Senior Security Engineer, SOC

4 weeks ago


Thiruvananthapuram, India Poshmark Full time

Responsibilities

  • Monitor and analyze security event logs and alerts to detect potential incidents, and lead investigations for containment, eradication, and recovery.
  • Lead security incident investigation, containment, eradication, and recovery activities.
  • Monitor AWS Security tools including GuardDuty, CloudTrail, IAM, AWS WAF, Shield, VPC Flow Logs to monitor and secure cloud workloads.
  • Perform in-depth analysis of sophisticated security incidents and targeted attacks across systems, networks, and code to identify root causes and prevent recurrence.
  • Enhance detection and response capabilities through automation, including fine-tuning alerts to reduce false positives and automating responses to repetitive incidents.
  • Develop and maintain incident response playbooks for distinct types of security incidents, ensuring they align with current threats.
  • Leverage IOCs, threat intelligence, and other data sources to enrich security events, improving detection accuracy and reducing incident response time.
  • Work with security stakeholders and cross-functional teams to coordinate incident response efforts and improve overall security initiatives.
  • Conduct proactive threat hunting to identify potential malicious activities and mitigate emerging risks before they escalate.
  • Collaborate with Product security and infrastructure security team to conduct vulnerability scans, penetration tests, and risk assessments to uncover weaknesses in the security posture.
  • Collaborate with IT and development and other relevant stakeholders to identify and contain the incident till to ensure timely patching and remediation of vulnerabilities.


Required Experience:

  • A minimum of 5 years of experience in a Security Operations Center (SOC) environment.
  • Relevant certifications such GCIA, GCIH, AWS Security Specialist or any other certification that is in the field of Security Operations or Incident Response.
  • Hands-on experience with security tools and technologies such as SIEMs, Endpoint Detection and Response (EDR), Web Application Firewalls (WAFs), Intrusion Detection Systems (IDS), and vulnerability scanners.
  • Proficient in the incident response process, including identification, containment, remediation, and recovery.
  • Skilled in defense-in-depth and layered security architecture design and implementation.
  • Experience with cloud security services, preferably in AWS environments.
  • Strong analytical and problem-solving skills with a detail-oriented approach to security challenges.
  • Excellent verbal and written communication skills, capable of conveying complex security concepts to non-technical stakeholders.


6-Month Accomplishments:

  • Continuously perform security incident investigation, containment, eradication, and recovery. This includes identifying and responding to security incidents, containing the spread of the incident, eradicating the malware or other malicious code, and recovering the affected systems.
  • Stay up-to-date on the current IT threat landscape and upcoming trends in security. This involves reading security blogs and articles, attending security conferences, and subscribing to security mailing lists. You should also use security tools and services that provide threat intelligence.
  • Write new high-fidelity detections and incident response playbooks. This includes writing new rules and playbooks for your organization's security tools to help detect and respond to security incidents. You should have a deep understanding of your organization's security infrastructure and be familiar with the latest security threats and attack vectors.


12+ Month Accomplishments:

  • Reduce Mean-Time-to-Detect (MTTD) and Mean-Time-to-Respond (MTTR) through automation.
  • Improve Security Operations Posture by continuously improving detections, writing high fidelity detections and maintaining up to date Incident Response Playbooks.
  • Partner with cross-functional teams to identify business-critical operations and recommend strategies to enhance business continuity and resilience
  • Working on Projects that will help shore up the Security Operations Posture


Good to have:

Coding Skills: Proficient in coding languages like Python or Go


  • SOC Engineer

    6 days ago


    Pattom, Thiruvananthapuram, Kerala, India Albetech Software Solutions LLP Full time ₹ 2,40,000 - ₹ 3,00,000 per year

    We are seeking a skilled and motivated SOC Engineer with 2 years of hands-on experience in cybersecurity operations. The ideal candidate will be responsible for monitoring, detecting, analyzing, and responding to security incidents within our environment. You will work closely with other security and IT teams to ensure the confidentiality, integrity, and...

