Talent.com
(Immediate joiners only)Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response

(Immediate joiners only)Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response

Triune Infomatics Incthiruvananthapuram, India
8 days ago
Job description

Role : Senior Cybersecurity SOC Engineer – Threat Hunting & Incident Response

Working Hours : Monday to Friday, 9 AM – 5 PM PST (U.S. Business Hours)

Reporting To : Security Operations (SecOps) Leader – USA

About the Role : We are seeking an elite Senior Cybersecurity SOC Engineer—a hands-on security expert with deep technical knowledge and proven experience in threat hunting, incident response, and SOC program maturity. This role will report directly to the SecOps Manager in India and requires someone who thrives in a collaborative environment and leads by example. If you are a true expert with Microsoft Sentinel, CrowdStrike, MDE, SOAR platforms, MITRE ATT&CK framework, APT detection, and scripting, this role offers a great opportunity to build and defend a modern SOC environment.

Please note : This is not a SOC Analyst role. Candidates must have 7-10+ years of hands-on SOC Engineer experience with deep threat hunting and incident response expertise. Must be available to work U.S. business hours (PST timezone).

Key Responsibilities :

  • Threat Hunting :
  • Lead proactive threat hunting initiatives aligned with MITRE ATT&CK framework to identify, investigate, and mitigate advanced threats and adversary behaviors.
  • Use telemetry from Microsoft Sentinel, CrowdStrike Falcon, MDE, and other tools to detect anomalies and emerging attack patterns.
  • Develop and optimize threat hunting queries and playbooks using KQL, Python, and PowerShell.
  • Continuously improve detection coverage to reduce dwell time and prevent breaches.
  • Incident Response :
  • Design, implement, and maintain an effective Incident Response (IR) program and playbooks covering APTs, ransomware, insider threats, and complex multi-stage attacks.
  • Lead investigations on high-fidelity security alerts, conduct root cause analysis, containment, eradication, and recovery.
  • Utilize CrowdStrike Falcon EDR (including RTR), Microsoft Defender for Endpoint, and Tenable for comprehensive endpoint and vulnerability correlation during incidents.
  • Perform network forensics and packet analysis using Fortinet and Palo Alto firewall logs.
  • Manage cloud security incidents within Azure (Azure Sentinel, Security Center) and Microsoft 365 environments.
  • Coordinate with internal teams and external partners for timely, coordinated response to security incidents.
  • SOC Engineering & Program Maturity :
  • Build and mature the SOC’s SIEM and SOAR architecture, detection engineering, and response automation.
  • Develop advanced detection logic, hunting queries, and automation workflows.
  • Mentor junior SOC members and act as a technical escalation point.
  • Collaborate with managed SOC partners and other security teams to enhance detection and response capabilities.

Required Experience & Skills :

  • 7+ years of hands-on experience in SOC engineering, with a strong focus on threat hunting and incident response.
  • Expertise in :

  • Microsoft Sentinel (SIEM & SOAR) and advanced KQL queries for hunting and IR
  • CrowdStrike Falcon EDR (RTR, IOAs, threat containment)
  • Microsoft Defender for Endpoint (MDE) telemetry and IR
  • Tenable vulnerability correlation during investigations
  • Fortinet and Palo Alto firewalls for forensic analysis
  • Microsoft Entra ID (Azure AD), SSO, Conditional Access, MFA security controls
  • Deep operational knowledge of MITRE ATT&CK for threat hunting, detection tuning, and adversary simulation.
  • Proven ability to analyze and respond to APTs, malware persistence, lateral movement, privilege escalation, command & control, and data exfiltration incidents.
  • Strong scripting skills (KQL, Python, PowerShell) for threat hunting automation and incident response workflows.
  • Experience with SOAR platforms integration and automation (Microsoft Sentinel SOAR, Palo Alto XSOAR).
  • Excellent communication, collaboration, and mentoring abilities.
  • Must be able to work U.S. business hours (PST timezone).
  • Preferred Certifications :

