Description
Role Overview
The Security Operations Engineer is responsible for safeguarding the organization's cloud platforms, applications, infrastructure, and data assets through proactive security monitoring, vulnerability management, threat detection, incident response, and compliance management.
The role works closely with Cloud Operations, Engineering, Salesforce, Product, and Compliance teams to ensure security controls are effectively implemented, monitored, and continuously improved across all environments.
Key Responsibilities:
1.
Security Monitoring and Threat Detection
• Monitor security events and alerts across AWS, Azure, Heroku, Salesforce, and internal systems.
• Configure and maintain security monitoring platforms, SIEM tools, and alerting systems.
• Investigate suspicious activities, anomalous behavior, and potential security incidents.
• Analyze logs from cloud platforms, applications, identity systems, and network devices.
• Develop and tune detection rules to reduce false positives and improve threat visibility.
• Perform threat hunting activities to identify emerging risks and vulnerabilities.
2.
Incident Response and Security Operations
• Lead investigation, containment, eradication, and recovery activities for security incidents.
• Develop and maintain Incident Response (IR) playbooks and procedures.
• Coordinate cross-functional response efforts during security events.
• Conduct root cause analysis and document lessons learned following incidents.
• Ensure timely reporting and escalation of security incidents.
• Support disaster recovery and business continuity activities from a security perspective.
3.
Vulnerability and Risk Management
• Conduct regular vulnerability assessments across infrastructure, applications, cloud services, and endpoints.
• Coordinate penetration testing activities and track remediation efforts.
• Maintain vulnerability remediation plans and monitor closure timelines.
• Assess risks associated with new technologies, integrations, and third-party services.
• Collaborate with engineering teams to prioritize remediation based on risk and business impact.
• Maintain a service risk register and security risk dashboard.
4.
Identity and Access Management (IAM)
• Maintain and review access controls across AWS, Azure, Heroku, Salesforce, and corporate systems.
• Implement and enforce least-privilege access principles.
• Monitor privileged account usage and administrative activities.
• Conduct periodic access reviews and recertification exercises.
• Ensure Multi-Factor Authentication (MFA), Single Sign-On (SSO), and Role-Based Access Control (RBAC) policies are properly implemented.
• Support Joiner, Mover, and Leaver (JML) access governance processes.
5.
Cloud Security
• Implement and maintain cloud security controls across AWS, Azure, and Heroku environments.
• Ensure secure configuration of cloud services, networking, storage, and identity components.
• Continuously review cloud environments against security best practices and benchmarks.
• Monitor cloud security posture and misconfiguration findings.
• Support secure deployment pipelines and DevSecOps initiatives.
• Collaborate with Cloud Operations teams to improve platform resilience and security.
6.
Compliance, Governance, and Audit Readiness
• Support compliance initiatives including ISO 27001, SOC 2, GDPR, and customer security requirements.
• Maintain security policies, standards, procedures, and control documentation.
• Assist in internal and external security audits.
• Track compliance findings and remediation activities.
• Ensure security evidence and documentation are maintained for audit readiness.
• Participate in vendor and third-party security assessments.
7.
Application and Data Security
• Work with engineering teams to identify and mitigate application security risks.
• Support secure software development lifecycle (SSDLC) practices.
• Review security configurations for APIs, integrations, and Salesforce-connected applications.
• Ensure encryption standards are applied for data in transit and at rest.
• Monitor data access patterns and investigate potential data exposure risks.
• Support secret management, certificate management, and key rotation activities.
8.
Security Awareness and Continuous Improvement
• Conduct security awareness and phishing simulation programs.
• Educate teams on security best practices and emerging threats.
• Develop security runbooks, SOPs, and operational documentation.
• Track security metrics, KPIs, and risk indicators.
• Recommend improvements to security processes, tooling, and controls.
• Promote a security-first culture across the organization.
Required Skills & Qualifications:
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or equivalent experience.
• 2-4 years of experience in Security Operations, Cybersecurity, Cloud Security, or related roles.
• Hands-on experience securing AWS and Azure environments.
• Strong understanding of security principles, risk management, and incident response.
• Experience with vulnerability management and security assessment tools.
• Knowledge of networking, firewalls, DNS, VPNs, web security, and secure architectures.
• Experience with SIEM, log analysis, and security monitoring platforms.
• Understanding of IAM, SSO, MFA, RBAC, and privileged access management.
• Scripting or automation skills using Python, PowerShell, or Bash.
• Familiarity with DevSecOps practices and CI/CD security controls.
Preferred Qualifications:
• Experience securing Salesforce, Heroku, and SaaS platforms.
• Hands-on experience with Microsoft Defender, Sentinel, Splunk, ELK, CrowdStrike, Wiz, Lacework, Prisma Cloud, or similar security tools.
• Knowledge of OWASP Top 10 and application security concepts.
• Experience with container and Kubernetes security.
• Exposure to threat intelligence and threat hunting techniques.
• Experience working in ISO 27001, SOC 2, GDPR, HIPAA, or regulated environments.
• Understanding of cloud security frameworks such as CIS Benchmarks and NIST Cybersecurity Framework.
Only shortlisted candidates will be notified regarding the further selection process.