368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$29k – $65k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Alcon is a global medical company specializing in eye care products, headquartered in Geneva, Switzerland, and founded in 1945. The company develops and manufactures a wide range of surgical equipment, intraocular lenses, contact lenses, and ocular health products such as dry eye drops. Operating as an independent publicly traded corporation since its spin-off from Novartis in 2019, the firm serves patients and eye care professionals in over 140 countries.

Summary of Position:

Responsible for planning, managing, and implementing cybersecurity and IT compliance to ensure effective enterprise protection and innovation in the organization.

We are looking for an intermediate-level Security Engineer who can support Alcon’s Cyber Incident Response and Threat Management function across AWS cloud security, SIEM monitoring, EDR/XDR operations, cloud incident response, and emerging AI security risks. This person should be hands-on, practical, and comfortable working with SOC, Cloud, Infrastructure, Identity, and application teams to improve threat detection, response, and security posture.

Role Expectations:

  • Monitor, investigate, and respond to security alerts across cloud, endpoint, identity, email, SaaS, and enterprise environments.
  • Take ownership of assigned incidents from triage through containment, remediation support, documentation, and lessons learned.
  • Work with internal teams and external SOC partners to ensure incidents are handled consistently and within defined operational expectations.
  • Contribute to detection improvements, playbook maturity, operational documentation, and knowledge sharing across the SOC team.

Key Responsibilities:

1. AWS Security Incident Response & Cloud Security

  • Investigate AWS security alerts, suspicious activity, misconfigurations, and potential compromise scenarios using available cloud logs and security tooling.
  • Review AWS security findings from services such as GuardDuty, Security Hub, CloudTrail, Config, IAM, CloudWatch, Inspector, and related monitoring sources.
  • Support containment and remediation activities for cloud security incidents in coordination with Cloud Engineering and application owners.
  • Identify gaps in cloud logging, monitoring, alerting, access control, and security posture, and recommend practical improvements.
  • Assist in building and maintaining cloud incident response runbooks, investigation steps, and escalation procedures.
  • Enhance incident detection and response capabilities for Cloud platforms.

2. SIEM Monitoring & Detection Engineering

  • Work on Microsoft Sentinel and other SIEM-related monitoring activities to detect, investigate, and correlate threats across multiple data sources.
  • Create, review, and tune SIEM use cases to improve alert quality and reduce false positives.
  • Support onboarding and validation of important log sources including cloud, identity, endpoint, email, firewall, SaaS, and application logs.
  • Develop dashboards, basic reporting, and operational metrics to improve visibility for SOC and leadership stakeholders.
  • Map detections and investigation logic to common attacker behaviors using MITRE ATT&CK where applicable.

3. EDR / XDR Operations

  • Investigate EDR/XDR alerts from platforms such as Microsoft Defender XDR and other endpoint security tools.
  • Perform endpoint triage, device isolation support, IOC validation, malware investigation, and remediation coordination.
  • Identify endpoints missing security coverage and work with responsible teams to support remediation and visibility improvement.
  • Support policy tuning, alert validation, and operational improvements to strengthen endpoint detection and response.
  • Coordinate with Infrastructure, Desktop Engineering, and Vulnerability Management teams where endpoint issues require ownership outside SOC.

4. AI Security & Secure AI Operations

  • Support security monitoring and investigation of AI-related risks such as unauthorized AI usage, data leakage, prompt injection, model misuse, risky plugins/connectors, and AI-assisted phishing or social engineering.
  • Assist in defining practical AI security guardrails for SOC usage, including access control, logging, acceptable use, data handling, and escalation criteria.
  • Contribute to AI security incident response workflows and help document how AI-related security events should be triaged and escalated.
  • Support secure use of Microsoft Security Copilot and other AI-enabled security tools by helping validate use cases, risks, controls, and operational logging needs.
  • Stay current on AI threat trends and translate them into practical SOC monitoring and response actions.

5. Incident Response, Threat Hunting & Continuous Improvement

  • Perform structured incident analysis including scope identification, timeline review, evidence collection, containment recommendations, and post-incident documentation.
  • Participate in threat hunting and proactive detection improvement activities across cloud, endpoint, identity, and SIEM data.
  • Create and maintain SOC knowledge articles, incident handling guides, detection notes, and runbooks.
  • Support internal and external audit requests by providing clear operational evidence where applicable.
  • Identify automation opportunities using SOAR, scripting, KQL, PowerShell, Python, or cloud-native capabilities to reduce repetitive manual effort.