  • GCFA, GCIH, GCTI, CISSP, AZ-500, MS-500, or equivalent.
  • MITRE ATT&CK Defender (MAD), OSCP, or Red Team certifications are a strong plus.
  • Create a job alert for this search

    Cybersecurity Engineer • thiruvananthapuram, India

    Related jobs
    • Promoted
    Sr. Lead - Cloud Security

    Sr. Lead - Cloud Security

    Sycamore Informatics Inc.Kollam, IN
    Cloud security framework; Strong scripting skills with PowerShell and.Solid understanding of version control tools, particularly Git. Experience with cloud platforms, including AWS, Azure and GCP.Pr...Show moreLast updated: 30+ days ago
    • Promoted
    Sr. SecOps Engineer

    Sr. SecOps Engineer

    ConfidentialThiruvananthapuram / Trivandrum, Bengaluru / Bangalore
    Become an expert in technology stack to understand points of weakness and opportunities for security solutions.Assist in monitoring IT control environment to identify key risks, related controls an...Show moreLast updated: 30+ days ago
    • Promoted
    Vulnerability Management / DevSecOps Engineer - 3+ Years | Trivandrum | Immediate Joiner

    Vulnerability Management / DevSecOps Engineer - 3+ Years | Trivandrum | Immediate Joiner

    USTThiruvananthapuram, Thiruvananthapuram (district)
    CCTC | ECTC | Notice Period | Location Preference.Act fast for immediate attention! ⏳📩.Rapid7 InsightVM, CrowdStrike, Nexus. DevOps, SysAdmins, and Developers.Grafana, Splunk, Jira) for tracking an...Show moreLast updated: 1 day ago
    • Promoted
    Microsoft Sentinel Technical Lead / Architect - Security Operations Center

    Microsoft Sentinel Technical Lead / Architect - Security Operations Center

    PIT Solutions Pvt. Ltd.Trivandrum
    Role : Microsoft Sentinel Technical Lead & SOC Architect Position Type : Full-time Experience : 7 to 12...Show moreLast updated: 30+ days ago
    • Promoted
    Cyber Threat Investigator

    Cyber Threat Investigator

    ColorTokens Inc.Kollam, IN
    At ColorTokens, we empower businesses to stay operational and resilient in an increasingly complex cybersecurity landscape. Breaches happen—but with our cutting-edge ColorTokens Xshield™ platform, c...Show moreLast updated: 8 days ago
    • Promoted
    SOC Lead

    SOC Lead

    USTTrivandrum, Kerala, India
    UST is looking for a SOC Lead with atleast 8 years of exp.NP : Immediate to 30 days only.Interested candidate can share your updated CV to bhoopathyraja. Must have experience as Lead / Manager in SOC ...Show moreLast updated: 15 days ago
    • Promoted
    Senior Cloud Engineer

    Senior Cloud Engineer

    AptonetKollam, IN
    Senior Cloud Developer – Offshore (India | Remote).Contract Role | Multi-Cloud Security Projects | Cutting-Edge AI & Automation. This role offers the opportunity to work on.Python preferred; also Ja...Show moreLast updated: 25 days ago
    • Promoted
    CyberArk Engineer

    CyberArk Engineer

    Next VenturesThiruvananthapuram, IN
    Job Opportunity : CyberArk Engineer.Contract / Permanent / Fixed Term.Privileged Access Management (PAM) implementations using CyberArk technologies. CyberArk Core-PAS, AAM, PTA, HTML5 Gateway.AUTOIT...Show moreLast updated: 15 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    CBTSthiruvananthapuram, India
    Senior level roles as IT Security Architect, IT Security Engineer, IT Security Auditor, Cyber-Security Analyst, Cyber-Intelligence Analyst. Certifications, Accreditations, Licenses.One or more of th...Show moreLast updated: 6 days ago
    • Promoted
    Senior Consultant

