Senior Security Engineer / Incident Response Lead (L3)
Company: Cywarden Global Services Location: Mohali, India (On-site) Department: Security Operations Center (SOC) Experience Level: L3 / Lead
About the Role
Cywarden Global Services is looking for a Senior Security Engineer / Incident Response Lead (L3) to serve as the highest technical escalation point within our Security Operations Center in Mohali. This role owns the full incident response lifecycle for the most complex security events, drives the organization's detection strategy, and mentors the broader SOC team. You will work across cloud, identity, endpoint, email, and network environments, translating threat intelligence and emerging attack techniques into concrete detection and security improvements.
Key Responsibilities
- Lead end-to-end incident response activities, including preparation, detection, analysis, containment, eradication, recovery, and post-incident review.
- Act as the technical lead for complex security incidents across cloud, identity, endpoint, email, and network environments.
- Design and continuously improve the organization's detection strategy by identifying visibility gaps and implementing advanced detection use cases.
- Develop advanced Microsoft Sentinel analytics rules, KQL queries, Microsoft Defender XDR detections, automation playbooks, and response workflows.
- Lead proactive threat hunting activities to identify sophisticated threats and attacker behavior across the environment.
- Review and improve security monitoring coverage across Azure, OCI, OCVS, Active Directory, Entra ID, Microsoft 365, Palo Alto Firewalls, Cisco/Meraki infrastructure, and other enterprise technologies.
- Assess security architecture and recommend improvements based on industry best practices.
- Develop and maintain incident response playbooks, detection standards, investigation methodologies, and technical documentation.
- Perform root cause analysis and provide long-term remediation recommendations to strengthen the overall security posture.
- Translate threat intelligence, vulnerabilities, and emerging attack techniques into actionable detections and security improvements.
- Review new infrastructure, cloud services, and applications to ensure appropriate security monitoring and logging are implemented before production.
- Lead technical discussions with customers during security incidents and provide remediation guidance.
- Mentor SOC analysts through technical coaching, investigation reviews, and knowledge-sharing sessions.
- Drive continuous improvement initiatives for SOC maturity, detection engineering, automation, and incident response processes.
- Act as the highest technical escalation point for the SOC team during critical security incidents.
Required Skills & Experience
- 6–8+ years of experience in security operations, incident response, or detection engineering, with demonstrated experience leading complex investigations end-to-end.
- Deep expertise in Microsoft Sentinel (advanced analytics rules, automation/playbooks) and KQL for complex detection engineering.
- Strong hands-on experience with Microsoft Defender XDR, Entra ID, Active Directory, Microsoft 365, and Azure security architecture.
- Experience securing and monitoring OCI/OCVS, Palo Alto Firewalls, and Cisco/Meraki network infrastructure.
- Proven track record of designing detection strategy and closing visibility gaps across multi-cloud and hybrid environments.
- Strong grasp of security architecture principles and ability to recommend improvements aligned to industry best practices.
- Experience turning threat intelligence and vulnerability data into actionable detections and mitigations.
- Excellent root cause analysis skills with a track record of driving long-term remediation, not just incident closure.
- Strong customer-facing communication skills, with experience leading technical discussions during live incidents.
- Demonstrated experience mentoring and upskilling SOC analysts (L1/L2) through coaching and investigation reviews.
- Experience driving SOC maturity initiatives — detection engineering, automation, and process improvement.
Nice to Have
- Certifications such as GCIH, GCFA, GCTI, CISSP, SC-200, AZ-500, or equivalent.
- Scripting/automation experience (PowerShell, Python, Logic Apps/Playbooks) for SOAR-driven response.
- Experience reviewing new infrastructure/application deployments for security logging and monitoring readiness.
- Prior experience in an MSSP or managed detection & response (MDR) environment at a lead/escalation level.
What We Offer
- A high-ownership role as the technical anchor of the SOC, shaping detection strategy and incident response maturity.
- Exposure to a broad, modern security stack spanning Microsoft, OCI/OCVS, Palo Alto, and Cisco/Meraki.
- Direct influence over SOC processes, mentoring pathways, and customer-facing incident leadership.
To Apply: Interested candidates can send their updated resume with relevant experience details.
Cywarden Global Services | Mohali
Pay: ₹1,000,000.00 - ₹1,200,000.00 per year
Work Location: In person