Key Requirements/Minimum Qualifications:

  • 5-7 years of experience in SOC operations, incident response, cloud security, SIEM engineering, EDR/XDR operations, or a related cybersecurity role.
  • Hands-on experience with AWS security concepts including IAM, logging, monitoring, network security, encryption, and incident investigation.
  • Working knowledge of AWS security services such as GuardDuty, Security Hub, CloudTrail, Config, Inspector, IAM, and CloudWatch.
  • Experience with SIEM tools, preferably Microsoft Sentinel, including alert investigation, KQL/log analysis, rule tuning, and dashboard/reporting support.
  • Experience with EDR/XDR platforms, preferably Microsoft Defender XDR, including endpoint investigation, containment, and remediation coordination.
  • Support secure adoption of AI capabilities by identifying security risks, monitoring misuse scenarios, and helping define security guardrails.
  • Good understanding of incident response lifecycle, threat hunting, common attack techniques, and MITRE ATT&CK.
  • Basic scripting or query skills using KQL, PowerShell, Python, or similar technologies.
  • Good written communication skills with the ability to document incidents, actions taken, findings, and recommendations clearly.

Preferred Qualifications

  • AWS Certified Security - Specialty, AWS Solutions Architect Associate, or equivalent cloud security certification.
  • Microsoft SC-200, SC-100, AZ-500, GCIH, GCIA, or similar security certifications.
  • Experience working in a global SOC or managed security operations model.
  • Exposure to Microsoft Security Copilot, SOAR platforms, threat intelligence platforms, or automation workflows.
  • Experience in regulated environments such as healthcare, life sciences, or global enterprise operations.

Work hours: 4 PM to 1 AM IST

Relocation assistance: Yes

Employment Scams: Alcon is aware of employment scams which make false use of our company name or leader’s names to defraud job seekers. Alcon does not offer any positions without interview and never asks candidates for money. All our current job openings are displayed here on the Careers section of our website, where you can search for open positions and apply directly.

If you have encountered a job posting or been approached with a job offer that you suspect may be fraudulent, we strongly recommend you do not respond, send money or personal information, and check our website for current job openings.

ATTENTION: Current Alcon Employee/Contingent Worker

If you are currently an active employee/contingent worker at Alcon, please click the appropriate link below to apply on the Internal Career site.

Find Jobs for Employees

Find Jobs for Contingent Worker

Alcon is an Equal Opportunity Employer and takes pride in maintaining a diverse environment. We do not discriminate in recruitment, hiring, training, promotion or other employment practices for reasons of race, color, religion, gender, national origin, age, sexual orientation, gender identity, marital status, disability, or any other reason.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
$68k – $85k per year • In office • Full-Time • Master's Degree • San Jose
Python
AI/ML
AI Agents
DevOps
Amazon EC2
AWS
AWS Lambda
Bitbucket
CI/CD
CloudFormation
Docker
Git
Kubernetes
Terraform
Amazon S3
IAM
HPC
Cybersecurity
Least Privilege
Apply
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$110k – $131k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree
DevOps
AWS
Incident Management
VMWare
Apply
$169k – $321k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Phoenix
AI/ML
AI Agents
Anomaly Detection
LLM Guardrails
DevOps
AWS
Kong
Amazon S3
API Gateway
Cybersecurity
Zero Trust
Apply
In office • Part-Time • 2+ years exp • Bachelor's Degree • Ness Ziona
C#
Java
AI/ML
Copilot
Cursor
DevOps
CI/CD
GitHub
Apply
$29k – $78k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru
Java
Java
Hibernate
Spring Boot
Spring Cloud
Spring MVC
DevOps
AWS
CI/CD
Helm
Jenkins
Kubernetes
Apply
$37k – $117k per year (Estimated) • Remote • Contractor • 3+ years exp • Australia
Python
Design
SolidWorks
Apply
$90k – $181k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Lake Forest
Apply
$162k – $308k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Fort Worth
Python
SQL
AI/ML
RAG
AI Agents
Apply
$115k – $226k per year (Estimated) • In office • Full-Time • 13+ years exp • Bachelor's Degree • Fort Worth
Apply
$41k – $89k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C#
TypeScript
JavaScript
C#
.NET
Databases
Apache Kafka
AI/ML
Copilot
LLM
OpenAI
Frontend
Angular
GraphQL
DevOps
Azure
Azure AKS
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Grafana
Kubernetes
Prometheus
Rest API
Apply
$38k – $83k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Bengaluru
Databases
Oracle
DevOps
AWS
Platform Engineering
Apply
Data Architect 2 hours ago
$38k – $91k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru • Pune
Node JS
Python
SQL
JavaScript
Databases
Databricks
MongoDB
Redis
Apply
$28k – $71k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
DevOps
CI/CD
Platform Engineering
Apply
$26k – $69k per year (Estimated) • In office • Full-Time • 9+ years exp • Bachelor's Degree • Bengaluru • Hyderabad • Chennai • Noida
Databases
Db2
IMS
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.