Lead Engineer, Information Security
Quick Summary
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Engineer, Information Security based in India.
This is a hands-on senior security role focused on strengthening security monitoring, detection, vulnerability management, and incident response capabilities. You will investigate security events, improve SIEM detection logic, and ensure critical telemetry is visible and actionable. The role combines day-to-day security operations with continuous improvement and technical ownership. You will collaborate closely with Security, Infrastructure, Cloud, Application, and other technology teams. The position offers the opportunity to work with modern SIEM, EDR, cloud security, and vulnerability management technologies. You will play a key role in reducing noise, improving detection coverage, and increasing incident response readiness. Success will be measured through stronger security visibility, automation, and measurable improvements to the overall security program.
-
Investigate, triage, document, and respond to security alerts, events, and incidents, ensuring timely and appropriate resolution.
-
Develop, test, tune, and maintain SIEM correlation and detection rules while improving detection accuracy and reducing unnecessary false positives.
-
Identify gaps in security monitoring and validate that relevant Windows, endpoint, network, application, cloud, and security logs are properly collected and usable for investigations.
-
Support the onboarding and integration of new systems, applications, cloud platforms, and security technologies into the monitoring environment.
-
Work with security technologies such as Exabeam, CrowdStrike, Wiz, and comparable security monitoring and cloud security platforms.
-
Support vulnerability management through analysis, reporting, dashboards, trend identification, and improved visibility into security risks.
-
Develop security dashboards, metrics, and automated reporting that reduce manual effort and provide actionable information to technical teams and leadership.
-
Assist with incident investigations by collecting and analyzing relevant logs, telemetry, and other security evidence.
-
Participate in incident response tabletop exercises and security preparedness activities.
-
Identify operational and technical improvement opportunities and own initiatives from problem identification through implementation and validation.
-
Collaborate with Security Operations and wider technology teams, sharing expertise and contributing to stronger processes and capabilities.
-
Maintain clear documentation covering detection logic, monitoring coverage, investigations, security procedures, and operational practices.
Requirements
~2 min read-
Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related discipline.
-
4+ years of hands-on experience in security operations, security monitoring, incident detection and response, vulnerability management, or a related information security field.
-
Strong practical experience investigating security events and working with SIEM platforms, including developing or tuning detection and correlation rules.
-
Solid understanding of security telemetry and log sources across Windows, endpoints, networks, applications, cloud environments, and security platforms.
-
Ability to distinguish legitimate activity, false positives, suspicious behavior, and potential security threats through detailed event analysis.
-
Experience with EDR technologies such as CrowdStrike or equivalent solutions.
-
Working knowledge of vulnerability management and cloud security platforms.
-
Strong understanding of threat detection, incident response, identity and access management, network security, endpoint security, and cloud security concepts.
-
Ability to independently investigate technical issues, take ownership, and drive problems through resolution.
-
Strong written and verbal communication skills, with the ability to explain technical security topics clearly to both technical and non-technical stakeholders.
-
Ability to collaborate effectively with infrastructure, application, cloud, and security teams.
-
Experience with Exabeam or another enterprise SIEM or security analytics platform is preferred.
-
Experience with Wiz or comparable cloud security and vulnerability management technologies is preferred.
-
Familiarity with Sumo Logic or similar log management platforms is advantageous.
-
Experience developing detection logic using multiple security data sources and onboarding or validating SIEM log sources is beneficial.
-
Scripting or automation experience using PowerShell, Python, APIs, or similar technologies is a plus.
-
Familiarity with NIST CSF, NIST Incident Response Guidance, MITRE ATT&CK, CIS Controls, or ISO 27001 is desirable.
-
Relevant certifications such as CISSP, Security+, CISM, GIAC, GCIH, GCIA, or equivalent are preferred.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- First seen
- October 6, 2026
- Last seen
- October 6, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 6, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.