Lead Engineer, Information Security

Lever, Inc.

India

Remote

INR 1,500,000 - 2,200,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Fully remote within India
Senior technical ownership
Exposure to enterprise SIEM/EDR/cloud
Security analytics focus
Cross-functional collaboration
Professional growth

Job summary

Lever, Inc. is seeking a Lead Engineer, Information Security in India to lead monitoring, detection, and incident response efforts.

The role emphasizes hands-on operations, SIEM rule tuning, and cross-team collaboration to strengthen security visibility and automation. You will own monitoring improvements, validate telemetry coverage across Windows, endpoints, cloud, and networks, and drive measurable reductions in noise and vulnerabilities.

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline.
  • 4+ years of hands-on experience in security operations, security monitoring, incident detection and response, vulnerability management, or a related information security field.
  • Strong practical experience investigating security events and working with SIEM platforms, including developing or tuning detection and correlation rules.
  • Solid understanding of security telemetry and log sources across Windows, endpoints, networks, applications, cloud environments, and security platforms.
  • Ability to distinguish legitimate activity, false positives, suspicious behavior, and potential security threats through detailed event analysis.
  • Experience with EDR technologies such as CrowdStrike or equivalent solutions.
  • Working knowledge of vulnerability management and cloud security platforms.
  • Strong understanding of threat detection, incident response, identity and access management, network security, endpoint security, and cloud security concepts.
  • Ability to independently investigate technical issues, take ownership, and drive problems through resolution.
  • Strong written and verbal communication skills, with the ability to explain technical security topics clearly to both technical and non-technical stakeholders.
  • Ability to collaborate effectively with infrastructure, application, cloud, and security teams.
  • Experience with Exabeam or another enterprise SIEM or security analytics platform is preferred.
  • Experience with Wiz or comparable cloud security and vulnerability management technologies is preferred.
  • Familiarity with Sumo Logic or similar log management platforms is advantageous.
  • Experience developing detection logic using multiple security data sources and onboarding or validating SIEM log sources is beneficial.
  • Scripting or automation experience using PowerShell, Python, APIs, or similar technologies is a plus.
  • Familiarity with NIST CSF, NIST Incident Response Guidance, MITRE ATT&CK, CIS Controls, or ISO 27001 is desirable.
  • Relevant certifications such as CISSP, Security+, CISM, GIAC, GCIH, GCIA, or equivalent are preferred.

Responsibilities

  • Investigate, triage, document, and respond to security alerts, events, and incidents, ensuring timely and appropriate resolution.
  • Develop, test, tune, and maintain SIEM correlation and detection rules while improving detection accuracy and reducing unnecessary false positives.
  • Identify gaps in security monitoring and validate that relevant Windows, endpoint, network, application, cloud, and security logs are properly collected and usable for investigations.
  • Support the onboarding and integration of new systems, applications, cloud platforms, and security technologies into the monitoring environment.
  • Work with security technologies such as Exabeam, CrowdStrike, Wiz, and comparable security monitoring and cloud security platforms.
  • Support vulnerability management through analysis, reporting, dashboards, trend identification, and improved visibility into security risks.
  • Develop security dashboards, metrics, and automated reporting that reduce manual effort and provide actionable information to technical teams and leadership.
  • Assist with incident investigations by collecting and analyzing relevant logs, telemetry, and other security evidence.
  • Participate in incident response tabletop exercises and security preparedness activities.
  • Identify operational and technical improvement opportunities and own initiatives from problem identification through implementation and validation.
  • Collaborate with Security Operations and wider technology teams, sharing expertise and contributing to stronger processes and capabilities.
  • Maintain clear documentation covering detection logic, monitoring coverage, investigations, security procedures, and operational practices.

Skills

SIEM
Incident response
Vulnerability management
EDR (CrowdStrike)
Cloud security
Telemetry/logs
Automation
Log analytics
PowerShell/Python
Stakeholder comms

Education

Bachelor's degree in Information Security / Cybersecurity / CS / IT or related

Tools

Exabeam
CrowdStrike
Wiz
Sumo Logic

Job description

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Engineer, Information Security based in India.

This is a hands-on senior security role focused on strengthening security monitoring, detection, vulnerability management, and incident response capabilities. You will investigate security events, improve SIEM detection logic, and ensure critical telemetry is visible and actionable. The role combines day-to-day security operations with continuous improvement and technical ownership. You will collaborate closely with Security, Infrastructure, Cloud, Application, and other technology teams. The position offers the opportunity to work with modern SIEM, EDR, cloud security, and vulnerability management technologies. You will play a key role in reducing noise, improving detection coverage, and increasing incident response readiness. Success will be measured through stronger security visibility, automation, and measurable improvements to the overall security program.

Accountabilities
  • Investigate, triage, document, and respond to security alerts, events, and incidents, ensuring timely and appropriate resolution.

  • Develop, test, tune, and maintain SIEM correlation and detection rules while improving detection accuracy and reducing unnecessary false positives.

  • Identify gaps in security monitoring and validate that relevant Windows, endpoint, network, application, cloud, and security logs are properly collected and usable for investigations.

