SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies

Dadri

On-site

INR 2,400,000 - 4,200,000

Full time

32 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Happiest Minds Technologies is seeking an seasoned security operations professional to lead high‑severity incidents end to end. You will coordinate containment, eradication and recovery while guiding cross‑functional teams and performing root‑cause analyses.

You will drive detection engineering, threat hunting and playbook creation across SIEM/EDR/SOAR, mentor analysts and shape SOC maturity in a fast‑paced environment.

Qualifications

  • Bachelor's degree or equivalent in information security or related field.
  • Strong knowledge of MITRE ATT&CK and incident response lifecycle.
  • Experience leading complex incidents end to end and mentoring analysts.

Responsibilities

  • Act as incident lead for high severity security incidents, coordinating containment, eradication and recovery.
  • Lead multi‑stage investigations across endpoint, identity, network, cloud and SaaS telemetry.
  • Define detection strategy and measure coverage across SIEM, XDR, EDR and SOAR.
  • Conduct threat hunts and translate findings into new detections and playbooks.
  • Oversee Tier 2 SOC operations, SLAs and escalation flows.
  • Maintain SOC playbooks, runbooks and knowledge base with current threat changes.
  • Identify process improvements across SOC and contribute to strategy.
  • Mentor Tier 1/2 analysts and participate in cross‑functional security forums.
  • Provide escalation coverage for major incidents.

Skills

Incident response
Threat hunting
SIEM
EDR
SOAR
Python/PowerShell
MITRE ATT&CK
Cloud security
Leadership
Mentoring

