This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Cybersecurity Defense Specialist based in India.
This role is focused on strengthening enterprise security through advanced engineering, detection, automation, and incident response capabilities.
You will work across SIEM, SOAR, threat detection, vulnerability management, identity and access management, and security monitoring.
The position also brings AI and machine learning into security operations, including intelligent detection, alert triage, threat hunting, and automated response.
You’ll contribute to security architecture, penetration testing, red teaming, and continuous improvements to defensive capabilities.
The role operates within a highly technical environment supporting a large global enterprise and requires strong cross-domain collaboration.
You’ll have the opportunity to build reusable security automation, detection-as-code workflows, and AI-enabled security solutions.
Success in this position requires technical depth, ownership, analytical thinking, and the ability to operate effectively in high-pressure security situations.
Accountabilities
Design, implement, enhance, and support security technology solutions across enterprise environments.
Develop and deploy AI-powered detection rules using machine learning anomaly models, LLM-generated Sigma/SPL/KQL content, and behavioral analytics.
Build intelligent SOAR playbooks that use automation and AI-assisted reasoning to support dynamic security responses.
Implement and tune AI-driven alert triage systems for automated scoring, enrichment, prioritization, and routing.
Administer and optimize SIEM platforms, including indexing, search performance, and data model maintenance.
Create prompt engineering frameworks and evaluation environments for security-focused LLM applications.
Build RAG pipelines using internal security knowledge bases, operational runbooks, and threat intelligence.
Conduct AI-augmented threat hunting by combining LLM-generated hypotheses with machine learning and behavioral analysis.
Develop and maintain CI/CD pipelines supporting detection rules, SOAR playbooks, and machine learning model deployments.
Continuously improve vulnerability management, threat analysis, security monitoring, incident response, and identity and access management processes.
Conduct application security reviews, penetration testing, and red team exercises to identify weaknesses and translate findings into stronger detection and response capabilities.
Automate and orchestrate security processes to improve operational efficiency, consistency, and response times.
Develop operational documentation, procedures, runbooks, and training materials for security support teams.
Analyze security data and KPIs to assess operational effectiveness and the health of security controls.
Collect, preserve, analyze, and present digital evidence supporting security breaches, vulnerability remediation, and relevant investigations.
Collaborate across technical teams and geographies while supporting security initiatives, projects, and continuous improvement programs.
Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
8-10 years of relevant professional experience, including at least 5 years in security engineering with demonstrated cross-domain experience.
Strong experience across SIEM and SOAR, or SIEM and security detection engineering.
Proficiency with SIEM query languages such as SPL and KQL and experience developing SOAR playbooks using Python and/or low-code platforms.
Experience building or integrating AI/ML models for cybersecurity use cases.
Strong Python programming skills and familiarity with machine learning frameworks such as scikit-learn and PyTorch, as well as LLM APIs.
Practical detection engineering experience, including Sigma rules, MITRE ATT&CK mapping, and detection rule tuning methodologies.
Experience with Git-based workflows, detection-as-code, and infrastructure-as-code practices.
Knowledge of security technology, vulnerability management, threat analysis, security monitoring, incident response, and identity and access management.
Experience with application security reviews, penetration testing, red teaming, or related security assessment activities.
Relevant cybersecurity or technology certifications are advantageous, alongside equivalent demonstrated professional experience.
Strong analytical skills and exceptional attention to detail, with the ability to identify important security signals accurately and efficiently.
Excellent written and verbal English communication skills, along with proficiency in the relevant local language.
Ability to create and deliver clear technical presentations to different audiences and interact effectively with all levels of management.
Strong multicultural collaboration, leadership, organizational, and time-management skills.
Ability to work independently with limited supervision while taking ownership of tasks through completion.
Comfortable working under pressure, managing high workloads, and meeting time-sensitive deadlines.
Ability to learn new systems and technologies quickly and operate relevant enterprise applications at an advanced level.
Willingness to participate in on-call rotations, occasional non-standard working hours, and business-related travel as required.
Global working environment with opportunities to collaborate across teams and geographies.
Professional development programs, including leadership development and on-demand learning opportunities.
Well-being support covering financial, physical, and mental wellness through seminars, events, and an assistance program.
Diversity, equity, and inclusion initiatives designed to foster an inclusive and collaborative workplace.
Community engagement opportunities, including peer-led communities, business resource groups, volunteering, and social initiatives.
Structured onboarding and networking opportunities to help new employees connect with colleagues across the organization.
Country-specific elective benefits designed to accommodate local employee needs and lifestyles.
Opportunity to work with advanced cybersecurity, AI, ML, SIEM, SOAR, and automation technologies in a large-scale enterprise environment.

