Role description
Security Operations Engineer
We are looking for a Security Operations Engineer – L1 with 4–5 years of experience in enterprise cybersecurity operations. The ideal candidate should have a strong foundation in networking, operating systems, endpoint security, security monitoring, and incident response.
The role will be responsible for 24x7 security monitoring, initial incident triage and investigation, security tool health monitoring, troubleshooting, ticket management, and escalation of complex incidents to L2/L3 teams. The candidate will work closely with infrastructure, network, server, application, and security teams to support timely resolution of security incidents and maintain the overall security posture of the organization.
Key Responsibilities
- Monitor enterprise security tools and security events in a 24x7 shift-based environment.
- Monitor and respond to security s and tickets within defined SLA and operational procedures.
- Perform initial triage, investigation, troubleshooting, and escalation of security incidents.
- Analyze security events across endpoint, network, email, identity, and cloud environments.
- Investigate security incidents involving:
- Malware and ransomware
- Phishing and malicious emails
- Suspicious logins and authentication activity
- Unauthorized access
- Endpoint security s
- Indicators of Compromise (IOCs)
- Perform basic log analysis and correlation using SIEM and other security monitoring platforms.
- Conduct daily health checks and operational monitoring of security tools and identify issues requiring remediation.
- Execute approved standard changes and operational activities in accordance with change management processes.
- Create, update, and maintain security incident tickets with accurate investigation details, actions taken, and resolution information.
- Maintain and update SOPs, operational runbooks, knowledge articles, and troubleshooting guides.
- Coordinate with Network, Server, Infrastructure, Application, Cloud, IAM, and other IT teams during security incident investigation and resolution.
- Escalate complex or high-severity incidents to L2/L3 security teams with appropriate investigation details and evidence.
- Support vulnerability remediation, endpoint compliance, and security hygiene activities.
- Participate in shift handovers, incident reviews, knowledge-sharing sessions, and continuous improvement initiatives.
- Follow established security policies, procedures, and incident response processes.
Mandatory Technical Skills
- Strong understanding of TCP/IP and OSI models.
- Working knowledge of Routing, Switching, VLANs, DNS, DHCP, NAT, HTTP/HTTPS, and VPN.
- Ability to perform basic network troubleshooting and understand common network security events.
- Strong working knowledge of Windows and Linux operating systems.
- Understanding of Windows security concepts, services, event logs, processes, and basic troubleshooting.
Hands-on experience with at least one enterprise endpoint security platform such as:
- Microsoft Defender for Endpoint
- CrowdStrike
- SentinelOne
- Cortex XDR
- or equivalent EDR/XDR solutions.
Basic to working knowledge of:
- NGFW / Firewall
- WAF
- Proxy
- IPS/IDS
- Email Security
- SIEM
- PAM
- Identity and Access Security
- Endpoint Detection and Response (EDR/XDR)
- Understanding of Active Directory and Microsoft Entra ID.
- Knowledge of Group Policy, authentication, authorization, MFA, and account security.
- Basic understanding of suspicious authentication and unauthorized access scenarios.
- Basic hands-on experience with SIEM platforms and security log analysis.
- Understanding of common security threats and attack techniques, including:
- Malware
- Ransomware
- Phishing
- Brute-force attacks
- Suspicious authentication
- Unauthorized access
- Indicators of Compromise (IOC)
- Basic understanding of MITRE ATT&CK framework and common attack techniques.
- Ability to perform initial incident triage and determine appropriate escalation paths.
- Basic knowledge of PowerShell or Python is an added advantage.
Preferred Certifications
- CompTIA Security+
- Microsoft SC-900 / SC-200
- CCNA
- Microsoft Defender / SentinelOne security certifications or fundamentals
- CEH – preferred but not mandatory
Behavioral & Soft Skills
- Strong analytical, troubleshooting, and problem-solving skills.
- Good understanding of security operations and incident management processes.
- Strong written and verbal communication skills.
- Ability to work effectively in a 24x7 shift environment.
- Strong attention to detail and ability to follow defined SOPs and processes.
- Good documentation and ticket management skills.
- Ability to work collaboratively with cross-functional technical teams.
- Proactive attitude with a strong willingness to learn emerging cybersecurity technologies and threats.
- Customer-focused approach with a strong sense of ownership and accountability.
Key Performance Indicators (KPIs)
- Security acknowledgement and response SLA compliance.
- Accuracy and effectiveness of incident triage and initial investigation.
- Quality, completeness, and timeliness of security ticket documentation.
- Quality and accuracy of shift handovers.
- Compliance with security tool health-check and monitoring procedures.
- Adherence to security SOPs, operational processes, and escalation procedures.
- Timely and appropriate escalation of security incidents.
- Contribution to vulnerability remediation and endpoint compliance activities.
- Continuous technical learning and progress toward relevant cybersecurity certifications.
Experience
4–5 years of relevant experience in:
- Security Operations / SOC
- Cybersecurity Operations
- Security Monitoring
- Incident Triage and Response
- Endpoint Security / EDR
- SIEM Monitoring
- Enterprise IT Security Operations
Skills
TCP/IP, Windows, Linux, SentinelOne
About UST
UST is a global digital transformation solutions provider. For more than 20 years, UST has worked side by side with the world’s best companies to make a real impact through transformation. Powered by technology, inspired by people and led by purpose, UST partners with their clients from design to operation. With deep domain expertise and a future-proof philosophy, UST embeds innovation and agility into their clients’ organizations. With over 30,000 employees in 30 countries, UST builds for boundless impact—touching billions of lives in the process.