Cybersecurity Operations Engineer

Armanino India LLP (USD)

Ahmedabad District

On-site

INR 1,500,000 - 2,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Armanino India LLP seeks a skilled cybersecurity operations professional to monitor, triage, and respond to security alerts across identity, endpoint, cloud, and collaboration platforms. The role emphasizes urgent escalation, thorough runbook adherence, and cross-continental teamwork with New York leadership.

Ideal candidates bring 4+ years in security operations, familiarity with incident response, and a hands-on approach to monitoring, documentation, and improved security processes.

Qualifications

  • 4+ years in cybersecurity operations, security monitoring, incident response support, infrastructure operations, cloud operations, systems administration, or related technology operations role
  • Hands-on experience supporting security monitoring, alert triage, incident response workflows, ticketing, documentation, and escalation processes
  • Experience managing cybersecurity escalations, monitoring alerts, incident response support, and operational handoffs
  • Experience working with U.S.-based or global technology teams
  • Experience operating in a structured runbook, ticketing, monitoring, and escalation environment
  • Cybersecurity operations across identity, endpoint, cloud, email, network, infrastructure, and collaboration platforms
  • Cybersecurity monitoring concepts, alert triage, escalation handling, and incident documentation
  • Monitoring and alerting tools, ticketing systems, dashboards, and operational reporting
  • Consistent hands-on work with monitoring solutions to improve visibility, alert quality, response accuracy, and operational follow-through
  • Microsoft security, identity, endpoint, Microsoft 365, Azure, Windows Server, Active Directory, and network security fundamentals
  • Incident management, problem management, change awareness, and operational handoff practices
  • Runbook execution, process documentation, escalation procedures, and service operations discipline
  • Strong individual ownership, accountability, prioritization, and workload management skills
  • Clear, concise communication with New York-based leadership and cross-functional teams
  • Excellent verbal and written communication skills with the ability to keep leadership informed during active issues, escalations, and operational handoffs
  • Strong judgment on when to resolve, escalates, or request additional support
  • Availability to manage multiple operational priorities while maintaining accuracy and urgency
  • Extreme ownership mindset with strong documentation, follow-through, accountability, and attention to detail for all assigned responsibilities
  • Self-starter who can identify issues, take action, improve monitoring coverage, and drive work forward without waiting for step-by-step direction
  • Demonstrates extreme urgency when responding to escalations, alerts, incidents, and time-sensitive operational issues
  • Availability to overlap with New York-based teams through at least 12:00 PM Eastern Time
  • Experience working on an offshore or India-based technology operations team supporting U.S. stakeholders
  • Experience in professional services, consulting, financial services, or other high-accountability enterprise environments
  • Experience with Microsoft security, endpoint, identity, and cloud operations tools
  • Experience improving runbooks, alert tuning, dashboards, or operational reporting
  • ITIL, SOC, NOC, or service operations background
  • Certifications: Security+, SC-900, AZ-900, AZ-500, Microsoft security certifications, ITIL Foundation, Network+, or equivalent

Responsibilities

  • Support the India-based Infrastructure and Cybersecurity Operations Team responsible for day-to-day cybersecurity monitoring and operational response
  • Monitor security, identity, endpoint, cloud, email, and infrastructure alerts according to assigned responsibilities and defined procedures
  • Take ownership of assigned tickets, alerts, escalations, and follow-up items through resolution or proper handoff
  • Maintain clear daily visibility into open work, aging issues, blockers, and items requiring escalation
  • Escalate risks, blockers, recurring issues, and operational gaps to team leadership and New York-based teams
  • Triage and support cybersecurity incidents across identity, endpoint, cloud, email, network, infrastructure, and collaboration environments
  • Follow approved security runbooks for investigation, validation, documentation, response, containment support, and escalation
  • Support response for security-impacting issues and communicate status clearly
  • Partner with New York-based cybersecurity, infrastructure, platform, and engineering teams on escalated security issues
  • Respond to security escalations with extreme urgency and ensure issues are followed through to resolution or proper handoff
  • Identify repeat security issues and recommend process, monitoring, automation, or control improvements
  • Perform initial review, triage, documentation, and escalation of cybersecurity alerts from security, identity, endpoint, cloud, email, and monitoring platforms
  • Ensure alert handling follows approved security runbooks and escalation paths
  • Coordinate with cybersecurity, compliance, infrastructure, and cloud teams on incidents that require deeper investigation or escalation
  • Track assigned alert activity, response notes, handoffs, and follow-up actions
  • Raise patterns, control gaps, and recurring alert issues to New York-based leadership
  • Ensure all cybersecurity alerts, incidents, and escalations are handled according to defined security runbooks
  • Maintain consistency in ticket documentation, alert notes, handoffs, and escalation summaries
  • Review runbook gaps and recommend updates based on recurring operational issues
  • Understand expected response steps, communication standards, escalation thresholds, and documentation requirements
  • Drive a culture of repeatable execution, ownership, and follow-through
  • Maintain clear communication with team leadership, the Director of Core Technology in New York, and New York-based Core Technology and cybersecurity teams on assigned alerts, incidents, escalations, and operational priorities
  • Provide concise status updates on active incidents, alerts, risks, and follow-up actions
  • Work directly with New York-based teams to ensure clean handoffs, shared visibility, and consistent ownership
  • Participate in regular operational reviews, escalation discussions, and planning sessions with U.S.-based leadership
  • Ensure availability to work with New York-based teams until at least 12:00 PM Eastern Time
  • Take extreme ownership of assigned responsibilities, tickets, alerts, monitoring tasks, and escalations
  • Operate as a self-starter who identifies issues, takes action, improves monitoring visibility, and drives work forward without waiting for step-by-step direction
  • Maintain strong documentation, clear handoffs, and consistent follow-through on all assigned work
  • Work with urgency on escalations, incidents, alerts, and time-sensitive operational issues
  • Raise blockers, capacity concerns, skill gaps, and improvement opportunities to team leadership early

