Lead Security Engineer

Arcana

Bengaluru

Hybrid

INR 1,200,000 - 1,800,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Arcana is seeking a hands-on Senior Security Engineer to own security operations across corporate IT, cloud, and Kubernetes environments. You will drive monitoring, incident response, tooling integrations, and automation to protect our systems.

You will work with Infrastructure and Engineering teams to implement detection coverage, improve logging, and develop practical incident-response playbooks for end-to-end investigations in GCP, GKE, and on-premise components.

Qualifications

  • 5–7 years hands-on cybersecurity experience in security operations, engineering, or incident response.
  • Extensive SIEM and EDR experience including log analysis, detection development, and incident handling.
  • Experience integrating security telemetry via APIs or automation.
  • GCP and Kubernetes (GKE) security monitoring and IAM/RBAC experience.
  • Strong scripting ability (Python, shell) for automation.

Responsibilities

  • Own security monitoring, triage, investigation, and incident response across endpoints, identity, email, network, SaaS, GCP, and GKE.
  • Operate and improve SIEM, EDR, DLP, cloud security, network security, and identity security controls.
  • Integrate security tools and telemetry into the SOC to improve visibility, correlation, investigation, and response.
  • Build and tune detections, correlation rules, alerts, dashboards, and monitoring use cases based on attack scenarios.
  • Build automated workflows for alert enrichment, triage, investigation, containment, escalation, and response using APIs and scripting.
  • Investigate incidents end-to-end: scoping, evidence collection, root-cause, containment, remediation, closure.
  • Monitor GCP and GKE activity: IAM changes, service accounts, cloud audit events, Kubernetes activity, network events.
  • Identify gaps across cloud IAM, Kubernetes RBAC, workloads, containers, secrets, and logging, and improve security controls.

Skills

SIEM
EDR
Cloud security
Kubernetes
Scripting
Incident response
Threat detection
Networking basics

Tools

GCP
GKE
IAM
RBAC
DLP
REST APIs

Job description

We are looking for a hands-on Senior Security Engineer to own and improve security operations across our corporate IT, cloud, and Kubernetes environments. The role covers security monitoring and detection, incident response, security tooling and integrations, automation, and day-to-day IT security.

What You'll Do
  • Own security monitoring, triage, investigation, and incident response across endpoint, identity, email, network, SaaS, GCP, and GKE environments.
  • Operate and improve security capabilities across SIEM, EDR, DLP, cloud security, network security, and identity security.
  • Integrate security tools and telemetry into the SOC to improve visibility, correlation, investigation, and response.
  • Build and tune detections, correlation rules, alerts, dashboards, and monitoring use cases based on attack scenarios and observed activity.
  • Build automated workflows for alert enrichment, triage, investigation, containment, escalation, and response using APIs and scripting.
  • Investigate incidents end-to-end, including scoping, evidence collection, root-cause analysis, containment, remediation, and post-incident actions.
  • Monitor and investigate GCP and GKE activity, including IAM changes, service-account activity, cloud audit events, Kubernetes activity, workload behaviour, and network events.
  • Identify gaps and misconfigurations across cloud IAM, Kubernetes RBAC, workloads, containers, secrets, network controls, logging, and security configurations.
  • Manage and tune DLP controls and investigate potential data-exfiltration or policy-violation events.
  • Investigate phishing and account-compromise activity, including email headers, URLs, domains, attachments, authentication events, and indicators of compromise.
  • Support IT security across endpoints, device posture, identity and access, SaaS applications, privileged access, and security configurations.
  • Work with infrastructure and engineering teams to remediate security findings and improve logging, detection coverage, and preventive controls.
  • Maintain practical incident-response playbooks, detection documentation, and investigation procedures.
What You'll Need
  • 5-7 years of hands-on cybersecurity experience, with strong experience in security operations, security engineering, or incident response.
  • Strong hands-on experience with SIEM and EDR, including log analysis, detection development, alert tuning, investigation, and response.
  • Experience integrating security technologies and telemetry using APIs, webhooks, scripts, or automation/orchestration platforms.
  • Experience building and automating SOC and incident-response workflows rather than relying entirely on manual triage.
  • Hands-on experience securing and monitoring Google Cloud Platform (GCP).
  • Strong understanding of GCP IAM, service accounts, audit logging, VPC networking, storage, KMS, and cloud security controls.
  • Hands-on security experience with Kubernetes/GKE, including RBAC, service accounts, namespaces, secrets, network policies, workload security, container security, and audit logging.
  • Ability to investigate activity across cloud control-plane, Kubernetes, container/workload, identity, and network telemetry.
  • Good understanding of DLP and experience tuning policies and investigating data-security events.
  • Strong networking fundamentals, including DNS, HTTP/S, TCP/IP, VPNs, proxies, firewalls, and network traffic analysis.
  • Experience investigating phishing, credential compromise, endpoint threats, suspicious network activity, cloud events, and container/Kubernetes security events.
  • Understanding of common attacker behaviours and techniques, including privilege escalation, credential abuse, persistence, lateral movement, and data exfiltration.
  • Working knowledge of MITRE ATT&CK and its practical application to detection and investigation.
  • Hands-on scripting or automation experience with Python, shell scripting, or similar technologies.
  • Ability to independently take a security event from initial detection through investigation, containment, remediation, and closure.
Good to Have
  • Experience building or maturing a SOC/security operations capability in a cloud-first environment.
  • Experience with security orchestration and automated response.
  • Experience with cloud security posture management, vulnerability management, and container/workload security.
  • Experience developing custom detections using telemetry from multiple security and infrastructure sources.
  • Familiarity with Infrastructure-as-Code and CI/CD security from an operational security perspective.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Cyber Security Engineer
Sr Cyber Security Engineer

TechBrein Solutions Private Limited • Kozhikode district

On-site
INR 1,200,000 - 2,400,000
DevSecOps Engineer
DevSecOps Engineer

Sutherland Global • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software GmbH • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Senior Security Engineer
Senior Security Engineer

INDmoney • Bengaluru

On-site
INR 1,500,000 - 2,600,000
Senior Information Security Engineer
Senior Information Security Engineer

Imagine Learning • Bengaluru

On-site
INR 1,500,000 - 2,500,000
Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000
SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 2,400,000 - 4,200,000
Cyber Security Engineer
Cyber Security Engineer

Playsimple Games Private Limited • Bengaluru

On-site
INR 1,500,000 - 2,000,000
Sr. Cybersecurity Analyst
Sr. Cybersecurity Analyst

Target • Bengaluru

On-site
INR 1,800,000 - 3,000,000
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

Larsen & Toubro • Chennai District

On-site
INR 2,500,000 - 4,000,000