Sr SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies

Dadri

On-site

INR 800,000 - 1,500,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Happiest Minds Technologies is seeking an experienced Senior SOC Lead to drive incident response, detection engineering, and threat hunts across endpoints, identities, and cloud environments.

You will define and evolve playbooks, oversee Tier 2 SOC operations, and mentor junior analysts while coordinating with global security teams to reduce risk and improve detection coverage.

Qualifications

  • Bachelor's degree in Information Systems, Cybersecurity or related field.
  • 8+ years in security operations or incident response.
  • Hands-on expertise with SIEM and EDR; knowledge of MITRE ATT&CK.
  • Experience leading complex incidents end to end and mentoring analysts.

Responsibilities

  • Act as incident lead for high-severity security incidents end to end.
  • Lead multi-stage investigations across endpoint, identity, network, cloud and SaaS telemetry.
  • Develop detection strategies aligned to MITRE ATT&CK.
  • Lead Tier 2 SOC operations and ensure SLAs.
  • Create and maintain SOC playbooks and runbooks.
  • Mentor Tier 1/2 analysts.
  • Translate findings into risk-based recommendations.

Skills

Incident response
Detection engineering
Team leadership
Automation scripting
Mentoring teammates
Threat hunting

Education

Bachelor's in Information Systems / Cybersecurity

Tools

SIEM platforms
EDR tooling
SOAR platforms
KQL / SPL
PowerShell

Job description

Primary Responsibilities

Act as incident lead for investigating and handling high-severity and complex security incidents end to end: direct scoping, containment, eradication and recovery, coordinate technical and business stakeholders, and own the root-cause analysis also provide details for post-incident review.
Lead complex, multi-stage investigations across endpoint, identity, network, cloud and SaaS telemetry, including advanced malware analysis, credential-compromise and lateral-movement investigations, and adversary tradecraft reconstruction.
Works on detection engineering lifecycle: define detection strategy aligned to MITRE ATT&CK and the organisations threat model, identify and recommend new detection logic across SIEM, XDR, EDR and SOAR, and measure coverage, precision and time-to-detect.
Works on hypothesis-driven threat hunts based on threat intelligence, emerging TTPs and gaps in detection coverage; convert findings into new detections, playbooks and control recommendations.
Lead Tier 2 SOC operations, including shift priorities, case load and escalation flow, ensuring SLAs and quality standards are consistently met.
Create and maintain SOC playbook, runbook and knowledge-based library: define structure and standards, author content for complex scenarios, and ensure content stays current with tooling and threat changes.
Identify, design and recommend process improvements across the SOC, measuring and reporting their impact.
Contribute to and help implement the multi-year security operations strategy, including detection coverage roadmap, telemetry strategy, automation targets and capability maturity.
Translate security findings into risk-based recommendations for security engineering, IT and business stakeholders, and influence control and architecture decisions across teams.
Mentor and develop Tier 1 and Tier 2 analysts through structured coaching, investigation walkthroughs and technical training; contribute to hiring and capability planning.
Participate the SOC in cross-functional forums and with global security teams to ensure a cohesive, consistent approach to security operations.
Provide seniors on-call escalation coverage for major incidents.

About You

8+ years in security operations, incident response, detection engineering or an equivalent blue-team role, including several years leading complex incidents end to end and acting as a technical escalation point for other analysts.
Bachelors degree in Information Systems, Cybersecurity or a related field, or equivalent experience.
Advanced certifications such as GCIA, GCIH, GCFA, GCDA, GNFA, GREM, OSCP, Microsoft SC-200 or equivalent are highly regarded.
Deep, hands‑on expertise with SIEM (advanced KQL, SPL or equivalent, including detection authoring and performance tuning) and EDR platforms (live response, forensic artefact collection, process‑tree and memory analysis); experience with SOAR design and automation.
Expert knowledge of Windows, Linux, Active Directory and Entra ID attack techniques and the telemetry needed to detect them; able to reconstruct an intrusion from raw logs without a playbook.
Strong experience in cloud security monitoring and response across at least one major provider (AWS, Azure or GCP), including identity, control‑plane and workload telemetry.
Proficiency in Python or PowerShell for automation, data analysis and tooling integration.
Deep working knowledge of MITRE ATT&CK, the incident response lifecycle, malware analysis and phishing investigation, and experience mapping detection coverage against adversary TTPs.
Track record of defining standards, processes and playbooks that others operate against, and of improving them based on evidence.
Demonstrated ability to mentor analysts and raise the technical bar of a team.
Sound, independent judgement under pressure; comfortable making and owning decisions during live incidents with incomplete information.
Clear, structured technical writing, including incident reports, RCAs and briefings for senior technical and non-technical audiences.
Strong influencing and collaboration skills; able to partner with engineering, IT and business teams locally and globally to drive change without direct authority.

Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

SENIOR SUPPORT ENGINEER - Cyber Security
SENIOR SUPPORT ENGINEER - Cyber Security

Happiest Minds Technologies • Dadri

On-site
INR 2,400,000 - 4,200,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

On-site
INR 1,500,000 - 2,100,000
Flexible/Remote work
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software GmbH • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Senior Incident Response Analyst
Senior Incident Response Analyst

Nopal Cyber, LLC. • Hyderabad

On-site
INR 1,500,000 - 2,800,000
Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Metmox • Hyderabad

On-site
INR 2,400,000 - 3,800,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software • Bengaluru

On-site
INR 4,000,000 - 6,400,000