  • Support the onboarding and integration of new systems, applications, cloud platforms, and security technologies into the monitoring environment.

  • Work with security technologies such as Exabeam, CrowdStrike, Wiz, and comparable security monitoring and cloud security platforms.

  • Support vulnerability management through analysis, reporting, dashboards, trend identification, and improved visibility into security risks.

  • Develop security dashboards, metrics, and automated reporting that reduce manual effort and provide actionable information to technical teams and leadership.

  • Assist with incident investigations by collecting and analyzing relevant logs, telemetry, and other security evidence.

  • Participate in incident response tabletop exercises and security preparedness activities.

  • Identify operational and technical improvement opportunities and own initiatives from problem identification through implementation and validation.

  • Collaborate with Security Operations and wider technology teams, sharing expertise and contributing to stronger processes and capabilities.

  • Maintain clear documentation covering detection logic, monitoring coverage, investigations, security procedures, and operational practices.

Requirements
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline.

  • 4+ years of hands-on experience in security operations, security monitoring, incident detection and response, vulnerability management, or a related information security field.

  • Strong practical experience investigating security events and working with SIEM platforms, including developing or tuning detection and correlation rules.

  • Solid understanding of security telemetry and log sources across Windows, endpoints, networks, applications, cloud environments, and security platforms.

  • Ability to distinguish legitimate activity, false positives, suspicious behavior, and potential security threats through detailed event analysis.

  • Experience with EDR technologies such as CrowdStrike or equivalent solutions.

  • Working knowledge of vulnerability management and cloud security platforms.

  • Strong understanding of threat detection, incident response, identity and access management, network security, endpoint security, and cloud security concepts.

  • Ability to independently investigate technical issues, take ownership, and drive problems through resolution.

  • Strong written and verbal communication skills, with the ability to explain technical security topics clearly to both technical and non-technical stakeholders.

  • Ability to collaborate effectively with infrastructure, application, cloud, and security teams.

  • Experience with Exabeam or another enterprise SIEM or security analytics platform is preferred.

  • Experience with Wiz or comparable cloud security and vulnerability management technologies is preferred.

  • Familiarity with Sumo Logic or similar log management platforms is advantageous.

  • Experience developing detection logic using multiple security data sources and onboarding or validating SIEM log sources is beneficial.

  • Scripting or automation experience using PowerShell, Python, APIs, or similar technologies is a plus.

  • Familiarity with NIST CSF, NIST Incident Response Guidance, MITRE ATT&CK, CIS Controls, or ISO 27001 is desirable.

  • Relevant certifications such as CISSP, Security+, CISM, GIAC, GCIH, GCIA, or equivalent are preferred.

Benefits
  • Fully remote working opportunity within India.

  • Senior technical ownership within a security-focused environment.

  • Exposure to enterprise SIEM, EDR, cloud security, vulnerability management, and security analytics technologies.

  • Opportunity to make measurable improvements to detection coverage, monitoring visibility, automation, reporting, and incident response readiness.

  • Cross-functional collaboration with Security, Infrastructure, Cloud, Application, and other technology teams.

  • Opportunity to contribute to security operations maturity and influence technical processes and capabilities.

  • Professional growth through hands-on exposure to modern cybersecurity practices and technologies.

  • Opportunity to develop expertise in security frameworks, detection engineering, incident response, and security automation.

  • Full-time employment.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Analyst, CSOC
Security Analyst, CSOC

Lever, Inc. • India

Remote
INR 900,000 - 1,500,000
Medical, dental, and vision insurance
Provident Fund
Remote work within India
+1
Information Security Spec II
Information Security Spec II

Jobgether SRL • India

Remote
INR 1,800,000 - 3,200,000
Remote work in India
Annual health checkup
Marriage and paternity leave
+4
Chief Analyst, Cyber Security Operations
Chief Analyst, Cyber Security Operations

SES S.A Brazil • Chennai District

On-site
INR 3,500,000 - 6,000,000
Lead Engineer - Security Consultant
Lead Engineer - Security Consultant

Esyasoft Holding Ltd • Kolkata Metropolitan Area

On-site
INR 4,000,000 - 7,000,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Neurealm • Chennai District

On-site
INR 2,800,000 - 6,000,000
Security Engineer
Security Engineer

HCL Technologies Limited • Dadri, Bengaluru

On-site
INR 2,000,000 - 4,000,000
Senior Security Engineer
Senior Security Engineer

Cynosure Corporate Solutions • Chennai

On-site
INR 1,500,000 - 2,000,000
Lead Engineer, Information Security
Lead Engineer, Information Security

Majesco • India

Remote
INR 1,200,000 - 1,800,000
Senior Analyst Detection Engineering, Information Security
Senior Analyst Detection Engineering, Information Security

Edwards Lifesciences • Pune District

On-site
INR 1,200,000 - 1,600,000
Threat Monitoring Security Engineer
Threat Monitoring Security Engineer

HireFlex • India

On-site
INR 1,200,000 - 2,000,000