Cloud App Security Engineer – Consultant

Jobtailor

Bengaluru

On-site

INR 700,000 - 1,100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a CSOC Cloud Applications Analyst to monitor and investigate security alerts generated by Microsoft Defender for Cloud Apps (MDCA) and perform alert triage within defined CSOC processes.

Responsibilities include supporting containment and remediation with Identity, Endpoint, Email Security, and IT operations teams, escalating complex findings to L2/L3 specialists, and documenting evidence and RCA outcomes.

Qualifications

  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or Engineering.
  • 2–4 years of cybersecurity experience with exposure to SOC operations, cloud security, or security monitoring roles.
  • Hands-on experience with Microsoft Defender for Cloud Apps is required.
  • Experience supporting cloud or SaaS security incidents in enterprise environments is preferred.
  • SC-200: Microsoft Security Operations Analyst certification.

Responsibilities

  • Monitor and investigate cloud‑application‑related security alerts generated by MDCA under CSOC processes.
  • Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.
  • Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.
  • Assist in containment and remediation activities with Identity, Endpoint, Email, and IT platform teams.
  • Escalate complex or high‑risk cloud‑app security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.
  • Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.
  • Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.
  • Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.
  • Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.
  • Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.
  • Maintain accurate investigation notes, incident documentation, and response records.
  • Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.
  • Support audit and compliance activities related to cloud application security controls when required.

Skills

Microsoft Defender for Cloud Apps
Cloud Security
Incident Investigation
SOC Operations
SC-200 Certification

Education

Bachelor's degree in CS/IT/Cybersecurity/Engineering

Tools

Microsoft Defender for Cloud Apps

Job description

  • Monitor and investigate cloud‑application‑related security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes.
  • Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.
  • Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.
  • Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams.
  • Escalate complex or high‑risk cloud‑app security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.
  • Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.
  • Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.
  • Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.
  • Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.
  • Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.
  • Maintain accurate investigation notes, incident documentation, and response records.
  • Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.
  • Support audit and compliance activities related to cloud application security controls when required.
Requirements
  • Bachelor’s degree in computer science, Information Technology, Cybersecurity, or Engineering.
  • 2 – 4 years of cybersecurity experience, with exposure to SOC operations, cloud security, or security monitoring roles.
  • Hands‑on experience or operational exposure to Microsoft Defender for Cloud Apps is required.
  • Experience supporting low to medium‑severity cloud or SaaS security incidents in enterprise environments is preferred.
  • Certifications:
  • - SC‑200: Microsoft Security Operations Analyst
Core Competencies

Demonstrates expertise in cloud application security, incident investigation, and risk assessment, with a strong focus on using Microsoft Defender for Cloud Apps. Capable of collaborating with cross-functional teams to enhance security posture and compliance.

Highest-signal resume keywords
  • Microsoft Defender For Cloud Apps
  • Cloud Security
  • Incident Investigation
  • Cybersecurity Experience
  • SC-200 Certification
ATS Optimization Keywords
Hard Skills
  • Alert Triage
  • Risk Assessment
  • Data Exposure Analysis
  • User Behavior Analysis
  • Cloud Telemetry Analysis
  • Incident Documentation
  • Policy Tuning
  • Cloud App Governance
  • Security Monitoring
  • RCA Discussions
Soft Skills
  • Collaboration
  • Communication
  • Analytical Thinking
  • Attention To Detail
Certifications & Qualifications
  • SC-200: Microsoft Security Operations Analyst
Industry Keywords
  • CSOC Processes
  • SaaS Security
  • Shadow IT Discovery
  • Cloud App Risk Assessments
  • Compliance Activities
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SOC Analyst – Cloud Security Operations
SOC Analyst – Cloud Security Operations

Delta6Labs FinTech Pvt Ltd • India

On-site
INR 1,000,000 - 1,500,000
Cloud Security & DevOps Expert
Cloud Security & DevOps Expert

Network Intelligence • Pune District

On-site
INR 800,000 - 1,200,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Jobtailor • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Cloud security governance Analyst
Cloud security governance Analyst

Promaynov Advisory Services Pvt. Ltd • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Cloud Security
Cloud Security

Thakral One • Bengaluru

On-site
INR 1,500,000 - 2,100,000
Associate Security Engineer
Associate Security Engineer

Minfy Technologies • Hyderabad

On-site
INR 900,000 - 1,500,000
Security Engineer
Security Engineer

ISA • Maharashtra

On-site
INR 1,500,000 - 2,300,000
Analyst - Microsoft Defender
Analyst - Microsoft Defender

CDW UK • Bengaluru

On-site
INR 800,000 - 1,200,000
Security Technician - SOC Analyst
Security Technician - SOC Analyst

Fujitsu • Pune District, Bengaluru, Dadri

Hybrid
INR 900,000 - 1,300,000
Expert IT Cyber Defense Analyst
Expert IT Cyber Defense Analyst

Jobtailor • Pune District

On-site
INR 900,000 - 1,500,000