Search by job, company or skills

Senior Security Engineer

Senior Security Engineer

Providence India
6-8 Years
Not Disclosed
  • Posted a month ago
  • Be among the first 10 applicants

Job Description

Job Description - Security Operations Engineer 2 (Threat Hunter)

Job Title

Security Operations Engineer 2

Role Summary:

The Threat Hunter is tasked with the proactive identification, investigation, and mitigation of advanced cyber threats within PGC enterprise environments. The candidate will utilize threat intelligence, hypothesis-driven hunting, behavior analytics, and advanced detection techniques to uncover malicious activities not addressed by traditional security controls.

Key Responsibilities:

  • Conduct proactive threat hunting across endpoints, network, cloud, identity, and email environments.
  • Develop and implement threat hunting hypotheses based on emerging threats and adversary tactics, techniques, and procedures (TTPs).
  • Analyze security telemetry using platforms such as SIEM, EDR/XDR, Cloud Security, Data Security, EASM, email security gateways, Threat Intelligence, Dark Web monitoring, identity management, SOAR, Case Management, and various log sources.
  • Investigating Indicators of Compromise (IOCs) and Indicators of Attack (IOAs).
  • Align threat hunting and investigation findings with the MITRE ATT&CK framework.
  • Create and refine threat detection rules, use cases, and behavioral analytics based on threat hunting outcomes and investigations to enhance security monitoring coverage.
  • Conduct digital forensic and incident analysis to determine the scope and impact of attacks.
  • Produce technical reports and executive summaries detailing threat hunting activities.
  • Perform triage, investigation, and response to security incidents.

Required Skills/Qualifications:

  • Comprehensive understanding of cyber-attack lifecycles and adversary behavior.
  • Expertise in the MITRE ATT&CK framework.
  • Experience with SIEM and SOAR platforms, such as CrowdStrike Falcon Next-Gen SIEM and Palo Alto Network Cortex XSOAR.
  • Hands-on experience with EDR/XDR solutions, including Microsoft Defender and CrowdStrike Falcon.
  • In-depth knowledge of Windows, Linux, Active Directory/Entra ID, Azure Cloud Platform, and networking protocols (DNS, HTTP(s), SMTP, LDAP, TCP/IP).
  • Proficiency in Kusto Query Language (KQL), SQL, and scripting languages such as Python and PowerShell.
  • Understanding of malware analysis and digital forensics.
  • Strong analytical, communication, and documentation skills.
  • SOAR Playbook Development

Preferred Qualifications:

  • 3-6 years of experience in cybersecurity, with at least 3 years in threat hunting.
  • Relevant certifications such as GIAC Certified Threat Hunter (GCTI/GCTH), GIAC Certified Forensic Analyst (GCFA/GNFA), MITRE ATT&CK Defender (MAD - All modules) or equivalent certifications.

More Info

Key Skills

Azure Cloud Platform

Next-Gen SIEM

SOAR platforms

Entra ID

CrowdStrike Falcon

Palo Alto Network Cortex XSOAR

Microsoft Defender

Windows

About Company

Providence, one of the US's largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, ‘Health for a better world', Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and services.

Similar Jobs

8-10 yrs
Bengaluru, India
Skills:
Microsoft Azure, Detection engineering, Linux and container platforms, Cloud Security Engineering, KQL, Microsoft Sentinel, ASIM and SIEM data normalization, Telemetry and log pipeline engineering
5-8 yrs
Ambattur, India
Skills:
Siem, Threat Intelligence, Log Analysis, automation, Python, detection engineering, detection-as-code, EDR, SOAR playbooks, ITSM tooling, network forensics
10-12 yrs
Bengaluru, India
Skills:
Siem, Sentinel One, Microsoft Defender, Defender XDR, Crowdstrike Falcon, Microsoft Sentinel, Crowdstrike, Google Chronicle, Next Gen Splunk, EDR
6-8 yrs
Bengaluru, India
Skills:
.NET, Java, Typescript, Javascript, API Security, Owasp Top 10, APEX, Python, Threat Modelling, Attack Simulation, CWE Top 25, Container Security, manual penetration testing, Secrets Management
5-7 yrs
Hyderabad, India
Skills:
threat modeling , API security, Ansible, Bash, Python, Docker, Terraform, Jenkins, Git, DAST, SCA, GitHub Actions, IaC, software supply chain security, GitLab CI, Go, CAC, Kubernetes security, LLM security, CircleCI, AI security, SAST, Inspec