Handles day to day security engineering activities, including configuration and maintenance of firewalls, IDS/IPS, SIEM tools, and endpoint protection systems.
Conduct vulnerability assessments and coordinate remediation with relevant infrastructure teams.
Monitor, analyze, and respond to security incidents and alerts in a timely manner.
Maintain and tune SIEM rules, correlation policies, and dashboards for accurate threat visibility.
Collaborate with IT, Network, and Cloud teams to ensure secure configuration and patch compliance.
Support audits, compliance checks, and risk assessments for regulatory and internal requirements.
Prepare and maintain security documentation, SOPs, and incident response playbooks.
Mentor engineers and junior engineers on routine tasks.
Measure Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) for security incidents.
Track vulnerability closure rate within defined SLAs.
Ensure compliance with internal and external security standards.
Aim for reduction in repeat or preventable incidents.