Majesco is looking for a Lead Engineer, Information Security to support and continuously improve our security monitoring, detection, vulnerability management, and incident response capabilities.
This role will be a senior technical contributor within the Information Security team, responsible for investigating security events, improving SIEM detection logic, validating security log coverage, reducing unnecessary false positives, and helping ensure that security monitoring provides meaningful and actionable detection across the environment.
The successful candidate should be comfortable both performing day-to-day security operations and identifying opportunities to make those operations more effective. This is a hands-on role that requires strong analytical skills, technical ownership, and the ability to work collaboratively across Security, Infrastructure, Cloud, and other technology teams.
KeyResponsibilities:
- Investigate,triage,document,andrespondtosecurityalertsandeventsinatimelymanner.
- Develop,test,tune,andmaintainSIEMcorrelationanddetectionrules.
- Analyzerecurringalertsandfalsepositivesandimplementappropriatetuning,exceptions,ordetectionimprovementswithout reducingmeaningfulsecuritycoverage.
- IdentifygapsinsecuritymonitoringandhelpensurerelevantsecuritylogsandtelemetryareproperlyingestedintotheSIEM.
- Validatethatlogsourcesprovidetheeventsanddatanecessarytosupporteffectivedetectionandinvestigation.
- Supporttheintegrationofnewsystems,applications,cloudplatforms,andsecuritytechnologiesintothesecuritymonitoring environment.
- WorkwithtechnologiessuchasExabeam,CrowdStrike,Wiz,andothersecuritymonitoringandcloudsecurityplatforms.
- Supportvulnerabilitymanagementactivities,includinganalysis,dashboards,reporting,andidentificationofmeaningfulsecurity trends.
- Developandimprovesecuritydashboardsandreportingtoreducemanualeffortandprovideusefulinformationtotechnical teamsandleadership.
- Assistwithsecurityincidentinvestigations,includingcollectionandanalysisofrelevantlogsandsecuritytelemetry.
- Participateinthedevelopmentandexecutionofincidentresponsetabletopexercisesandothersecuritypreparednessactivities.
- WorkcollaborativelywithothermembersoftheSecurityOperationsteam,sharingtechnicalknowledgeandhelpingimprove teamprocessesandcapabilities.
- Identifyopportunitiestoimprovesecurityoperationsandtakeownershipofimprovementsfrominitialproblemidentification throughimplementationandvalidation.
- Maintainappropriatedocumentationfordetectionlogic,monitoringcoverage,investigations,andoperationalprocedures.
RequiredQualifications:
- Bachelor'sdegreeinInformationSecurity,Cybersecurity,ComputerScience,InformationTechnology,orarelatedfield.
- 4+yearsofhands-onexperienceinsecurityoperations,securitymonitoring,incidentdetectionandresponse,vulnerability management,orarelatedinformationsecuritydiscipline.
- Stronghands-onexperienceinsecurityoperations,securitymonitoring,orincidentdetectionandresponse.
- ExperienceworkingwithSIEMplatforms,includinginvestigatingalertsanddevelopingortuningdetectionandcorrelationrules.
- UnderstandingofWindows,endpoint,network,application,cloud,andsecuritylogsources.
- Abilitytoanalyzesecurityeventsanddistinguishlegitimateactivity,falsepositives,andpotentiallymaliciousbehavior.
- Experiencewithendpointdetectionandresponse(EDR)technologiessuchasCrowdStrikeorequivalentplatforms.
- Understandingofvulnerabilitymanagementandexperienceworkingwithvulnerabilitymanagementorcloudsecurityplatforms.
- Workingknowledgeofcommonsecurityconcepts,includingthreatdetection,incidentresponse,identityandaccess management,networksecurity,endpointsecurity,andcloudsecurity.
- Abilitytoindependentlyinvestigatetechnicalissuesanddrivethemthroughresolution.
- Strongwrittenandverbalcommunicationskills,includingtheabilitytoexplaintechnicalsecurityissuesclearlytobothtechnical andnon-technicalaudiences.
- Abilitytoworkeffectivelyacrosstechnicalteamsandcollaboratewithinfrastructure,application,cloud,andsecuritypersonnel.
PreferredQualifications:
- ExperiencewithExabeamoranotherenterpriseSIEMorsecurityanalyticsplatform.
- ExperiencewithWizorcomparablecloudsecurityandvulnerabilitymanagementtechnologies.
- Experiencedevelopingdetectionlogicusingmultiplesecuritydatasources.
- Experienceonboarding,validating,andmaintainingSIEMlogsources.
- FamiliaritywithSumoLogicorsimilarlogmanagementplatforms.
- Experienceparticipatinginsecurityincidentresponseinvestigationsandtabletopexercises.
- Experiencecreatingsecuritydashboards,metrics,andautomatedreporting.
- ScriptingorautomationexperienceusingPowerShell,Python,APIs,orsimilartechnologies.
- FamiliaritywithcybersecurityframeworksandpracticessuchasNISTCSF,NISTIncidentResponseGuidance,MITREATT&CK,CISControls,orISO27001.
- RelevantindustrycertificationssuchasCISSP,Security+,CISM,GIAC,GCIH,GCIA,orequivalentcertificationsare preferred.
WhatSuccessLooksLike
A successful Lead Engineer will not simply process alerts. They will continuously improve the effectiveness of security operations by enhancing detection accuracy, identifying monitoring gaps, reducing avoidable false positives, strengthening log coverage, improving vulnerability visibility, and taking ownership of technical security improvements.
They will demonstrate measurable improvements to the security program through stronger detection coverage, more effective correlation rules, improved visibility into security risks, reduced manual effort through automation, enhanced reporting and metrics, and increased incident response readiness.
They are viewed as a trusted technical resource who proactively identifies problems, drives solutions, and helps elevate the overall maturity of Majesco's security operations capabilities.