Itsm Lead

Tekskills

Bengaluru

Hybrid

INR 1,800,000 - 2,800,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Tekskills seeks a talented Cyber Security Architect with 10–12 years of hands-on experience to lead EDR and SIEM operations. The role covers Defender and SentinelOne, MS Sentinel workflow, and diverse WAF platforms.

You will tune IDS/IPS rules, build KQL-based detections, and develop playbooks to enhance security posture. Candidates should understand Linux, Windows, AD, and network logging; readiness for US shift timing; and optional certifications SC-200/SC-100/CCNA Security/AZ-500 will be an

Qualifications

  • 10–12 years of experience in MS Defender, MS Sentinel, MS Intune, MS Purview, SentinelOne, Cisco IDS/IPS, Checkpoint IDS/IPS, F5 DCS WAF.
  • Experience implementing and optimizing MS Purview DLP solutions is a good to have.
  • Knowledge of Kusto query language; playbook & workbook creation and updation, Logic Apps configuration in MS Sentinel.
  • Understanding of Linux, Windows, AD, Network and security event logging.
  • In-depth understanding of security threats and threat environment to develop detection use cases.
  • Ensure effective operation of SIEM content: filters, rules, expressions and other identification mechanisms.
  • Provide professional data analysis to drive security measures and risk mitigation.
  • Strong verbal and written interpersonal communication skills.
  • Willingness to work in US shift timings as required.
  • Completion of one or more certifications: SC-200, SC-100, CCNA Security, AZ-500 is an added advantage.

Responsibilities

  • EDR platform management and optimisation in MS Defender and SentinelOne.
  • SIEM solution management and implementation in MS Sentinel.
  • Azure WAF, AWS WAF and F5 DCS WAF configuration, maintenance, and optimisation.
  • Checkpoint and Cisco Firepower IDS/IPS rules and signature tuning.
  • Perform Risk Assessment and provide recommendations to improve Security posture.
  • Prior experience in SOC and incident response.

Skills

EDR platform management
SIEM management
WAF configuration
IDS/IPS tuning
KQL / Kusto queries
Playbooks & Logic Apps
SOC & incident response
Security data analysis
Security logging & fundamentals
Threat detection use cases

Education

SC-200
SC-100
CCNA Security
AZ-500

Tools

MS Defender
SentinelOne
MS Sentinel
MS Intune
MS Purview
Azure WAF
AWS WAF
F5 DCS WAF
Checkpoint IDS/IPS
Cisco Firepower IDS/IPS

Job description

  • Primary mandate skill required
  1. EDR platform management and optimisation experience in tools : MS Defender and SentinelOne.
  1. SIEM solution management and implementation in MS sentinel.
  • Detection Engineering
  • Log source management
  • KQL logic and Defender Advanced hunting query building
  • Logic App implementation
  • SOAR playbook and use cases creation
  • AIR implementation
  • M365 Copilot Agent creation and implementation
  • Dashboard creation and optimisation
  • Secondary mandate skill required Azure WAF, AWS WAF and F5 DCS WAF(Distributed cloud) – Configuration, maintenance, and optimisation.
  • Flexible to hire in any location – If not, please mention job location – Chennai / Bangalore / Pune / Hyderabad
  • Detailed Job Description – Attached the JD.

Should have minimum 10 - 12 years of experience in the following technologies and tools including MS Defender, MS Sentinel, MS Intune, MS Purview, SentinelOne, Cisco IDS/IPS, Checkpoint IDS/IPS, F5 DCS WAF.

Experience in implementing, maintaining, and optimizing MS Purview DLP solutions will be good to have.

Should have knowledge in Kusto query language; playbook & workbook creation and updation, logic app configuration in MS Sentinel.

Understanding of Linux, Windows, AD, Network, and security event logging.

In-depth understanding of security threats, threat attack methods and the current threat environment to develop detection use cases.

Ensure effective operation of SIEM content: filters, rules, expressions and other identification mechanisms of the threat and vulnerability management technologies.

Provide professional data analysis to drive further security measures and risk mitigation activities.

Strong verbal and written interpersonal communication skills.

Willingness to work in US shift timings as required to support the team or at priority calls.

Completion of one or more certifications on the below is an added advantage: SC-200, SC-100, CCNA Security, AZ-500.

Primary skillset: Cyber Security Architect - ITM Engineering
Operational and Implementation hands-on expertise in
  1. 1. EDR platform management and optimisation experience in tools : MS Defender and SentinelOne.
  2. 2. SIEM solution management and implementation in MS sentinel.
  3. 3. Azure WAF, AWS WAF and F5 DCS WAF(Distributed cloud) – Configuration, maintenance, and optimisation.
  4. 4. Checkpoint and Cisco Firepower IDS/IPS rules and signature fine tuning.
  5. 5. Perform Risk Assessment and provide recommendations to improve Security posture.
  6. 6. Prior experience in SOC and incident response.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Itsm Lead
Itsm Lead

Tekskills • Pune District

Hybrid
INR 1,500,000 - 2,100,000
Itsm Lead
Itsm Lead

Tekskills • Chennai District

Hybrid
INR 2,000,000 - 4,500,000
Cyber Security Engineer
Cyber Security Engineer

Futurism Technologies • Mhalunge

On-site
INR 1,800,000 - 3,400,000
Security Solution Architect
Security Solution Architect

Netenrich Technologies • Hyderabad

On-site
INR 4,000,000 - 6,000,000
Technical Lead Engineer – Security Delivery
Technical Lead Engineer – Security Delivery

Whitefield Careers • Bengaluru

On-site
INR 1,800,000 - 3,200,000
Senior Cyber Threat Engineer
Senior Cyber Threat Engineer

YO IT Consulting • Maharashtra

On-site
INR 1,200,000 - 2,000,000
MS Sentinel and EDR Specialist, SOC L3 (SME)
MS Sentinel and EDR Specialist, SOC L3 (SME)

HypTechie • Faridabad District

On-site
INR 1,200,000 - 1,800,000
Cybersecurity Engineer – SIEM & Threat Detection
Cybersecurity Engineer – SIEM & Threat Detection

YO IT Consulting • Maharashtra

On-site
INR 1,200,000 - 1,500,000
Microsoft Defender Engineer
Microsoft Defender Engineer

JUARA IT SOLUTIONS • Chennai District

On-site
INR 1,200,000 - 2,200,000
Cyber Security Engineer
Cyber Security Engineer

Futurism Technologies, INC. • Pune District

Hybrid
INR 2,000,000 - 3,400,000