Lead Engineer, Information Security

Majesco

Mumbai

On-site

INR 1,800,000 - 2,400,000

Full time

9 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Majesco is seeking a Lead Engineer, Information Security in Mumbai to enhance security monitoring, detection, and incident response. The role blends hands-on security operations with optimization of SIEM rules and telemetry coverage across cloud and on-premises environments.

The ideal candidate will own investigations, validate log sources, and drive improvements in detection accuracy while collaborating with Security, Infrastructure, and Cloud teams.

Qualifications

  • Bachelor's degree in information security, cybersecurity, computer science, information technology, or related field.
  • 4+ years in security operations, monitoring, incident detection and response, or vulnerability management.
  • Hands-on experience investigating alerts and developing or tuning detection and correlation rules.
  • Experience with SIEM platforms and validating logs for effective detection.

Responsibilities

  • Investigate, triage, document and respond to security alerts and events promptly.
  • Develop, test, tune and maintain SIEM correlation and detection rules.
  • Identify monitoring gaps and tune logs/telemetry to maintain coverage without compromising relevance.
  • Support vulnerability management activities, dashboards, and trend reporting.
  • Collaborate across Security, Infrastructure and Cloud teams to improve monitoring.

Skills

SIEM operations
Incident response
Security monitoring
Vulnerability management
Cloud security
EDR experience
Communication
Scripting (PowerShell/Python)

Education

Bachelor's in Information Security/ Cybersecurity/ CS/ IT

Tools

Exabeam
CrowdStrike
Wiz
Sumo Logic

Job description

Majesco is looking for a Lead Engineer, Information Security to support and continuously improve our security monitoring, detection, vulnerability management, and incident response capabilities.

This role will be a senior technical contributor within the Information Security team, responsible for investigating security events, improving SIEM detection logic, validating security log coverage, reducing unnecessary false positives, and helping ensure that security monitoring provides meaningful and actionable detection across the environment.

The successful candidate should be comfortable both performing day-to-day security operations and identifying opportunities to make those operations more effective. This is a hands-on role that requires strong analytical skills, technical ownership, and the ability to work collaboratively across Security, Infrastructure, Cloud, and other technology teams.

