Lead Engineer, Information Security
- Hiring from
- India
- Work type
- Remote
- Posted
- Sep 29, 2026
Majesco is looking for a Lead Engineer, Information Security to support and continuously improve our security monitoring, detection, vulnerability management, and incident response capabilities.
This role will be a senior technical contributor within the Information Security team, responsible for investigating security events, improving SIEM detection logic, validating security log coverage, reducing unnecessary false positives, and helping ensure that security monitoring provides meaningful and actionable detection across the environment.
The successful candidate should be comfortable both performing day-to-day security operations and identifying opportunities to make those operations more effective. This is a hands-on role that requires strong analytical skills, technical ownership, and the ability to work collaboratively across Security, Infrastructure, Cloud, and other technology teams.
Key Responsibilities:
- Investigate, triage, document, and respond to security alerts and events in a timely manner.
- Develop, test, tune, and maintain SIEM correlation and detection rules.
- Analyze recurring alerts and false positives and implement appropriate tuning, exceptions, or detection improvements without reducing meaningful security coverage.
- Identify gaps in security monitoring and help ensure relevant security logs and telemetry are properly ingested into the SIEM.
- Validate that log sources provide the events and data necessary to support effective detection and investigation.
- Support the integration of new systems, applications, cloud platforms, and security technologies into the security monitoring environment.
- Work with technologies such as Exabeam, CrowdStrike, Wiz, and other security monitoring and cloud security platforms.
- Support vulnerability management activities, including analysis, dashboards, reporting, and identification of meaningful security trends.
- Develop and improve security dashboards and reporting to reduce manual effort and provide useful information to technical teams and leadership.
- Assist with security incident investigations, including collection and analysis of relevant logs and security telemetry.
- Participate in the development and execution of incident response tabletop exercises and other security preparedness activities.
- Work collaboratively with other members of the Security Operations team, sharing technical knowledge and helping improve team processes and capabilities.
- Identify opportunities to improve security operations and take ownership of improvements from initial problem identification through implementation and validation.
- Maintain appropriate documentation for detection logic, monitoring coverage, investigations, and operational procedures.
Required Qualifications:
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
- 4+ years of hands-on experience in security operations, security monitoring, incident detection and response, vulnerability management, or a related information security discipline.
- Strong hands-on experience in security operations, security monitoring, or incident detection and response.
- Experience working with SIEM platforms, including investigating alerts and developing or tuning detection and correlation rules.
- Understanding of Windows, endpoint, network, application, cloud, and security log sources.
- Ability to analyze security events and distinguish legitimate activity, false positives, and potentially malicious behavior.
- Experience with endpoint detection and response (EDR) technologies such as CrowdStrike or equivalent platforms.
- Understanding of vulnerability management and experience working with vulnerability management or cloud security platforms.
- Working knowledge of common security concepts, including threat detection, incident response, identity and access management, network security, endpoint security, and cloud security.
- Ability to independently investigate technical issues and drive them through resolution.
- Strong written and verbal communication skills, including the ability to explain technical security issues clearly to both technical and non-technical audiences.
- Ability to work effectively across technical teams and collaborate with infrastructure, application, cloud, and security personnel.
Preferred Qualifications:
- Experience with Exabeam or another enterprise SIEM or security analytics platform.
- Experience with Wiz or comparable cloud security and vulnerability management technologies.
- Experience developing detection logic using multiple security data sources.
- Experience onboarding, validating, and maintaining SIEM log sources.
- Familiarity with Sumo Logic or similar log management platforms.
- Experience participating in security incident response investigations and tabletop exercises.
- Experience creating security dashboards, metrics, and automated reporting.
- Scripting or automation experience using PowerShell, Python, APIs, or similar technologies.
- Familiarity with cybersecurity frameworks and practices such as NIST CSF, NIST Incident Response Guidance, MITREATT&CK, CIS Controls, or ISO 27001.
- Relevant industry certifications such as CISSP, Security+, CISM, GIAC, GCIH, GCIA, or equivalent certifications are preferred.
What Success Looks Like
A successful Lead Engineer will not simply process alerts. They will continuously improve the effectiveness of security operations by enhancing detection accuracy, identifying monitoring gaps, reducing avoidable false positives, strengthening log coverage, improving vulnerability visibility, and taking ownership of technical security improvements.
They will demonstrate measurable improvements to the security program through stronger detection coverage, more effective correlation rules, improved visibility into security risks, reduced manual effort through automation, enhanced reporting and metrics, and increased incident response readiness.
They are viewed as a trusted technical resource who proactively identifies problems, drives solutions, and helps elevate the overall maturity of Majesco's security operations capabilities.