L3 Incident Response
1 week ago
Job Description: L3 Incident Response & Network Security Engineer
Position:
L3 Incident Response / Security Operations Engineer
Location:
(Specify)
Experience:
5–10 Years
Sector:
Telecom / Enterprise / Managed Security Services
Role Overview
We are looking for a
hands-on L3 Incident Response & Network Security Engineer
with strong troubleshooting skills across firewalls, proxy solutions, WAFs, and secure email gateways. The engineer will act as the
highest technical escalation point (L3)
for SOC operations, handling major incidents, performing deep-dive investigations, tuning security controls, and providing advanced operational support.
This role requires extensive knowledge of enterprise security infrastructure, IR processes, and direct L3 SOC operations.
Key Responsibilities
- L3 Incident Response & Escalations
- Act as the L3 escalation point for all major security incidents.
- Perform detailed triage, containment, recovery, and root cause analysis.
- Investigate alerts and escalations from SOC L1/L2 teams including malware, intrusion attempts, DDoS indicators, suspicious traffic, or compromised accounts.
- Lead war-room calls for P1/P2 security incidents.
- Hands-on Troubleshooting (Critical Skill)
Deep troubleshooting across:
Firewall rules, access/ACL issues, NAT, VPN failures
- Proxy policies, URL filtering, SSL inspection
- WAF tuning, false positive reduction, signature adjustments
Email gateway issues: spam, phishing, TLS routing, mail delivery
Review packet captures, logs, and security alerts to isolate issues.
- Perform configuration corrections and implement mitigation steps.
- SOC L3 Operations
- Support day-to-day SOC operations at L3 level.
- Validate and enhance detection logic across SIEM/SOAR platforms.
- Collaborate with threat intel, detection engineering, and incident commanders.
- Guide SOC L1/L2 teams on escalations, tuning, and false positive reduction.
- Security Control Tuning & Optimization
Continuously fine-tune:
Firewall policies (ASA/FTD/Palo Alto/Checkpoint)
- IPS/IDS signatures
- WAF rules (F5 ASM, Imperva, Akamai, etc.)
- Proxy categories, SSL bypass policies, DLP rules
Email security policies for phishing, malware, and spoofing
Conduct periodic policy reviews and compliance validation.
- Change & Problem Management
- Manage and execute complex L3-level changes during planned maintenance windows.
- Perform impact analysis, pre/post checks, and documentation.
- Participate in root cause analysis and long-term remediation planning.
- Threat Hunting & Log Analysis
- Perform proactive threat hunting across network and security datasets.
- Analyze logs from firewalls, proxies, IPS, WAF, and email gateways.
- Identify anomalous patterns and work with SOC for follow-up actions.
Required Technical Skills
Hands-on Expertise (Mandatory)
- Firewalls (Cisco ASA, Firepower, Palo Alto, Check Point)
- Proxy solutions (Blue Coat, Zscaler, Squid)
- WAF platforms (F5 ASM, Imperva, Cloudflare, Akamai)
- Email Security Gateways (Cisco ESA/IronPort, Proofpoint, Mimecast)
- IDS/IPS analysis and tuning
Incident Response & SOC Skills
- Strong understanding of IR frameworks (NIST, SANS).
- Experience with SIEM platforms (Splunk, QRadar, Sentinel, Arcsight).
- Experience with SOAR automation (preferred).
- Packet capture analysis (Wireshark, tcpdump).
Additional Operational Security Tools (Advantage)
- FireEye
- Cisco ASA/Firepower
- Cisco ISE
- Arbor DDoS
- AlgoSec
Soft Skills
- Strong analytical and decision-making capability.
- Excellent communication during incidents.
- Ability to lead high-pressure security bridges.
- Strong documentation and reporting skills.
Preferred Certifications
- CCNP Security / CCIE Security
- GIAC Certifications (GCIA, GCIH, GCFA, GCFE)
- CEH / CHFI
- ITIL Foundation
Skills: incident response,soc,firewalls,security,email,operations,tuning,cisco,proxy
-
SOC L3-incident Response
2 days ago
Navi Mumbai, Maharashtra, India Atos Full time**Job Applicant Privacy Notice**: **SOC L3-Incident Response**: - Publication Date: Jul 2, 2025 - Ref. No: 533512 - Location: Mahape, Navi Mumbai, Maharasht, IN - TBC - Act as the final escalation point for complex security incidents and alerts. Perform deep-dive analysis of security events using SIEM, EDR, and other security tools. Lead incident response...