Education

Bachelor's degree in Information Systems or Cybersecurity

Tools

SIEM platforms
EDR tools
SOAR
KQL
SPL
Windows
Linux
Entra ID
Active Directory

Job description

Primary Responsibilities
  • Act as incident lead for investigating and handling high‑severity and complex security incidents end to end: direct scoping, containment, eradication and recovery, coordinate technical and business stakeholders, and own the root‑cause analysis also provide details for post‑incident review.
  • Lead complex, multi‑stage investigations across endpoint, identity, network, cloud and SaaS telemetry, including advanced malware analysis, credential‑compromise and lateral‑movement investigations, and adversary tradecraft reconstruction.
  • Works on detection engineering lifecycle: define detection strategy aligned to MITRE ATT&CK and the organisation's threat model, identify and recommend new detection logic across SIEM, XDR, EDR and SOAR, and measure coverage, precision and time‑to‑detect.
  • Works on hypothesis‑driven threat hunts based on threat intelligence, emerging TTPs and gaps in detection coverage; convert findings into new detections, playbooks and control recommendations.
  • Lead Tier 2 SOC operations, including shift priorities, case load and escalation flow, ensuring SLAs and quality standards are consistently met.
  • Create and maintain SOC playbook, runbook and knowledge‑based library: define structure and standards, author content for complex scenarios, and ensure content stays current with tooling and threat changes.
  • Identify, design and recommend process improvements across the SOC, measuring and reporting their impact.
  • Contribute to and help implement the multi‑year security operations strategy, including detection coverage roadmap, telemetry strategy, automation targets and capability maturity.
  • Translate security findings into risk‑based recommendations for security engineering, IT and business stakeholders, and influence control and architecture decisions across teams.
  • Mentor and develop Tier 1 and Tier 2 analysts through structured coaching, investigation walkthroughs and technical training; contribute to hiring and capability planning.
  • Participate the SOC in cross‑functional forums and with global security teams to ensure a cohesive, consistent approach to security operations.
  • Provide seniors on‑call escalation coverage for major incidents.
Primary Responsibilities
  • Act as incident lead for investigating and handling high‑severity and complex security incidents end to end: direct scoping, containment, eradication and recovery, coordinate technical and business stakeholders, and own the root‑cause analysis also provide details for post‑incident review.
  • Lead complex, multi‑stage investigations across endpoint, identity, network, cloud and SaaS telemetry, including advanced malware analysis, credential‑compromise and lateral‑movement investigations, and adversary tradecraft reconstruction.
  • Works on detection engineering lifecycle: define detection strategy aligned to MITRE ATT&CK and the organisation's threat model, identify and recommend new detection logic across SIEM, XDR, EDR and SOAR, and measure coverage, precision and time‑to‑detect.
  • Works on hypothesis‑driven threat hunts based on threat intelligence, emerging TTPs and gaps in detection coverage; convert findings into new detections, playbooks and control recommendations.
  • Lead Tier 2 SOC operations, including shift priorities, case load and escalation flow, ensuring SLAs and quality standards are consistently met.
  • Create and maintain SOC playbook, runbook and knowledge‑based library: define structure and standards, author content for complex scenarios, and ensure content stays current with tooling and threat changes.
  • Identify, design and recommend process improvements across the SOC, measuring and reporting their impact.
  • Contribute to and help implement the multi‑year security operations strategy, including detection coverage roadmap, telemetry strategy, automation targets and capability maturity.
  • Translate security findings into risk‑based recommendations for security engineering, IT and business stakeholders, and influence control and architecture decisions across teams.
  • Mentor and develop Tier 1 and Tier 2 analysts through structured coaching, investigation walkthroughs and technical training; contribute to hiring and capability planning.
  • Participate the SOC in cross‑functional forums and with global security teams to ensure a cohesive, consistent approach to security operations.
  • Provide seniors on‑call escalation coverage for major incidents.
About You
  • 8+ years in security operations, incident response, detection engineering or an equivalent blue‑team role, including several years leading complex incidents end to end and acting as a technical escalation point for other analysts.
  • Bachelor's degree in Information Systems, Cybersecurity or a related field, or equivalent experience.
  • Advanced certifications such as GCIA, GCIH, GCFA, GCDA, GNFA, GREM, OSCP, Microsoft SC-200 or equivalent are highly regarded.
  • Deep, hands‑on expertise with SIEM (advanced KQL, SPL or equivalent, including detection authoring and performance tuning) and EDR platforms (live response, forensic artefact collection, process‑tree and memory analysis); experience with SOAR design and automation.
  • Expert knowledge of Windows, Linux, Active Directory and Entra ID attack techniques and the telemetry needed to detect them; able to reconstruct an intrusion from raw logs without a playbook.
  • Strong experience in cloud security monitoring and response across at least one major provider (AWS, Azure or GCP), including identity, control‑plane and workload telemetry.
  • Proficiency in Python or PowerShell for automation, data analysis and tooling integration.
  • Deep working knowledge of MITRE ATT&CK, the incident response lifecycle, malware analysis and phishing investigation, and experience mapping detection coverage against adversary TTPs.
  • Track record of defining standards, processes and playbooks that others operate against, and of improving them based on evidence.
  • Demonstrated ability to mentor analysts and raise the technical bar of a team.
  • Sound, independent judgement under pressure; comfortable making and owning decisions during live incidents with incomplete information.
  • Clear, structured technical writing, including incident reports, RCAs and briefings for senior technical and non‑technical audiences.
  • Strong influencing and collaboration skills; able to partner with engineering, IT and business teams locally and globally to drive change without direct authority.

Cyber Security, SOC 2, Threat hunting, AWS Cloud Security

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr SUPPORT ENGINEER - Cyber Security
Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 800,000 - 1,500,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software GmbH • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software • Bengaluru

On-site
INR 4,000,000 - 6,400,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Uvcyber • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

UltraViolet Cyber • Hyderabad

On-site
INR 2,800,000 - 4,200,000
SOC Principal
SOC Principal

HCLSoftware • Bengaluru

On-site
INR 4,500,000 - 7,500,000
Lead SOC Analyst
Lead SOC Analyst

Sampoorna Consultants • Bengaluru

On-site
INR 1,000,000 - 1,500,000