KeyResponsibilities:
  • Investigate,triage,document,andrespondtosecurityalertsandeventsinatimelymanner.
  • Develop,test,tune,andmaintainSIEMcorrelationanddetectionrules.
  • Analyzerecurringalertsandfalsepositivesandimplementappropriatetuning,exceptions,ordetectionimprovementswithout reducingmeaningfulsecuritycoverage.
  • IdentifygapsinsecuritymonitoringandhelpensurerelevantsecuritylogsandtelemetryareproperlyingestedintotheSIEM.
  • Validatethatlogsourcesprovidetheeventsanddatanecessarytosupporteffectivedetectionandinvestigation.
  • Supporttheintegrationofnewsystems,applications,cloudplatforms,andsecuritytechnologiesintothesecuritymonitoring environment.
  • WorkwithtechnologiessuchasExabeam,CrowdStrike,Wiz,andothersecuritymonitoringandcloudsecurityplatforms.
  • Supportvulnerabilitymanagementactivities,includinganalysis,dashboards,reporting,andidentificationofmeaningfulsecurity trends.
  • Developandimprovesecuritydashboardsandreportingtoreducemanualeffortandprovideusefulinformationtotechnical teamsandleadership.
  • Assistwithsecurityincidentinvestigations,includingcollectionandanalysisofrelevantlogsandsecuritytelemetry.
  • Participateinthedevelopmentandexecutionofincidentresponsetabletopexercisesandothersecuritypreparednessactivities.
  • WorkcollaborativelywithothermembersoftheSecurityOperationsteam,sharingtechnicalknowledgeandhelpingimprove teamprocessesandcapabilities.
  • Identifyopportunitiestoimprovesecurityoperationsandtakeownershipofimprovementsfrominitialproblemidentification throughimplementationandvalidation.
  • Maintainappropriatedocumentationfordetectionlogic,monitoringcoverage,investigations,andoperationalprocedures.
RequiredQualifications:
  • Bachelor'sdegreeinInformationSecurity,Cybersecurity,ComputerScience,InformationTechnology,orarelatedfield.
  • 4+yearsofhands-onexperienceinsecurityoperations,securitymonitoring,incidentdetectionandresponse,vulnerability management,orarelatedinformationsecuritydiscipline.
  • Stronghands-onexperienceinsecurityoperations,securitymonitoring,orincidentdetectionandresponse.
  • ExperienceworkingwithSIEMplatforms,includinginvestigatingalertsanddevelopingortuningdetectionandcorrelationrules.
  • UnderstandingofWindows,endpoint,network,application,cloud,andsecuritylogsources.
  • Abilitytoanalyzesecurityeventsanddistinguishlegitimateactivity,falsepositives,andpotentiallymaliciousbehavior.
  • Experiencewithendpointdetectionandresponse(EDR)technologiessuchasCrowdStrikeorequivalentplatforms.
  • Understandingofvulnerabilitymanagementandexperienceworkingwithvulnerabilitymanagementorcloudsecurityplatforms.
  • Workingknowledgeofcommonsecurityconcepts,includingthreatdetection,incidentresponse,identityandaccess management,networksecurity,endpointsecurity,andcloudsecurity.
  • Abilitytoindependentlyinvestigatetechnicalissuesanddrivethemthroughresolution.
  • Strongwrittenandverbalcommunicationskills,includingtheabilitytoexplaintechnicalsecurityissuesclearlytobothtechnical andnon-technicalaudiences.
  • Abilitytoworkeffectivelyacrosstechnicalteamsandcollaboratewithinfrastructure,application,cloud,andsecuritypersonnel.
PreferredQualifications:
  • ExperiencewithExabeamoranotherenterpriseSIEMorsecurityanalyticsplatform.
  • ExperiencewithWizorcomparablecloudsecurityandvulnerabilitymanagementtechnologies.
  • Experiencedevelopingdetectionlogicusingmultiplesecuritydatasources.
  • Experienceonboarding,validating,andmaintainingSIEMlogsources.
  • FamiliaritywithSumoLogicorsimilarlogmanagementplatforms.
  • Experienceparticipatinginsecurityincidentresponseinvestigationsandtabletopexercises.
  • Experiencecreatingsecuritydashboards,metrics,andautomatedreporting.
  • ScriptingorautomationexperienceusingPowerShell,Python,APIs,orsimilartechnologies.
  • FamiliaritywithcybersecurityframeworksandpracticessuchasNISTCSF,NISTIncidentResponseGuidance,MITREATT&CK,CISControls,orISO27001.
  • RelevantindustrycertificationssuchasCISSP,Security+,CISM,GIAC,GCIH,GCIA,orequivalentcertificationsare preferred.
WhatSuccessLooksLike

A successful Lead Engineer will not simply process alerts. They will continuously improve the effectiveness of security operations by enhancing detection accuracy, identifying monitoring gaps, reducing avoidable false positives, strengthening log coverage, improving vulnerability visibility, and taking ownership of technical security improvements.

They will demonstrate measurable improvements to the security program through stronger detection coverage, more effective correlation rules, improved visibility into security risks, reduced manual effort through automation, enhanced reporting and metrics, and increased incident response readiness.

They are viewed as a trusted technical resource who proactively identifies problems, drives solutions, and helps elevate the overall maturity of Majesco's security operations capabilities.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Engineer, Information Security
Lead Engineer, Information Security

Majesco • India

Remote
INR 1,200,000 - 1,800,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Neurealm • Chennai District

On-site
INR 2,800,000 - 6,000,000
Lead Engineer, Information Security
Lead Engineer, Information Security

Lever, Inc. • India

Remote
INR 1,500,000 - 2,200,000
Fully remote within India
Senior technical ownership
Exposure to enterprise SIEM/EDR/cloud
+3
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Lead Cybersecurity Engineer
Lead Cybersecurity Engineer

Providence Health & Services • Hyderabad

On-site
INR 3,500,000 - 4,500,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software GmbH • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Lead Security Engineer
Lead Security Engineer

mpc • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

Datacore • Bengaluru

On-site
INR 900,000 - 1,500,000