Cyber Security Engineer

Insight Global

India

On-site

INR 2,800,000 - 6,000,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Insight Global seeks a senior cybersecurity incident responder to lead major investigations. You will coordinate triage, containment, eradication and recovery across enterprise environments.

Responsibilities include root-cause analysis, threat hunting, and developing SOC playbooks. Strong SIEM/EDR experience and cross-functional collaboration are essential for success in this role.

Qualifications

  • Bachelor's degree in Cybersecurity or related field.
  • 10+ years in cybersecurity with SOC/IR experience.
  • Led investigations of major incidents and data breaches.
  • Strong incident response methods and forensics knowledge.
  • Experience with enterprise security infrastructures.

Responsibilities

  • Lead investigation and response to major cybersecurity incidents.
  • Triage, analyze, contain, eradicate, and recover from incidents.
  • Perform root cause and impact analysis of attacks.
  • Analyze alerts using SIEM, EDR, and cloud security tools.
  • Coordinate across cybersecurity, infra, legal, and business teams.
  • Develop playbooks, runbooks, and SOC workflows.
  • Communicate incident status to executives and regulators.

Skills

Cybersecurity
SOC
Incident Response
Threat Intelligence
Automation
Leadership
Communication

Education

Bachelor's degree in Cybersecurity
Information Security
Computer Science / IT

Tools

Microsoft Sentinel
Splunk
QRadar
Elastic
LogRhythm

Job description

  • Lead the investigation and response of major cybersecurity incidents, including ransomware, phishing, insider threats, malware, credential compromise, and data breaches.
  • Perform incident triage, analysis, containment, eradication, recovery, and post-incident activities.
  • Conduct root cause and impact analysis to identify attack vectors, affected systems, and business impact.
  • Analyze security alerts, logs, network traffic, endpoint telemetry, cloud activity, and threat intelligence to determine the scope of incidents.
  • Utilize SIEM, EDR, NDR, cloud security, email security, and identity security tools to investigate and respond to security events.
  • Correlate data from multiple security technologies to identify malicious activity, reconstruct attack timelines, and uncover threat actor behavior.
  • Perform threat hunting activities and identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs).
  • Serve as the technical lead during major incidents and coordinate response efforts across cybersecurity, infrastructure, cloud, application, legal, privacy, compliance, and business teams.
  • Provide clear incident communications, status updates, executive briefings, and ensure proper documentation and regulatory reporting.
  • Develop, maintain, and optimize incident response playbooks, runbooks, and standard operating procedures.
  • Design and implement automation and SOAR workflows to improve investigation efficiency, response consistency, and SOC effectiveness.
  • Create and improve detection rules, use cases, and response processes while driving continuous improvements through lessons learned, threat intelligence, and incident trend analysis.

Minimum Qualifications:

  • Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field.
  • 10+ years of experience in cybersecurity, including significant experience in Security Operations Center (SOC) and Incident Response functions.
  • Proven experience leading investigations of major cybersecurity incidents and security breaches.
  • Strong understanding of incident response methodologies, attacker tactics, and forensic investigation techniques.
  • Experience working in enterprise or global environments with complex security infrastructures.
  • Ability to coordinate technical and non-technical stakeholders during high-pressure incident situations.
  • Experience working in one of the SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, LogRhythm, etc.)
  • Experience working in one of the Endpoint Detection and Response platforms (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, etc.)
  • Experience with query languages and scripting (KQL, SPL, Python, PowerShell, Bash/Shell scripting)
  • Experience with API integrations and workflow automations
  • Preferred Certifications:
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Forensic Analyst (GCFA)
  • CISSP
  • Certified SOC Analyst (CSA)
  • Microsoft Security Operations Analyst Associate

SANS Incident Response training or equivalent

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
Cyber Security Analyst
Cyber Security Analyst

Dun & Bradstreet • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Cybersecurity Advisor
Cybersecurity Advisor

Primera Medical Technologies • India

On-site
INR 2,800,000 - 4,600,000
Senior Security Engineer
Senior Security Engineer

Jobtailor • Bengaluru

On-site
INR 400,000 - 700,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Cyber Security Analyst (SOC)
Cyber Security Analyst (SOC)

Genpact • Pune District

On-site
INR 900,000 - 1,500,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,500,000 - 2,800,000
Security Operations Manager
Security Operations Manager

Angel One • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Cyber - Incident Management- Manager
Cyber - Incident Management- Manager

Deloitte Shared Services India • Bengaluru

On-site
INR 2,800,000 - 4,800,000
Associate SOC
Associate SOC

Publicis Groupe ANZ • Gurgaon

On-site
INR 1,400,000 - 2,200,000