  • L2 SOC Analyst

    1 week ago


    Thiruvananthapuram, Kerala, India UST Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    5 - 7 Years1 OpeningTrivandrumRole descriptionJob Title: L2 SOC AnalystExperience : 5 to 7 yearsLocation: Trivandrum, Kochi, Chennai, Bangalore, HyderabadCompany: CyberProof, A UST CompanyKey Roles & Responsibilities Resolve, escalate, report, and raise recommendations for resolving and remediating security incidentsHandle the advanced monitoring of system...

  • L1 SOC Analyst

    14 hours ago


    Thiruvananthapuram, Kerala, India UST Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    2 - 4 Years1 OpeningTrivandrumRole descriptionExperience : 2 to 4 yearsLocation : Bangalore/Hyderabad/Chennai/Kochi/TrivandumThe primary role of a SOC Level 1 Analyst is to serve as the frontline defense, managing first triage and ranking of security cases, and initiating the threat detection and response processes for client-related security events. The...

  • Security Analyst

    2 weeks ago


    Thiruvananthapuram, India CONNECTING 2 WORK Full time

    Job Description REQUIREMENTS 5 + years experience in the Security Operations domain Experience in L2 role in the SOC domain Experienced in leading investigations of Security incidents Experienced in developing new use cases for Security Operations Experienced in Threat Intelligence Operations Experienced in leading team


  • Thiruvananthapuram, India HireIT Consultants Full time

    Job Description : SOC AdministratorPosition : SOC AdministratorEducation : BE/B.Tech in Computer Science, Information Technology, or related fieldCertifications (Preferred) : CEH / CISA / CISSP / CISMExperience : Minimum 5 years of relevant experienceRole Overview :We are seeking a highly skilled SOC Administrator to manage and oversee the day-to-day...

  • L3 Soc Analyst

    2 weeks ago


    Thiruvananthapuram, Kerala, India UST Full time

    L3 SOC Analyst Experience 7 plus years Location Hyderabad Trivandrum Kochi Bangalore Chennai Company CyberProof A UST Company CyberProof is seeking a SOC L3 Engineer who will be part of our growing Global Operations Delivery team which monitors investigates and resolves security incidents violations and suspicious activities Our global Operations group takes...


  • Thiruvananthapuram, Kerala, India Quantiphi Analytics Solution Pvt Ltd Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Senior Cyber Security Engineer While technology is the heart of our business, a global and diverse culture is the heart of our success. We love our people and we take pride in catering them to a culture built on transparency, diversity, integrity, learning and growth.If working in an environment that encourages you to innovate and excel, not just in...

  • Security Analyst

    3 weeks ago


    Thiruvananthapuram, India CONNECTING 2 WORK Full time

    Job Description REQUIREMENTS 5 + years experience in the Security Operations domain Experience in L2 role in the SOC domain Experienced in leading investigations of Security incidents Experienced in developing new use cases for Security Operations Experienced in Threat Intelligence Operations Experienced in leading team

  • Security Analyst

    3 weeks ago


    Thiruvananthapuram, India CONNECTING 2 WORK Full time

    Job Description REQUIREMENTS 5 + years experience in the Security Operations domain Experience in L2 role in the SOC domain Experienced in leading investigations of Security incidents Experienced in developing new use cases for Security Operations Experienced in Threat Intelligence Operations Experienced in leading team

  • DevSecOps Engineer

    4 days ago


    Thiruvananthapuram, Kerala, India GreenBay IT Solutions Private Limited Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    DevSecOps Engineer Experience: 5–7 years Location: Trivandrum Job Type: Full Time, Permanent Mandatory Skills: Cloud Security (AWS, GCP, Azure), IAM, Compliance, Infrastructure Hardening Automation: Ansible, Azure DevOps, CI/CD Security: Threat Detection & Incident Response (IDS/IPS, SIEM, Vulnerability Scanners) Compliance: ISO 27001, NIST, CIS Linux...