Specialist, CSIRT
Owns frontline security alert triage, incident response, detection coverage, and automation across cloud, SaaS, container, and Web3 environments. Requires at least three years of hands-on security operations experience and proficiency with scripting, SIEM platforms, and threat intelligence tooling.
About the job
Responsibilities
- Own second-line triage and response for security alerts, leading incident management through resolution and driving post-incident improvements.
- Build and maintain runbooks for repeatable response patterns, then define and implement automation to eliminate manual toil.
- Partner with Security Operations teams to develop monitoring strategies informed by attacker investigation findings.
- Drive security monitoring and incident response for emerging Web3 product launches.
- Mentor peers, share knowledge, and participate in 24/7 rotational coverage across time zones.
Requirements
- 3+ years of hands-on security operations experience, including incident response, alert triage, and network/host forensics across cloud, SaaS, and container environments.
- Ability to identify detection gaps and build coverage across diverse log sources, including cloud platforms, SaaS applications, container orchestration, and M&A integrations.
- Proficiency scripting automation workflows using Python, Bash, or equivalent.
- Working knowledge of networking fundamentals and Windows, Linux, and macOS sufficient to analyze host- and network-level artifacts.
- Experience with SIEM platforms and threat intelligence tooling at scale, including tuning alerts and improving signal-to-noise ratios.
- Responsible use of generative AI with human oversight to deliver business-ready outputs and improve workflow efficiency, cost, and quality.
Compensation and Benefits
- Annual base salary: ₹2,755,300–₹2,755,300 INR.
- Total compensation may also include equity, bonus eligibility, and medical, dental, and vision benefits.
Skills
Incident Response, Security Operations, Alert Triage, Network Forensics, Host Forensics, Python, Bash, SIEM, Threat Intelligence, Cloud Security, Container Security, Linux, Windows, macOS, Generative AI
Similar jobs
Security Engineering jobsSecures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Secures Glean's software supply chain by managing vulnerabilities, hardening images, protecting open-source dependencies, and embedding trusted release controls in CI/CD. Requires 3+ years in application security or vulnerability management, strong cloud-native and container security knowledge, and experience with FedRAMP audits.
Senior product security engineer responsible for embedding security across the SDLC, building security automation, conducting reviews and penetration testing, and leading vulnerability response. Requires 5+ years of security experience, strong web and mobile security expertise, and hands-on AWS, CI/CD, and security tooling knowledge.
Leads application and AI security assessments across web, API, cloud-native, and LLM-based systems. Requires 8+ years of cybersecurity experience, hands-on penetration testing and secure SDLC expertise, and experience adversarially testing AI applications.