Search by job, company or skills

Security Engineer

Early Applicant
  • Posted a day ago
  • Be among the first 10 applicants

Job Description

We are hiring a Security Engineer who lives at the intersection of SOC alerting and vulnerability remediation - the work that connects something looks wrong to something is fixed. You will own the close-the-loop motion: triage SOC alerts and vulnerability findings, prioritise against business context and threat intel, assign and chase down remediation owners, and measure what actually got fixed. AI leverage: AI SAST AppSec triage, CSPM findings, and prioritising AISOC for L1/L2 alert handling and intel agents for the repetitive parts owners remediation loop.

Responsibilities

  • SOC alert triage and response. Operate primarily as a SOC engineer and analyst. Triage alerts. Calibrate severity. Route or escalate. Be the human in the loop with AI and agents operating under your authority.
  • Vulnerability alert handling and remediation coordination. Take the daily dose of vulnerability findings (SAST/SCA/secrets, CSPM, container/infra, and endpoint via EDR) and turn it into a managed remediation pipeline. Apply CTEM/risk-context prioritisation: CVSS + EPSS + KEV + business context.
  • Close-the-loop ownership. Open the ticket; assign the right owner (engineering / SRE / Corp IT / AppSec); ensure the SLA (runAppSec) can rescan/retest; SLA-manage the rescan/retest platform; and close the GRC Platform - open and forgotten is a thing of the past.
  • SLA enforcement and metrics. Operate the SLA dashboard. Watch for ageing items at 75% of the SLA window and escalate. Run the WeAgeingLA compliance report on the SLA. Own the monthly CISO view of open vulnerabilities, MTTR trends, and ageing by owner.
  • Threat hunting partnership. Support the senior SOC/detection engineer's senior detection engineer accounts. Bring vulnerability and remediating context into hunts (e. g., a known unpatched asset-focused hunt).
  • AI agents for the loop. Build agents where the work is repetitive (e. g., alert deduplication and enrichment, vuln-to-owner routing, SLA-vulnerability-to-owner references, evidence collection for closures, and post-mortem disclosures) and decide where the human stays in the loop.
  • Incident response support. During Severity 1/2 events, serve as a SOC technical contributor for investigation, event contribution, timeline documentation, customer advice documentation, and content (with CSIRT/PSIRT/CISO oversight).
  • Customer reports. Be the SOC partner for customer-reported security issues, initial triage, severity calibration, and handoff to the right internal owner with proper escalation.

You May Work On

  • MDR partnership runbook authorship and detection content engineering.
  • Code-level vulnerability fixes (owned by engineering; you coordinate, prioritise, and verify and may even help provide or author the code patches).
  • Ensure production patching execution SLAs are completed by SRE/DevOps.
  • Endpoint patching execution (owned by Corporate IT; you set SLA expectations and ensure compliance).
  • Incident command for Severity 1 events (owned by the Sr SOC engineer, escalating to CISO).

First 90 Days

  • SOC triage shift coverage is operational with the SOC lead-defined handoff cadence, escalation paths, and on-call rotation seat.
  • Vulnerability remediation pipeline measured end-to-end: time-to-triage, time-to-assignment, time-to-fix, and SLA compliance baseline established.
  • First AI agent shipped for the remediation loop (e. g., alert enrichment, vuln-to-owner routing, or SLA chase cadence).
  • Top 10 highest-ageing vulnerabilities triaged and either closed, exception-approved, or escalated with documented compensating controls.
  • A weekly SLA compliance dashboard is live for the CISO and director of security engineering review.

Requirements

  • Four or more years in SOC, security operations, vulnerability management, or incident response with hands-on alert triage and remediation coordination experience.
  • Hands-on with SIEM/EDR/XDR tooling (CrowdStrike, Splunk, Sentinel, Chronicle, Sumo, or equivalent).
  • Hands-on with at least one vulnerability scanner or AppSec platform (Endor, Snyk, Tenable, Qualys, Rapid7 Wiz, Aqua, AWS Inspector, or comparable).
  • Fluency with CVSS v3.1/v4.0 EPSS, CISA KEV, and risk-context prioritisation frameworks (CTEM or similar).
  • Strong written and verbal communication: you can write a remediation ticket an engineer will actually act on, and you can escalate to the CISO when needed.
  • Demonstrated comfort with MITRE ATT& CK and threat-actor TTPs at the conversational level.

Preferred

  • Hands-on building AI agents or automations for SOC, vulnerability management, or IT operations work.
  • Operational experience with an MDR partner (Expel, Arctic Wolf, Rapid7 Red Canary, or comparable).
  • Experience with AISOC platforms.
  • GIAC certifications (GCIA, GCFA, GCIH) or equivalent.
  • Cloud-native security experience (AWS, Azure, GCP): You understand cloud findings and can route them to the right owner.
  • Familiarity with PKI / certificate management / machine identity relevant to AppViewX's product domain.

This job was posted by Sai Amrith from AppViewX.

More Info

Job Type:
Industry:
Employment Type:

About Company

Job ID: 153449879

Similar Jobs

Bengaluru, India

Skills:

Cloud securityIncident ResponseSecurity ArchitectureSIEM and vulnerability toolsRisk managementOWASP and secure engineering practices

Bengaluru, India

Skills:

DASTIso 27001GcpDockerIamSiemOwasp Top 10KubernetesAWSZero Trust architectureNIST CSFSOARSOC2SCASAST

Bengaluru, India

Skills:

Splunk Grafana Nagios Zabbix ThousandEyesLinux Unix Windows AdministrationBCP High Availability ResiliencyChange Incident Problem Major Incident Management ServiceNowShell Python Scripting AutomationStrong Troubleshooting Analytical Problem-Solving SkillsServiceNow Jira ConfluenceProduction Support Rotational On-Call SupportKPI KRI Monitoring Operational ExcellenceSQL MySQL PostgreSQL Oracle KnowledgeCloud Fundamentals Azure AWS GCPVulnerability Remediation Patch ManagementAgile Scrum ITIL Practices

Bengaluru, India

Skills:

reporting metrics policy development NetworkingIpsIncident ResponseIamFirewallsIdsSiemCismSecurity Assessmentsinformation protectionSOARVendor ManagementSecurity ImplementationIdentity Management SystemsRisk ManagementissapSystem Design IntegrationVulnerability ScansCisspOt SecurityTraining Awareness

Bengaluru, India

Skills:

lifecycle management Upgradesnetwork securityautomationIntegrationsconfiguration managementScriptingSiemcloud securityApisVulnerability Scanninginfrastructure-as-codeTroubleshootingSOARXDRAI securityMonitoringEDRplatform configurationPatching

Beware of Scammers

We don’t charge money for job offers