Security Engineer – AWS Security Incident Response, Cloud Security, AI Security, EDR & SIEM

Alcon MX

Bengaluru

On-site

INR 1,200,000 - 2,200,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Alcon seeks an intermediate-level Security Engineer to support Cyber Incident Response and Threat Management across AWS cloud security, SIEM monitoring, and EDR/XDR operations. You will investigate alerts, triage incidents, coordinate with SOC partners, and help mature playbooks and runbooks while aligning with MITRE ATT&CK techniques.

The role focuses on cloud, identity, and endpoint protection, with emphasis on practical threat detection improvements, governance, and knowledge sharing within a

Qualifications

  • 5–7 years of experience in SOC operations, incident response, cloud security, SIEM engineering, EDR/XDR operations, or a related cybersecurity role.
  • Hands-on experience with AWS security concepts including IAM, logging, monitoring, network security, encryption, and incident investigation.
  • Working knowledge of AWS security services such as GuardDuty, Security Hub, CloudTrail, Config, Inspector, IAM, and CloudWatch.
  • Experience with SIEM tools, preferably Microsoft Sentinel, including alert investigation, KQL/log analysis, rule tuning, and dashboard/reporting support.
  • Experience with EDR/XDR platforms, preferably Microsoft Defender XDR, including endpoint investigation, containment, and remediation coordination.
  • Support secure adoption of AI capabilities by identifying security risks, monitoring misuse scenarios, and helping define security guardrails.
  • Good understanding of incident response lifecycle, threat hunting, common attack techniques, and MITRE ATT&CK.
  • Basic scripting or query skills using KQL, PowerShell, Python, or similar technologies.
  • Good written communication skills with the ability to document incidents, actions taken, findings, and recommendations clearly.

Responsibilities

  • Monitor, investigate, and respond to security alerts across cloud, endpoint, identity, email, SaaS, and enterprise environments.
  • Take ownership of incidents from triage through containment, remediation support, documentation, and lessons learned.
  • Work with internal teams and external SOC partners to ensure incidents are handled consistently and within defined operational expectations.
  • Contribute to detection improvements, playbook maturity, operational documentation, and knowledge sharing across the SOC team.
  • Develop dashboards, basic reporting, and operational metrics to improve visibility for SOC and leadership stakeholders.

Skills

SOC operations
Incident response
AWS security concepts
SIEM engineering
EDR/XDR operations
Scripting (KQL/PowerShell/Python)
MITRE ATT&CK knowledge
Documentation skills

Tools

AWS GuardDuty
AWS Security Hub
AWS CloudTrail
AWS Config
IAM
CloudWatch
Microsoft Sentinel
Microsoft Defender XDR

Job description

Summary of Position: Responsible for planning, managing, and implementing cybersecurity and IT compliance to ensure effective enterprise protection and innovation in the organization. We are looking for an intermediate-level Security Engineer who can support Alcon’s Cyber Incident Response and Threat Management function across AWS cloud security, SIEM monitoring, EDR/XDR operations, cloud incident response, and emerging AI security risks. This person should be hands‑on, practical, and comfortable working with SOC, Cloud, Infrastructure, Identity, and application teams to improve threat detection, response, and security posture.

Role Expectations

Monitor, investigate, and respond to security alerts across cloud, endpoint, identity, email, SaaS, and enterprise environments. Take ownership of assigned incidents from triage through containment, remediation support, documentation, and lessons learned. Work with internal teams and external SOC partners to ensure incidents are handled consistently and within defined operational expectations. Contribute to detection improvements, playbook maturity, operational documentation, and knowledge sharing across the SOC team.

