Job Purpose :-
Own and operate a broad enterprise security technology portfolio covering data protection, privileged access management, endpoint and extended detection and response, deception, and network threat detection and prevention. The role combines platform administration, policy engineering, service-health monitoring, incident support, configuration tuning, security integrations, operational reporting and continuous control improvement. The role also provides structured backup coverage for database activity monitoring and API security monitoring.
Key Responsibilities : -
- Lead day-to-day operation, administration and lifecycle management of assigned information security platforms.
- Design, implement, test and tune data loss prevention, information protection, access-control, endpoint, detection and network-security policies.
- Monitor platform availability, agent and sensor health, policy deployment, event ingestion, integration status, capacity and licensing dependencies.
- Investigate security alerts and service issues; coordinate containment, recovery, escalation and root-cause analysis.
- Maintain privileged-access controls, including account onboarding, credential governance, session monitoring, access reviews and emergency-access controls.
- Maintain endpoint and XDR coverage, validate telemetry, investigate events and coordinate approved response actions.
- Operate deception, intrusion-detection and intrusion-prevention controls; tune policies and exceptions.
- Integrate security telemetry with SIEM, ITSM and approved monitoring or case-management services.
- Own technology changes through impact assessment, testing, approval, implementation, rollback planning and validation.
- Maintain SOPs, runbooks, architecture records, baselines, inventories, access matrices and recovery procedures.
- Produce reporting covering coverage, availability, incidents, exceptions, risks, backlogs and remediation.
- Support audits, risk assessments and closure of technology findings.
- Mentor supporting engineers and ensure knowledge transfer and backup readiness.
- Provide first-level backup coverage for database activity monitoring and API security monitoring.
Required Experience and Skills : -
- 10+ years of information security, security engineering or security operations experience.
- Deep hands-on experience in at least two primary domains: DLP/information protection, PAM, endpoint/XDR, deception or IDS/IPS; working exposure to the remaining domains is preferred.
- Experience designing and tuning policies, classifiers, detection logic, thresholds, exceptions and response actions.
- Experience with security integrations, APIs, event forwarding, SIEM, ITSM and incident workflows.
- Strong understanding of least privilege, data classification, endpoint telemetry and network-security controls.
- Ability to troubleshoot platform, connector, agent, sensor, policy and event-ingestion issues.
- Strong documentation, reporting, stakeholder-management and mentoring skills.
Education and Preferred Credentials :
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering or a related discipline.
- Relevant professional certification in information security, security management or audit is preferred.
- Capability-based certifications in data protection, privileged access, endpoint/XDR or network security are advantageous.
- IT service management certification is advantageous.
Success Measures :-
- Platforms remain supported, available, integrated and measurably effective.
- Coverage gaps and failed components are identified and tracked to closure.
- Policy changes are tested, approved, documented and validated.
- Alert quality improves through evidence-based tuning.
- Documentation, backup access and knowledge-transfer records remain audit-ready.