Location : Remote We are seeking a Sr. Advanced Cybersecurity Engineer based in India to serve as a detection and threat intelligence engineer within our Threat Detection & Response (TDR) program. This role focuses on detection engineering, threat intelligence operationalization, and SOAR automation across IT enterprises, cloud, OT/ICS, and identity environments. The ideal candidate will design and tune detection logic, drive security telemetry coverage improvements, build automated enrichment and detection workflows, and own the full detection development lifecycle from hypothesis through production deployment. Key Responsibilities Design, implement, and continuously tune threat detections across SIEM, EDR/XDR, OT security platforms, and cloud-native security tooling. Own the end-to-end detection engineering lifecycle — hypothesis development, rule authoring, validation, deployment, tuning, and retirement — aligned to MITRE ATT&CK across IT, OT, cloud, and identity environments. Operationalize threat intelligence by translating finished intel, IOCs, and adversary TTPs into actionable detection rules, hunt hypotheses, and automated enrichment workflows. Manage and maintain threat intelligence feeds and platforms, including ingestion, validation, confidence scoring, and expiration of IOC libraries. Build, maintain, and improve SOAR automation playbooks, enrichment pipelines, and detection workflows to increase alert fidelity and reduce analyst toil. Develop and maintain detection content for OT/ICS environments, including industrial protocol anomaly detection, Purdue model segmentation visibility, and OT-specific threat actor TTPs. Improve security telemetry quality and coverage by collaborating with infrastructure, network, cloud, OT, and platform engineering teams to onboard new log sources and validate data fidelity. Required Skills & Experience Must reside in India — this role is approved for India-based candidates only. 7–10+ years of experience in cybersecurity with a focus on detection engineering, security operations, or threat intelligence. Strong hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or QRadar — including rule authoring, query development, and data onboarding. Deep understanding of adversary tactics, techniques, and procedures with applied experience mapping detections to MITRE ATT&CK. Hands-on experience developing detection rules, correlation logic, behavioral analytics, and threshold-based alerting across multiple telemetry sources. Demonstrated experience with SOAR platforms for building automated enrichment pipelines, detection workflows, and threat intel operationalization. Strong scripting and automation skills in Python, PowerShell, or KQL for detection development, data parsing, and workflow automation. Experience with threat intelligence platforms (TIP) for IOC lifecycle management, feed integration, and intel-to-detection operationalization. Preferred Qualifications Experience building or maturing a detection engineering program including detection backlog management, coverage gap analysis, and ATT&CK heatmap maintenance. Experience with OT/ICS security monitoring . Familiarity with threat intelligence integration and threat hunting methodologies . Familiarity with detection-as-code practices , version control for detection content, and automated rule testing pipelines . Knowledge of cloud-native security monitoring and identity telemetry. Relevant certifications such as GDAT, GCDE, GCIA, GCED, or equivalent credentials.
Senior Artificial Intelligence/Machine Learning Engineer
Ciklum
Business Intelligence Engineer
DTCC Candidate Experience Site
Artificial Intelligence Engineer
Weekday
Artificial Intelligence Engineer
LLM Decode
Senior Artificial Intelligence Engineer
Ameriprise
Senior Engineering Intelligence Analyst
Five9