TECHNICAL LEAD - Cybersecurity

Happiest Minds Technologies

Bengaluru

On-site

INR 1,200,000 - 1,800,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

PropertyGuru is seeking a Cyber Defence Analyst to monitor, detect, and respond to threats across cloud, endpoint, and network environments. You will leverage SentinelOne Singularity XDR and cloud-native tools to drive incident response and continuous security improvements.

The role operates as Tier-2/3, investigating complex alerts, owning incidents, and collaborating with SOC, engineering, and IT teams to ensure rapid containment and resilience against evolving threats.

Qualifications

  • Bachelor’s or Master’s degree in cybersecurity, information technology, computer science, or a related discipline.
  • 3–5+ years of experience in Security Operations, Incident Response, or Cloud Security with exposure to AWS and GCP.
  • Hands-on experience with SentinelOne Singularity platform (EDR, XDR, AI SIEM, CNAPP, ITDR).
  • Proven track record investigating incidents across multiple domains (cloud, endpoint, network).
  • Scripting/automation knowledge (Python, Bash) for investigation and detection enrichment.

Responsibilities

  • Monitor logs and telemetry from cloud-native sources (CloudTrail, GCP Audit), endpoint EDR/EPP, and network security tools.
  • Develop, tune, and manage detection rules and use cases in SIEM/SOAR/XDR platforms.
  • Identify and investigate anomalies, TTPs, and attack vectors across cloud, endpoint and network layers.
  • Monitor cloud workload runtime threats, container activity, and misconfigurations using CNAPP signals.
  • Leverage SentinelOne AI detections and cross-domain correlations for early threat identification.
  • Coordinate incident response with SOC, IT, DevOps, and engineering teams to ensure containment and recovery.

Skills

Threat detection
Incident response
Threat hunting
Scripting (Python/Bash)
Security analytics
Documentation

Education

Bachelor’s/Master’s in cybersecurity or related

Tools

SentinelOne Singularity
AWS
GCP
SIEM/SOAR/XDR

Job description

Cyber Defence Analyst

At PropertyGuru, we strive to ?Build Southeast Asia?s Trust Platform? and security is at the centre of building that trust with our customers, agents, and partners across Singapore, Vietnam, Malaysia, Thailand & India.

