration workflows is required, and you must understand how to design and maintain playbooks.
- Experience with AI augmented security operations and responsible use of ML tools is required, and you should evaluate how these tools integrate safely.
- Integration of threat intelligence into detection logic and playbooks must be part of your history, and you should have prior examples of this work.
- You should demonstrate proactive threat hunting and post incident review capabilities, with documenting findings as a key part of this responsibility.
- Providing engineering support during incidents and contributing to detection improvements is mandatory, and participation in reviews is expected.
- A solid understanding of log sources, data pipelines, and platform performance tuning is needed, and you should identify bottlenecks and inefficiencies.
- You must be able to work within the constraints and requirements specific to the Gurugram location.
- Commitment to adhering to the security policies and standards defined by the organization is required.
Nice to have
- Familiarity with modern cloud native environments is beneficial. Experience with common security tooling is also advantageous.
Skills and tools
- You will work with SIEM platforms, SOAR platforms, and threat intelligence sources. Knowledge of the MITRE ATT&CK framework is necessary.
Practical notes
- Ensure all information aligns with current opportunities before proceeding.
- The role is based in Gurugram, India and is a full-time position.
- The compensation package for this role is 27.5 LPA.
- Candidates must be available to start within the timeframe specified in the official opportunity.
- Relocation support, if applicable, will be handled according to company policy and local regulations.
- Security clearance requirements, if any, will be communicated during the hiring process.
- The day-to-day responsibilities require sustained focus and collaboration across distributed teams.
- Proficiency in English is necessary for effective communication within the global team.
- The successful candidate must comply with all onboarding and training requirements without delay.
- Work authorization valid for the duration of the engagement must be maintained.
- This position involves monitoring and analyzing sensitive security data as part of daily operations.
- The role may require periodic reviews of security posture and adjustments to detection strategies.
- All activities must be conducted in accordance with company policies and industry best practices.
- The position reports to a senior security engineer and participates in technical design discussions.
- The workload may vary based on the security posture and emerging threats.
- Continuous learning is expected to keep pace with evolving security tools and methodologies.
- The hire will be responsible for maintaining documentation related to detection logic and response playbooks.
- Collaboration with product and engineering teams is essential to ensure security is integrated into the development lifecycle.
- The role contributes to the overall reliability and trustworthiness of the Anaplan platform.
- Long term success in this role is defined by the ability to automate security processes and improve detection accuracy.
- The position requires a balance of technical depth and operational discipline.
- The work environment demands attention to detail and strong problem-solving skills.
- You will be expected to mentor junior team members on security best practices over time.
- The role supports the broader mission of enabling structured planning and decision information for clients.
- Security engineering tasks will be tracked using standard project management tools.
- The use of version control for security content is a standard practice in this role.
- You will participate in regular incident response drills to maintain readiness.
- The position requires active engagement in security communities within the organization.
- Feedback from peers and stakeholders will be used to refine security processes continuously.
- The role involves a significant amount of hands on work with security tools and platforms.
- You will need to manage multiple priorities in a fast moving security operations environment.
- The success of the security program depends on the accuracy and efficiency of the automation you build.
- You will be required to document investigations and share knowledge with the security team.
- The position contributes to reducing the mean time to detect and respond to security incidents.
- The role interacts with external vendors and partners when necessary for security integration.
- You will analyze security trends to inform future detection strategies.
- The position requires a methodical approach to troubleshooting complex security issues.
- You will work with limited supervision once initial training is complete.
- The role supports the continuous improvement of the security operations center maturity.
- You will be expected to adhere to strict data privacy and confidentiality guidelines.
- The position involves monitoring security metrics to measure the effectiveness of controls.
- You will help define security requirements for new systems and integrations.
- The role requires coordination with security vendors to optimize tool performance.
- You will participate in post mortem activities to prevent future incidents.
- The position supports the development of security roadmaps aligned with business goals.
- You will leverage data analytics to drive improvements in security operations.
- The role requires a commitment to maintaining up to date knowledge of threat landscapes.
- The position contributes to the development of security playbooks and standard operating procedures.
- You will work with security architects to align detection strategies with architectural standards.
- The role supports the implementation of security best practices across the organization.
- The position requires the ability to work independently and as part of a team.
- You will engage with the security community to share insights and improve practices.
- The role involves the use of advanced security tools and technologies.
- The position requires a dedication to maintaining a strong security culture within the team.
- You will contribute to the security awareness and training initiatives within the organization.
- The role supports the mitigation of security risks across the enterprise.
- The position requires a thorough understanding of security frameworks and regulations.
- You will work to ensure compliance with security policies and standards.
- The role involves the analysis of security incidents to identify root causes.
- The position supports the development of metrics to track security performance.
- You will collaborate with legal and compliance teams on security matters.
- The role requires the ability to communicate technical concepts to non-technical stakeholders.
- The position supports the integration of security into the software development lifecycle.
- You will work to improve the efficiency of security operations through automation.
- The role requires a commitment to continuous improvement and learning.
- The position contributes to the overall security strategy of the organization.
- You will work with data scientists and analysts to improve security data insights.
- The role supports the implementation of security controls across the enterprise.
- The position requires the ability to manage security tools and configurations.
- You will participate in the evaluation of new security technologies.
- The role supports the maintenance of security baselines and benchmarks.
- The position requires the ability to troubleshoot security issues in a timely manner.
- You will work to improve the security posture of the organization over time.
- The role supports the development of security policies and procedures.
- The position requires a strong understanding of security principles and practices.
- You will collaborate with engineering teams to ensure security is built into products.
- The role supports the monitoring of security alerts and incidents around the clock.
- The position requires the ability to work under pressure during security incidents.
- You will contribute to the improvement of security processes and tools.
- The role supports the alignment of security practices with industry standards.
- The position requires the ability to manage security-related documentation.
- You will work to improve the security awareness across the organization.
- The role supports the implementation of security best practices.
- The position requires a commitment to the security mission of the organization.
- You will collaborate with security vendors to ensure effective tool usage.
- The role supports the continuous monitoring of security threats.
- The position requires the ability to analyze security data and derive actionable insights.
- You will work to improve the security maturity of the organization.
- The role supports the development of security metrics and reporting.
- The position requires a strong understanding of security operations.
- You will collaborate with product teams to ensure security requirements are met.
- The role supports the implementation of security solutions.
- The position requires the ability to manage security risks effectively.
- You will w