Group Specialist - Cyber Engineering Automation

DP World

Gurugram District

On-site

INR 3,500,000 - 6,000,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

DP World in Gurugram, India, seeks a senior security automation engineer to design and implement automated workflows across SOC, CSPM, VM, and IAM. You will integrate Sentinel, Wiz, SailPoint, Check Point and Zscaler via APIs and build SOAR-driven incident response and ticketing workflows.

The role emphasizes cross-platform integrations, real‑time telemetry, and scalable automation across global regions, with Terraform/Ansible/IaC guardrails and CI/CD integration.

Qualifications

  • Bachelor’s degree in Computer Science or Engineering.
  • 7–12 years in cybersecurity or security engineering with 3+ years in security automation/SOAR.
  • Hands-on expertise with SOAR platforms and scripting languages.
  • Cloud automation across Azure, AWS, GCP and related tools.
  • Experience with security APIs, JSON, YAML and CI/CD tooling.

Responsibilities

  • Design and implement automated workflows and playbooks across SOC, CSPM, VM, and IAM.
  • Integrate tools like Sentinel, Wiz, SailPoint, Check Point and Zscaler via APIs.
  • Build automation for incident response and ticketing using SOAR frameworks.
  • Develop cross-platform integrations for IT, OT, and Cloud security visibility.
  • Enable real-time telemetry ingestion and data correlation.
  • Create reusable automation modules for global rollout.
  • Automate cloud posture monitoring and remediation via CSPM/CNAPP APIs.
  • Engineer IaC security controls with Terraform, Ansible, or ARM templates.
  • Integrate automation into DevSecOps pipelines for continuous compliance.
  • Implement AI-driven response playbooks for phishing and malware cases.
  • Enrich threat intel and automate ticket closures (JIRA, ServiceNow).
  • Tune automation to MITRE ATT&CK and ATLAS techniques.

Skills

SOAR platforms
Security APIs
Cloud automation
IaC tools
Terraform
Ansible
Jenkins
GitHub Actions
SIEM/XDR
REST API
Python scripting
Cortex XSOAR