Role
  • The Cyber Defence Analyst monitors, detects, and responds to security threats across cloud (AWS & GCP), endpoint, and network environments. Leveraging the SentinelOne Singularity XDR platform (EDR, XDR, CNAPP, ITDR, and AI SIEM), cloud-native tools, and modern security technologies, the analyst plays a key role in threat detection, incident response, and continuous improvement of PropertyGuru?s security posture.
  • Operating as a Tier-2 / Tier-3 Cyber Defence Analyst, they are expected to independently investigate complex alerts and incidents, drive incidents end-to-end with minimal supervision, contribute to detection engineering, and support the continuous maturity of the SOC while collaborating closely with SOC, engineering, and infrastructure teams to ensure rapid response and resilience against evolving threats.
Responsibilities
1. Threat Monitoring & Detection (Cloud, Endpoint & Network)
  • Monitor logs and telemetry from cloud-native sources (CloudTrail, GCP Audit), endpoint EDR/EPP solutions, and network security tools (NDR, firewalls, IDS/IPS).
  • Develop, tune, and manage detection rules and use cases in SIEM/SOAR/XDR platforms.
  • Identify and investigate anomalies, TTPs, and attack vectors spanning cloud, endpoint, and network layers.
  • Monitor and investigate identity-based threats (suspicious logins, privilege escalation, service account abuse) using SentinelOne ITDR capabilities.
  • Monitor cloud workload runtime threats, container activity, and misconfigurations using SentinelOne CNAPP signals.
  • Leverage SentinelOne behavioral AI detections and cross-domain correlations for early threat identification.
2. Incident Response
  • Investigate and triage alerts across cloud, endpoint, and network environments collect logs, perform forensic analysis, and document findings.
  • Execute playbooks for a variety of scenarios: cloud key compromise, endpoint malware/ransomware, phishing, insider misuse, and lateral movement on networks.
  • Work with SOC, IT, DevOps, and engineering teams for containment, remediation, and recovery.
  • Act as primary incident owner for assigned incidents, driving investigation to closure within defined SLAs.
  • Execute SentinelOne response actions such as endpoint isolation, kill/rollback, identity containment, and cloud workload response.
  • Perform XDR-level incident correlation across endpoint, cloud, identity, and network telemetry to determine blast radius.
3. Threat Hunting
  • Conduct proactive hunts across multi-environment telemetry to uncover hidden threats or suspicious behavior.
  • Identify patterns such as credential abuse, anomalous lateral movement, and data exfiltration across hybrid infrastructure.
  • Build advanced dashboards and detection mechanisms across cloud, endpoint, and network.
  • Perform hypothesis-driven threat hunts using SentinelOne XDR across endpoint, identity, and cloud datasets.
  • Map hunt findings to MITRE ATT&CK (Enterprise & Cloud) and feed learnings back into detection engineering.
4. Security Analytics & Reporting
  • Produce actionable incident reports and threat summaries for stakeholders.
  • Correlate threat activity across domains (cloud, endpoint, network) to build holistic risk views.
  • Share insights into emerging attack trends and propose security control improvements.
  • Build and maintain SentinelOne dashboards for threat trends, attack paths, and detection coverage.
  • Provide executive-ready summaries highlighting risk, impact, and recommended remediation.
5. Collaboration, Tuning & Knowledge Sharing
  • Provide SME input on log integration, audit coverage, and SOC process improvements.
  • Mentor team members on detection, triage, and investigation best practices.
  • Maintain updated playbooks, runbooks, and investigation procedures.
  • Tune and optimize SentinelOne detection rules, AI alerts, and correlation logic to reduce noise and improve fidelity.
  • Collaborate with security engineering to onboard new log sources into SentinelOne SIEM/XDR.
6. Continuous Improvement
  • Stay current on adversary techniques across cloud, endpoint, and network.
  • Work with platform/infra/security engineering teams to close detection gaps.
  • Support purple team exercises, tabletop drills, and continuous validation of detection/response capabilities.
  • Leverage scripting (Python, Shell, or similar) for automation, log parsing, enrichment, and detection engineering to enhance SOC efficiency as added advantage.
  • Design and improve SOAR workflows and automated response playbooks within SentinelOne.
  • Identify repeatable investigations and drive automation-first approaches.
Who you are Qualifications
  • Bachelor?s or Master?s degree in cybersecurity, information technology, computer science, or a related discipline.
  • 3-5+ years of experience in Security Operations, Incident Response, or Cloud Security, with significant exposure to AWS and GCP platforms.
  • Hands-on experience with SentinelOne Singularity platform, including EDR, XDR, AI SIEM, CNAPP, and ITDR capabilities.
  • Proven track record investigating incidents across multiple domains (cloud, endpoint, network).
  • Scripting/automation knowledge (Python, Bash, or similar) for investigation and detection enrichment.
  • Certifications such as GCIH, GCFR, GCIA or equivalent are preferred.
  • Experience collaborating with cross-functional teams in time-sensitive, operational contexts.
  • Strong documentation and root cause analysis skills, with an ability to translate findings into actionable playbooks or recommendations.
Knowledge
  • Strong understanding of log sources: AWS CloudTrail/CloudWatch, GCP Audit, EDR telemetry, Windows/Linux syslogs, network IDS/IPS.
  • Familiarity with MITRE ATT&CK framework (Enterprise & Cloud).
  • Strong understanding of identity attack paths and IAM abuse techniques in cloud environments.
  • Knowledge of cloud runtime threats, container escape techniques, and workload lateral movement.
  • Knowledge of cloud, endpoint, and network attack vectors and associated defense techniques.
  • Awareness of compliance frameworks (SOC 2, ISO 27001, PCI DSS) relevant to multi-environment infrastructure.
  • Ability to apply threat intelligence for improving detection and hunting strategies.
Essential Personal Skills
  • Highly collaborative works seamlessly within a SOC and across cloud, engineering, and incident response teams.
  • Calm and decisive under pressure, able to manage multiple ongoing investigations and incidents simultaneously.
  • Proactive mindset, with a strong drive for continuous learning and keeping skills sharp in the evolving cloud security landscape.
  • Exceptional attention to detail and a methodical approach to investigation and documentation.
  • Integrity, sound judgment, and a commitment to protecting sensitive information and maintaining confidentiality.
  • Strong communication skills able to clearly document findings, communicate incident status, and share knowledge with both technical and non-technical audiences.
  • Resourceful and self-motivated, able to adapt quickly to shifting priorities.
  • Willingness to mentor team members and share best practices for effective cloud incident handling.
  • Demonstrates curiosity and an investigative mindset able to dig deep and identify root causes rather than symptoms.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

TECHNICAL LEAD - CLOUD SECURITY TECHNOLOGIES
TECHNICAL LEAD - CLOUD SECURITY TECHNOLOGIES

Happiest Minds Technologies • Bengaluru

On-site
INR 1,800,000 - 3,600,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Dun & Bradstreet • Hyderabad

Hybrid
INR 2,500,000 - 4,500,000
Cyber Security Analyst
Cyber Security Analyst

Dun & Bradstreet • Hyderabad

On-site
INR 3,000,000 - 5,000,000
Soc Analyst
Soc Analyst

BUSINESSNEXT • Dadri

On-site
INR 1,200,000 - 2,000,000
Sr. SOC Analyst
Sr. SOC Analyst

Ferfier Technologies • Dadri

Hybrid
INR 1,500,000 - 2,100,000
Flexible/Remote work
Sr. SOC Engineer (L3)
Sr. SOC Engineer (L3)

Larsen & Toubro • Chennai District

On-site
INR 2,500,000 - 4,000,000
Senior Cyber Security Analyst (R-19638)
Senior Cyber Security Analyst (R-19638)

Eyeota • Hyderabad

On-site
INR 1,100,000 - 2,400,000
Security Operations Engineer
Security Operations Engineer

NextGenEnergyJobs • Bengaluru

On-site
INR 2,500,000 - 5,200,000
Flexible time off
Wellness resources
Team events
Associate SOC
Associate SOC

Publicis Groupe • Gurgaon

On-site
INR 1,200,000 - 2,400,000
Associate SOC
Associate SOC

Publicis Groupe Holdings B.V • Gurugram District

On-site
INR 1,200,000 - 1,800,000