Sr Security Engineer
- Hiring from
- India
- Work type
- Hybrid
- Posted
Is this job info correct?
Show job descriptionHide job description
Job Summary:
The SOC Senior Engineer is an expert-level position responsible for overseeing the most complex and critical aspects of the organization's security operations. This role involves advanced threat detection, incident response, and strategic input into the development of the SOC's capabilities. The SOC Senior Engineer is expected to lead high-impact security initiatives, mentor junior team members, and collaborate with cross-functional teams to strengthen the organization’s overall security posture.
Key Responsibilities:
- Expert Security Monitoring and Analysis:
- Lead the monitoring, detection, and analysis of security events from a wide range of security tools (e.g., SIEM, EDR, IDS/IPS) to identify advanced threats and vulnerabilities.
- Perform deep-dive analysis of complex security incidents, leveraging expertise in threat intelligence and forensic techniques.
- Develop and refine detection techniques and strategies to enhance the SOC’s ability to identify and respond to emerging threats.
- Incident Response Leadership:
- Lead the response to high-severity and complex security incidents, coordinating efforts across the organization and with external partners.
- Oversee the development and execution of incident response plans, ensuring timely and effective containment, eradication, and recovery.
- Conduct comprehensive post-incident reviews to identify root causes, recommend improvements, and enhance the organization’s incident response capabilities.
- Threat Hunting and Intelligence:
- Proactively hunt for threats within the organization’s network and systems, identifying potential risks before they manifest into incidents.
- Integrate threat intelligence into SOC operations, ensuring that detection and response activities are informed by the latest threat data.
- Develop threat hunting methodologies and tools to improve the SOC’s proactive security capabilities.
- Strategic Development and Process Improvement:
- Contribute to the strategic development of the SOC, including the evaluation and implementation of new technologies and processes.
- Lead efforts to automate and optimize security monitoring, detection, and response workflows to improve efficiency and effectiveness.
- Participate in the development and refinement of SOC policies, procedures, and playbooks to align with industry best practices and regulatory requirements.
- Mentorship and Team Development:
- Provide expert guidance and mentorship to SOC engineers at all levels, fostering a culture of continuous learning and improvement.
- Lead training sessions, workshops, and tabletop exercises to enhance the team’s technical skills and incident response readiness.
- Act as a technical advisor to management and other departments on complex security issues and initiatives.
- Collaboration and Communication:
- Collaborate with IT, legal, compliance, and other departments to ensure a coordinated and comprehensive approach to security operations.
- Communicate effectively with senior leadership and stakeholders regarding the status, impact, and resolution of significant security incidents.
- Represent the SOC in external engagements, such as industry forums, conferences, and collaborations with law enforcement or other organizations.
- Continuous Learning and Innovation:
- Stay current with the latest cybersecurity threats, trends, tools, and best practices, continuously enhancing the SOC’s capabilities.
- Experiment with and adopt new technologies, techniques, and approaches to improve the organization’s ability to detect and respond to security threats.
- Contribute to the broader cybersecurity community by sharing insights, research, and best practices.
Skills and Qualifications:
- Technical Skills:
- Expert knowledge of cybersecurity principles, advanced threat landscapes, and a wide range of security technologies (e.g., Elastic SIEM, EDR, IDS/IPS, forensics tools).
- Extensive experience in incident response, threat hunting, and forensic analysis, with a proven ability to handle complex and high-impact incidents.
- Proficiency in scripting and automation (e.g., Python, PowerShell) to enhance SOC processes and capabilities.
- Analytical Skills:
- Exceptional analytical and problem-solving skills, with the ability to assess and respond to sophisticated security threats and incidents.
- Strong attention to detail and the ability to synthesize large amounts of data into actionable insights and recommendations.
- Communication and Leadership Skills:
- Excellent written and verbal communication skills, with the ability to convey complex technical information to both technical and non-technical audiences.
- Strong leadership skills, with the ability to coordinate and lead cross-functional teams during high-pressure situations.
- Certifications:
- Advanced certifications such as Certified Information Systems Security Professional (CISSP), GIAC Certified Incident Handler (GCIH), GIAC Reverse Engineering Malware (GREM), or similar are required.
- Additional certifications in specialized security domains (e.g., forensics, threat hunting, cloud security) are highly desirable.
- Education:
- Bachelor’s degree in Computer Science, Information Security, or a related field is required; a Master’s degree is preferred.
- Equivalent work experience in a related field may be considered.
- Experience:
- 8+ years of experience in cybersecurity, with a focus on security operations, incident response, threat hunting, and forensic analysis.
- Proven experience in leading incident response efforts for large and complex security incidents, including coordination with external partners.