Key Responsibilities
  1. AWS Security Incident Response & Cloud Security: Investigate AWS security alerts, suspicious activity, misconfigurations, and potential compromise scenarios using available cloud logs and security tooling. Review AWS security findings from services such as GuardDuty, Security Hub, CloudTrail, Config, IAM, CloudWatch, Inspector, and related monitoring sources. Support containment and remediation activities for cloud security incidents in coordination with Cloud Engineering and application owners. Identify gaps in cloud logging, monitoring, alerting, access control, and security posture, and recommend practical improvements. Assist in building and maintaining cloud incident response runbooks, investigation steps, and escalation procedures. Enhance incident detection and response capabilities for Cloud platforms.
  2. SIEM Monitoring & Detection Engineering: Work on Microsoft Sentinel and other SIEM-related monitoring activities to detect, investigate, and correlate threats across multiple data sources. Create, review, and tune SIEM use cases to improve alert quality and reduce false positives. Support onboarding and validation of important log sources including cloud, identity, endpoint, email, firewall, SaaS, and application logs. Develop dashboards, basic reporting, and operational metrics to improve visibility for SOC and leadership stakeholders. Map detections and investigation logic to common attacker behaviors using MITRE ATT&CK where applicable.
  3. EDR / XDR Operations: Investigate EDR/XDR alerts from platforms such as Microsoft Defender XDR and other endpoint security tools. Perform endpoint triage, device isolation support, IOC validation, malware investigation, and remediation coordination. Identify endpoints missing security coverage and work with responsible teams to support remediation and visibility improvement. Support policy tuning, alert validation, and operational improvements to strengthen endpoint detection and response. Coordinate with Infrastructure, Desktop Engineering, and Vulnerability Management teams where endpoint issues require ownership outside SOC.
  4. AI Security & Secure AI Operations: Support security monitoring and investigation of AI‑related risks such as unauthorized AI usage, data leakage, prompt injection, model misuse, risky plugins/connectors, and AI‑assisted phishing or social engineering. Assist in defining practical AI security guardrails for SOC usage, including access control, logging, acceptable use, data handling, and escalation criteria. Contribute to AI security incident response workflows and help document how AI‑related security events should be triaged and escalated. Support secure use of Microsoft Security Copilot and other AI‑enabled security tools by helping validate use cases, risks, controls, and operational logging needs. Stay current on AI threat trends and translate them into practical SOC monitoring and response actions.
  5. Incident Response, Threat Hunting & Continuous Improvement: Perform structured incident analysis including scope identification, timeline review, evidence collection, containment recommendations, and post‑incident documentation. Participate in threat hunting and proactive detection improvement activities across cloud, endpoint, identity, and SIEM data. Create and maintain SOC knowledge articles, incident handling guides, detection notes, and runbooks. Support internal and external audit requests by providing clear operational evidence where applicable. Identify automation opportunities using SOAR, scripting, KQL, PowerShell, Python, or cloud‑native capabilities to reduce repetitive manual effort.
Key Requirements/Minimum Qualifications
  • 5–7 years of experience in SOC operations, incident response, cloud security, SIEM engineering, EDR/XDR operations, or a related cybersecurity role.
  • Hands‑on experience with AWS security concepts including IAM, logging, monitoring, network security, encryption, and incident investigation.
  • Working knowledge of AWS security services such as GuardDuty, Security Hub, CloudTrail, Config, Inspector, IAM, and CloudWatch.
  • Experience with SIEM tools, preferably Microsoft Sentinel, including alert investigation, KQL/log analysis, rule tuning, and dashboard/reporting support.
  • Experience with EDR/XDR platforms, preferably Microsoft Defender XDR, including endpoint investigation, containment, and remediation coordination.
  • Support secure adoption of AI capabilities by identifying security risks, monitoring misuse scenarios, and helping define security guardrails.
  • Good understanding of incident response lifecycle, threat hunting, common attack techniques, and MITRE ATT&CK.
  • Basic scripting or query skills using KQL, PowerShell, Python, or similar technologies.
  • Good written communication skills with the ability to document incidents, actions taken, findings, and recommendations clearly.
Preferred Qualifications
  • AWS Certified Security – Specialty, AWS Solutions Architect Associate, or equivalent cloud security certification.
  • Microsoft SC-200, SC-100, AZ-500, GCIH, GCIA, or similar security certifications.
  • Experience working in a global SOC or managed security operations model.
  • Exposure to Microsoft Security Copilot, SOAR platforms, threat intelligence platforms, or automation workflows.
  • Experience in regulated environments such as healthcare, life sciences, or global enterprise operations.

Work hours: 4 PM to 1 AM IST

Relocation assistance: Yes

Alcon develops and manufactures innovative devices to serve the full life cycle of eye care needs. Its surgical group is one of the largest makers of equipment used for cataract removal and laser vision correction. Its consumer products include the well‑known Opti‑Free line of contact lens solutions and related products. Alcon, which was founded in 1945, sells its products in 180 countries worldwide.

Alcon is an Equal Opportunity Employer and takes pride in maintaining a diverse environment.

We do not discriminate in recruitment, hiring, training, promotion or other employment practices for reasons of race, color, religion, gender, national origin, age, sexual orientation, gender identity, marital status, disability, or any other reason.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Associate I, Software Engineering (Systems Analyst)
Sr. Associate I, Software Engineering (Systems Analyst)

Alcon MX • Bengaluru

On-site
INR 1,200,000 - 2,200,000
Relocation assistance
Principal I, Software Engineering
Principal I, Software Engineering

Alcon MX • Bengaluru

On-site
INR 2,000,000 - 3,200,000
Relocation assistance
Alcon Hiring Associate Software Engineer Fresher
Alcon Hiring Associate Software Engineer Fresher

Alcon • Bengaluru

On-site
INR 600,000 - 800,000
Principal I, Product Development, Security & Operations (DevSecOps)
Principal I, Product Development, Security & Operations (DevSecOps)

Alcon MX • Bengaluru

On-site
INR 1,600,000 - 2,800,000
Relocation assistance
Principal, Platform Architect - Teamcenter
Principal, Platform Architect - Teamcenter

alcon • Bengaluru

On-site
INR 4,200,000 - 7,000,000
Health insurance
Life insurance
Retirement plan
+1
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Sr. Associate II, General Engineering
Sr. Associate II, General Engineering

Alcon MX • Bengaluru

On-site
INR 1,200,000 - 1,800,000
Relocation assistance
Health insurance
Sr. Associate, Human Resources - India
Sr. Associate, Human Resources - India

Alcon MX • Bengaluru

On-site
INR 800,000 - 1,200,000
Security Operations Analyst
Security Operations Analyst

BetterCloud • India

On-site
INR 800,000 - 1,200,000
Sr. Associate I, Software Engineering
Sr. Associate I, Software Engineering

Alcon MX • Bengaluru

On-site
INR 1,200,000 - 2,000,000
Relocation assistance