Skills

Security monitoring
Incident response
Ticketing
Escalation processes
Cloud security
Identity security
Microsoft security
Active Directory

Tools

Microsoft 365
Azure
Windows Server
Active Directory

Job description

At Armanino, you determine your career path. This means it's possible to pursue challenges you are passionate about, in industries you care about. Armanino (USA) is proud to beamong the top 20 Largest Firms in the United States of Americaand one of theBest Places to Work. Armanino (USA) has more than 2500 employees across the USA and more than 20 offices in different states of the USA. We have a community of resources that are ready and willing to support your ideas, build your skills and expand your professional network. We want you to integrate all aspects of your life with your career. At Armanino, we know you don’t check-out of life when you check-in at work. That’s why we’ve created a unique work environment where your passions, work, and family & friends can overlap. We want to help you achieve growth by giving you access to a network of smart and supportive people, willing to listen to your ideas.

Responsibilities
  • Support the India-based Infrastructure and Cybersecurity Operations Team responsible for day-to-day cybersecurity monitoring and operational response
  • Monitor security, identity, endpoint, cloud, email, and infrastructure alerts according to assigned responsibilities and defined procedures
  • Take ownership of assigned tickets, alerts, escalations, and follow-up items through resolution or proper handoff
  • Maintain clear daily visibility into open work, aging issues, blockers, and items requiring escalation
  • Escalate risks, blockers, recurring issues, and operational gaps to team leadership and New York-based teams
  • Triage and support cybersecurity incidents across identity, endpoint, cloud, email, network, infrastructure, and collaboration environments
  • Follow approved security runbooks for investigation, validation, documentation, response, containment support, and escalation
  • Support response for security-impacting issues and communicate status clearly
  • Partner with New York-based cybersecurity, infrastructure, platform, and engineering teams on escalated security issues
  • Respond to security escalations with extreme urgency and ensure issues are followed through to resolution or proper handoff
  • Identify repeat security issues and recommend process, monitoring, automation, or control improvements
  • Perform initial review, triage, documentation, and escalation of cybersecurity alerts from security, identity, endpoint, cloud, email, and monitoring platforms
  • Ensure alert handling follows approved security runbooks and escalation paths
  • Coordinate with cybersecurity, compliance, infrastructure, and cloud teams on incidents that require deeper investigation or escalation
  • Track assigned alert activity, response notes, handoffs, and follow-up actions
  • Raise patterns, control gaps, and recurring alert issues to New York-based leadership
  • Ensure all cybersecurity alerts, incidents, and escalations are handled according to defined security runbooks
  • Maintain consistency in ticket documentation, alert notes, handoffs, and escalation summaries
  • Review runbook gaps and recommend updates based on recurring operational issues
  • Understand expected response steps, communication standards, escalation thresholds, and documentation requirements
  • Drive a culture of repeatable execution, ownership, and follow-through
  • Maintain clear communication with team leadership, the Director of Core Technology in New York, and New York-based Core Technology and cybersecurity teams on assigned alerts, incidents, escalations, and operational priorities
  • Provide concise status updates on active incidents, alerts, risks, and follow-up actions
  • Work directly with New York-based teams to ensure clean handoffs, shared visibility, and consistent ownership
  • Participate in regular operational reviews, escalation discussions, and planning sessions with U.S.-based leadership
  • Ensure availability to work with New York-based teams until at least 12:00 PM Eastern Time
  • Take extreme ownership of assigned responsibilities, tickets, alerts, monitoring tasks, and escalations
  • Operate as a self-starter who identifies issues, takes action, improves monitoring visibility, and drives work forward without waiting for step-by-step direction
  • Maintain strong documentation, clear handoffs, and consistent follow-through on all assigned work
  • Work with urgency on escalations, incidents, alerts, and time-sensitive operational issues
  • Raise blockers, capacity concerns, skill gaps, and improvement opportunities to team leadership early
Requirements
  • 4+ years in cybersecurity operations, security monitoring, incident response support, infrastructure operations, cloud operations, systems administration, or related technology operations role
  • Hands‑on experience supporting security monitoring, alert triage, incident response workflows, ticketing, documentation, and escalation processes
  • Experience managing cybersecurity escalations, monitoring alerts, incident response support, and operational handoffs
  • Experience working with U.S.-based or global technology teams
  • Experience operating in a structured runbook, ticketing, monitoring, and escalation environment
  • Cybersecurity operations across identity, endpoint, cloud, email, network, infrastructure, and collaboration platforms
  • Cybersecurity monitoring concepts, alert triage, escalation handling, and incident documentation
  • Monitoring and alerting tools, ticketing systems, dashboards, and operational reporting
  • Consistent hands‑on work with monitoring solutions to improve visibility, alert quality, response accuracy, and operational follow-through
  • Microsoft security, identity, endpoint, Microsoft 365, Azure, Windows Server, Active Directory, and network security fundamentals
  • Incident management, problem management, change awareness, and operational handoff practices
  • Runbook execution, process documentation, escalation procedures, and service operations discipline
  • Strong individual ownership, accountability, prioritization, and workload management skills
  • Clear, concise communication with New York-based leadership and cross-functional teams
  • Excellent verbal and written communication skills with the ability to keep leadership informed during active issues, escalations, and operational handoffs
  • Strong judgment on when to resolve, escalates, or request additional support
  • Availability to manage multiple operational priorities while maintaining accuracy and urgency
  • Extreme ownership mindset with strong documentation, follow-through, accountability, and attention to detail for all assigned responsibilities
  • Self-starter who can identify issues, take action, improve monitoring coverage, and drive work forward without waiting for step‑by-step direction
  • Demonstrates extreme urgency when responding to escalations, alerts, incidents, and time-sensitive operational issues
  • Availability to overlap with New York-based teams through at least 12:00 PM Eastern Time
  • Experience working on an offshore or India-based technology operations team supporting U.S. stakeholders
  • Experience in professional services, consulting, financial services, or other high-accountability enterprise environments
  • Experience with Microsoft security, endpoint, identity, and cloud operations tools
  • Experience improving runbooks, alert tuning, dashboards, or operational reporting
  • ITIL, SOC, NOC, or service operations background
  • Certifications: Security+, SC-900, AZ-900, AZ-500, Microsoft security certifications, ITIL Foundation, Network+, or equivalent
Compensation and Benefits
  • Compensation: Commensurate with Industry standards
  • Other Benefits: Provident Fund, Gratuity, Medical Insurance, Group Personal Accident Insurance etc. employment benefits depending on the position.