Education

Bachelor’s Degree in Computer Science or Engineering

Tools

Microsoft Sentinel Logic Apps
Splunk SOAR
FortiSOAR

Job description

Key Accountabilities
  • Design and implement automated workflows and playbooks across SOC, CSPM, VM, and IAM platforms.
  • Integrate diverse tools such as Sentinel (SIEM/XDR), Wiz (CSPM/CNAPP), SailPoint (IAM), Check Point (EDR/DLP), and Zscaler (SSE) using APIs and event-driven automation.
  • Build automation for incident response (IR), threat enrichment, user isolation, and ticketing workflows using SOAR and orchestration frameworks (e.g., Microsoft Sentinel Logic Apps, Cortex XSOAR, FortiSOAR, or custom Python-based frameworks).
  • Develop and maintain cross-platform integrations between IT, OT, and Cloud security tools for unified visibility.
  • Enable real-time telemetry ingestion and correlation using APIs, data pipelines, or event hubs.
  • Create reusable automation modules and templates for consistent rollout across global regions.
  • Automate cloud posture monitoring and remediation (Azure, AWS, GCP) using CSPM/CNAPP APIs
  • Engineer infrastructure-as-code (IaC) security controls and guardrails using Terraform, Ansible, or ARM templates.
  • Integrate automation into DevSecOps pipelines for continuous compliance, vulnerability scanning, and drift detection.
  • Implement AI-driven response and enrichment playbooks for phishing, malware, and insider threat cases.
  • Develop automation for threat intel enrichment (VirusTotal, MISP, Recorded Future, etc.) and ticket closure workflows (JIRA, ServiceNow).
  • Continuously tune automation based on MITRE ATT&CK and MITRE ATLAS techniques.
JOB DESCRIPTION
  • Design and implement automated workflows and playbooks across SOC, CSPM, VM, and IAM platforms.
  • Integrate diverse tools such as Sentinel (SIEM/XDR), Wiz (CSPM/CNAPP), SailPoint (IAM), Check Point (EDR/DLP), and Zscaler (SSE) using APIs and event-driven automation.
  • Build automation for incident response (IR), threat enrichment, user isolation, and ticketing workflows using SOAR and orchestration frameworks (e.g., Microsoft Sentinel Logic Apps, Cortex XSOAR, FortiSOAR, or custom Python-based orchestration).
  • Develop and maintain cross-platform integrations between IT, OT, and Cloud security tools for unified visibility.
  • Enable real-time telemetry ingestion and correlation using APIs, data pipelines, or event hubs.
  • Create reusable automation modules and templates for consistent rollout across global regions.
  • Automate cloud posture monitoring and remediation (Azure, AWS, GCP) using CSPM/CNAPP APIs
  • Engineer infrastructure-as-code (IaC) security controls and guardrails using Terraform, Ansible, or ARM templates.
  • Integrate automation into DevSecOps pipelines for continuous compliance, vulnerability scanning, and drift detection.
  • Implement AI-driven response and enrichment playbooks for phishing, malware, and insider threat cases.
  • Develop automation for threat intel enrichment (VirusTotal, MISP, Recorded Future, etc.) and ticket closure workflows (JIRA, ServiceNow).
  • Continuously tune automation based on MITRE ATT&CK and MITRE ATLAS techniques.
OTHER
  • Act as an ambassador for DP World always when working; promoting and demonstrating positive behaviours in harmony with DP World’s Founder’s Principles, values and culture; ensuring the highest level of safety is applied in all activities; understanding and following DP World’s Code of Conduct and Ethics policies
  • Perform other related duties as assigned
Qualifications, Experience And Skills
  • A Bachelor’s Degree in Computer Science, Engineering with 16+ years of relevant experience
  • 7–12 years of cybersecurity or security engineering experience, with at least 3 years in security automation/SOAR engineering.
  • Hands-on expertise with:
  • SOAR platforms: Cortex XSOAR, FortiSOAR, Microsoft Sentinel Logic Apps, Splunk SOAR, or custom Python-based orchestration.
  • Security APIs and scripting: Python, PowerShell, REST API, JSON, YAML.
  • Cloud environments: Azure, AWS, GCP automation (Lambda, Logic Apps, Functions, EventHub).
  • Infrastructure tools: Terraform, Ansible, Jenkins, GitHub Actions.
  • Knowledge of security tools integration across SIEM, EDR/XDR, IAM, DLP, CSPM, CNAPP, CASB, and vulnerability scanners.
  • Strong understanding of incident response, SOC processes, and MITRE ATT&CK frameworks.
  • Proven track record of reducing manual operational workload via automation at scale.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Group Specialist - Cyber Engineering Automation
Group Specialist - Cyber Engineering Automation

DP World • Hyderabad

On-site
INR 2,000,000 - 3,500,000
Group Specialist - Cyber Engineering Automation
Group Specialist - Cyber Engineering Automation

The Peninsular and Oriental Steam Navigation Company • Hyderabad

On-site
INR 1,800,000 - 3,000,000
Assoc. Manager, IT Security
Assoc. Manager, IT Security

Yum! Brands • Gurugram District

On-site
INR 3,000,000 - 6,000,000
Assoc. Manager, IT Security
Assoc. Manager, IT Security

KFC Corporation • India

Hybrid
INR 1,500,000 - 2,800,000
Group Security Operations Center Specialist
Group Security Operations Center Specialist

DP World • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Security Automation Engineer
Security Automation Engineer

Lumen Technologies India • Dadri

On-site
INR 1,800,000 - 2,800,000
Microsoft SC-200
AZ-204
Power Platform certification
+3
Automation Development Engineer
Automation Development Engineer

nTech Workforce • Hyderabad

On-site
INR 800,000 - 1,200,000
Security Automation Engineer
Security Automation Engineer

Wpp • Chennai District

Hybrid
INR 1,200,000 - 1,800,000
Hybrid work model
Security Automation Engineer
Security Automation Engineer

Cbts • Chennai District

On-site
INR 1,400,000 - 2,200,000
Security Automation Engineer
Security Automation Engineer

AlphaSense Oy • Delhi

On-site
INR 1,500,000 - 2,500,000