Verified today
Cyber Security Engineer II
About the role
The Cyber Security Engineer II role serves as the senior resource for the threat detection ecosystem, owning the end-to-end lifecycle of security operations infrastructure. Day-to-day work includes engineering high-fidelity SIEM correlation rules, orchestrating automated SOAR response playbooks, leading hypothesis-based threat hunting, and acting as the Tier 2 escalation point for high-priority incidents. The position is based in Hyderabad, Telangana, India.
What you’ll do
- Design, build, and maintain advanced detection rules within the SIEM/XDR environment that correlate disparate data sources (Identity, Network, Cloud, and Endpoint)
- Map all detection capabilities to the MITRE ATT&CK Framework to identify visibility gaps and ensure comprehensive coverage against modern TTPs
- Conduct continuous noise reduction by fine-tuning alerting logic and suppression lists to maximize the signal-to-noise ratio for frontline analysts
- Develop and maintain automated response playbooks (SOAR) to standardize incident handling, from automated enrichment and evidence collection to one-click containment
- Manage the health and integration of the SOC tech stack, ensuring seamless data ingestion from cloud providers (AWS/Azure/GCP) and SaaS applications into central monitoring hubs
- Regularly audit log sources for telemetry health, ensuring critical security logs are ingested correctly and meet compliance retention requirements
- Lead hypothesis-based threat hunting engagements using EDR and SIEM data to find silent lateral movement or credential harvesting
- Act as the Tier 2 escalation point for high-priority security incidents, performing deep-dive forensic analysis and providing technical leadership during containment and recovery
What you’ll bring
- 3-5 years of hands-on experience in a Security Operations Center (SOC) or Security Engineering role
- Bachelor's degree in Cybersecurity, Computer Science, or a related technical field
- Deep technical proficiency with SIEM/XDR platforms such as Splunk ES, Microsoft Sentinel, Google Chronicle, or Palo Alto Cortex XDR
- Solid understanding of monitoring cloud-native environments (CloudTrail, VPC Flow Logs, GuardDuty)
- Expert-level proficiency in query languages (KQL, SPL, or Lucene)
- Expert-level proficiency in scripting languages (primarily Python or PowerShell) for automation and data manipulation
- Ability to synthesize complex, fragmented data points into a cohesive narrative of an attack
- Strong ability to document complex workflows and lead technical training sessions for junior SOC analysts
Skills
Education
Bachelor’s degree in Cybersecurity, Computer Science, or a related technical field.