-
L3 Network Security Engineer
1 week ago
Mumbai Metropolitan Region, India Neev Full timeJob Description – L3 Network Security Engineer (Infrastructure Specialist)Role:L3 Network Security EngineerDepartment:Cybersecurity / Infrastructure Security OperationsLocation:(Specify)Experience:5–10 YearsType:Full-TimeRole OverviewThis role requires asenior, infrastructure-heavy L3 Security Engineerresponsible for advanced operational management and...
-
Incident Response
11 hours ago
Navi Mumbai, Maharashtra, India KPMG Assurance and Consulting Services LLP Full timeRole SummaryWe are seeking a highly skilled cybersecurity professional to join our team as a Threat Hunter / Incident Response Specialist. The ideal candidate will have hands-on experience in proactive threat hunting, incident detection, and response, with strong expertise in ELK (Elasticsearch, Logstash, Kibana) for log analysis and visualization.Key...
-
L3 Network Security Engineer
4 days ago
Mumbai Metropolitan Region, India Syndrome NewEdge Full timeJob DescriptionPrimary Responsibilities :Provide L3-level support and implementation expertise in Network Security, focusing on Checkpoint, Cisco ASA, and other Cisco Security technologies.Troubleshoot and resolve complex L2/L3 network security issues and drive high-severity incident resolution.Execute complex change activities including upgrades,...
-
Bengaluru, Mumbai, India Deloitte Consulting Full timeKey Responsibilities:Deep understanding of computer intrusion activities, incident response techniques, tools, and procedures. L2, L3 Support.Good Experience in SIEM monitoring (QRadar, Sentinel, Splunk, chronicle)Knowledge of SOAR technologies, working with playbooks (Cortex, chronicle, Splunk SOAR)Experience handling malware incidents (Flare VM, Remnux)...
-
Incident Response Specialist
2 weeks ago
mumbai, India beBeeIncident Full timeSeeking a seasoned Incident Response Specialist, you will play a pivotal role in driving improvements in incident management processes and ensuring timely communication with stakeholders.The ideal candidate will possess 12+ years of experience leading incident response efforts, exceptional communication skills, and the ability to collaborate effectively...
-
Incident Response Lead
1 week ago
Mumbai, Maharashtra, India Anzen Technologies Full timeANZEN Technologies Pvt. Ltd. is a leading cybersecurity service provider that empowers organizations across various industries with advanced security services, innovative solutions, and unmatched expertise in cybersecurity, IT Governance, Risk Management, and Compliance.Incident Response Lead Profile:The Incident Response Lead is responsible for driving and...
-
Incident Response Analyst
1 week ago
Mumbai, Mumbai Suburban, Navi Mumbai, India Godrej Infotech Full timeJD for Junior Incident Responder / Junior SOC AnalystRole: Assists in incident response activities, analyses potential threats, and supports senior incident responders in containment and recovery efforts.About the RoleAs a Junior Incident Responder, you will play a vital role in the Cyber Security Operations Center (SOC) by assisting in the detection,...
-
Incident Response Lead
1 week ago
mumbai, India beBeeCustomer Full timeWe are seeking an experienced professional to lead our incident response efforts.The ideal candidate will bring expertise in strategic decision-making, effective communication, and a strong customer-centric mindset.This role focuses on delivering exceptional support experiences during customer-facing incidents by coordinating across diverse teams and...
-
Network Security Specialist
4 weeks ago
Mumbai Metropolitan Region, India Getronics Full timeRole requires an infra-heavy L3 engineer for network firewalls, IDS/IPS, WAF, proxies, and email gateways. Hands-On with Security Infrastructure direct operational expertise with Palo Alto, Juniper SRX, Fortigate, McAfee IDS/IPS, Zscaler, Akamai WAF, CiscoIronPort Incident Response / L3 Escalation hands-on troubleshooter (firewall rules, proxy configs, WAF...