Armanino provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Armanino complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Armanino expressly prohibits any form of workplace harassment based on race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. Improper interference with the ability of Armanino employees to perform their job duties may result in discipline up to and including discharge.

We have a community of resources that are ready and willing to support your ideas, build your skills and expand your professional network.

Armanino is one of the top 25 largest independent accounting and business consulting firms in the United States. We are a nationwide leader serving privately held companies and private individuals, as well as nonprofit organizations and public entities.

Please see our Privacy Policy - Privacy Policy - (armanino.in)

We have a community of resources that are ready and willing to support your ideas, build your skills and expand your professional network.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager - Infrastructure and Security Operations Center
Manager - Infrastructure and Security Operations Center

Armanino India LLP (USD) • Ahmedabad District

On-site
INR 1,800,000 - 3,000,000
Provident Fund
Medical Insurance
Group Personal Accident Insurance
Infrastructure and Cloud Operations Engineer
Infrastructure and Cloud Operations Engineer

Armanino India LLP (USD) • Ahmedabad District

On-site
INR 1,500,000 - 2,500,000
Provident Fund
Gratuity
Medical Insurance
+1
Infrastructure and Cloud Operations Engineer
Infrastructure and Cloud Operations Engineer

Armanino • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Provident Fund
Gratuity
Medical Insurance
+1
Manager - Infrastructure and Security Operations Center
Manager - Infrastructure and Security Operations Center

Armanino • Ahmedabad District

On-site
INR 1,800,000 - 3,000,000
provident Fund
Gratuity
Medical Insurance
+1
Manager - Infrastructure and Security Operations Center
Manager - Infrastructure and Security Operations Center

Armanino LLP • India

On-site
INR 2,500,000 - 4,000,000
Provident Fund
Medical Insurance
Group Personal Accident Insurance
Senior Manager - Strategy and Transformation
Senior Manager - Strategy and Transformation

Armanino India LLP (USD) • Hyderabad

On-site
INR 1,400,000 - 2,200,000
Provident Fund
Gratuity
Medical Insurance
+1
Manager - IT Attest (SOC)
Manager - IT Attest (SOC)

Armanino India LLP (USD) • Hyderabad

On-site
INR 1,500,000 - 2,500,000
Provident Fund
Gratuity
Medical Insurance
+1
Manager - IT Attest (SOC)
Manager - IT Attest (SOC)

Armanino LLP • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Senior Finance Manager
Senior Finance Manager

Armanino India LLP (USD) • Ahmedabad District

On-site
INR 2,500,000 - 6,000,000
Provident Fund
Gratuity
Medical Insurance
+1
Senior Finance Manager
Senior Finance Manager

Armanino LLP • India

On-site
INR 2,500,000 - 4,500,000
Provident Fund
Gratuity
Medical Insurance
+1