    Senior Consultant

    Proglitethiruvananthapuram, India
    We are seeking a motivated and skilled.Network / Cloud / Security Engineer.AWS, Google Cloud Platform (GCP), Cisco Meraki, and Palo Alto firewalls. The ideal candidate will be responsible for design...Show moreLast updated: 8 days ago
    • Promoted
    AI Security & Cloud Engineer (Cybersecurity + Full-Stack)

    AI Security & Cloud Engineer (Cybersecurity + Full-Stack)

    CloudMatosThiruvananthapuram, IN
    In order to proceed further, you have to take the test.M2nO77GO-BogYEl0NY4ceD60TtSJ2hFPnlW0lhizqDE / edit?tab=t.CloudMatos is a next-generation cloud-security and AI-security platform designed for mo...Show moreLast updated: 5 days ago
    • Promoted
    Security & Compliance IT Specialist / Engineer

    Security & Compliance IT Specialist / Engineer

    aecc - digital innovation hubThiruvananthapuram, IN
    Support the organisation’s security posture through monitoring, incident response coordination, and compliance activities. Work closely with IT operations, engineering, and leadership to ensure syst...Show moreLast updated: 5 days ago
    • Promoted
    Cyber Security Specialist

    Cyber Security Specialist

    Tiger AdvisoryThiruvananthapuram, IN
    Tiger Advisory provides premier cybersecurity consulting services, helping clients manage risks, strengthen resilience, and achieve compliance in an ever-evolving digital landscape.Our mission is t...Show moreLast updated: 25 days ago
    • Promoted
    Lead Network & Security Engineer (Hyperscalers – OCI / GCP)

    Lead Network & Security Engineer (Hyperscalers – OCI / GCP)

    Cloud4C Servicesthiruvananthapuram, India
    Gartner’s Magic Quadrant (2021), is a leading automation-driven Cloud Managed Services Provider (MSP).We specialize in multi-cloud migration, management, and disaster recovery with zero data loss g...Show moreLast updated: 7 days ago
    • Promoted
    Illumio- Zero Trust Microsegmentation

    Illumio- Zero Trust Microsegmentation

    CareerXperts ConsultingThiruvananthapuram, IN
    Hiring : Manager - Zero Trust Microsegmentation.Bengaluru | 💼 5+ Years Experience.Lead Illumio microsegmentation implementations. Design & deploy Zero Trust policies.Analyze network infrastructure &...Show moreLast updated: 5 days ago
    • Promoted
    DevSecOps / AppSecOps Staff Engineer

    DevSecOps / AppSecOps Staff Engineer

    First American (India)Thiruvananthapuram, IN
    Our people-first culture empowers bold thinkers and passionate technologists to solve real-world challenges through scalable architecture and innovative design. If you're driven by impact, thrive in...Show moreLast updated: 30+ days ago
    • Promoted
    Quantiphi - Senior Cyber Security Engineer - Vulnerability Management

    Quantiphi - Senior Cyber Security Engineer - Vulnerability Management

    Quantiphi AnalyticsThiruvananthapuram
    Role : Senior Cyber Security Engineer.Experience Level : 3+ Years.Work location : Mumbai, Bangalore & Trivandrum.Role & Responsibilities : < / p&...Show moreLast updated: 30+ days ago
    • Promoted
    Vulnerability Management / DevSecOps Engineer – 3+ Years | Trivandrum | Immediate Joiner

    Vulnerability Management / DevSecOps Engineer – 3+ Years | Trivandrum | Immediate Joiner

    USTThiruvananthapuram, Kerala, India
    CCTC | ECTC | Notice Period | Location Preference.Act fast for immediate attention! ⏳📩.Rapid7 InsightVM, CrowdStrike, Nexus. DevOps, SysAdmins, and Developers.Grafana, Splunk, Jira) for tracking an...Show moreLast updated: 25 days ago