MTS-2 Security Operations Engineer
On-siteBengaluru, Karnataka, India
Job Summary
Monitor global security events and alerts across enterprise security platforms in a 24x7 operational environment, identifying, classifying, and prioritizing incidents for investigation. Perform initial triage of phishing and security alerts, document findings, and escalate incidents requiring advanced expertise to the Incident Response team. Execute containment actions to limit incident impact while assisting with forensic preservation and maintaining chain of custody. Analyze security alerts to identify indicators of compromise and recommend improvements to detection content and alert tuning. Collect, analyze, and disseminate open-source intelligence to support investigations and improve situational awareness. Participate in a rotating 24x7 shift schedule, including weekends and holidays, to support continuous global security operations within the CSIRT Operations team.
Required Qualifications
- Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience
- Minimum of three (3) years of professional experience in Security Operations, Security Incident Response, Threat Detection, Digital Forensics, or a related cybersecurity discipline
- Experience investigating security events and responding to cybersecurity incidents in an enterprise environment
- Experience working with SIEM, EDR, or other enterprise security monitoring technologies
- Must have at least one of the following certifications: SANS GIAC (GCIA, GCIH, GCED, GCFA, GCFE, GMON, GNFA, GREM, or equivalent) ISC2 (CISSP, CCSP) CompTIA Security+ Cisco (CCNA, CCNP) EC-Council (CEH, ECIH, CHFI) Offensive Security (OSCP)
- Minimum of three (3) years of specialised experience in one or more of the following areas: Security Operations Center (SOC) or Computer Security Incident Response Team (CSIRT)
- Security Incident Response and Investigation
- Threat Detection and Monitoring
- Digital Forensics and Evidence Preservation
- Cyber Threat Intelligence
- Security event monitoring, alert triage, incident classification, and response workflows within a Security Operations Center (SOC) or CSIRT environment
- Security investigation methodologies, containment techniques, evidence preservation, and incident documentation
- Experience working with Security Information and Event Management (SIEM) platforms to investigate alerts, analyze logs, and identify malicious activity
- Understanding of Windows, Linux, and endpoint security concepts, including basic forensic acquisition and investigation techniques
- Knowledge of TCP/IP networking protocols including HTTP, DNS, FTP, DHCP, ARP, and experience using network analysis tools such as Wireshark or tcpdump
- Familiarity with indicators of compromise (IOCs), MITRE ATT&CK, and open-source intelligence (OSINT) techniques
- Experience with Python or a similar scripting language to automate repetitive operational tasks and improve investigation efficiency
- Experience with endpoint detection and response (EDR), SIEM platforms, and other enterprise security monitoring tools
- Participate in a rotating 24x7 shift schedule, including weekends and holidays, as required to support continuous global security operations
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.