Job Closed

This listing is no longer active.

Security Lead

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 501-1,000Since 2002H1B No SponsorCompany SiteLinkedIn

Location

India

Posted

61 days ago

Salary

₹1,500K - ₹4,500K / year

Seniority

Senior

Job Description

Security Lead

Weekday

• Lead the implementation, configuration, and optimization of SIEM platforms to enable real-time monitoring, correlation, and analysis of security events. • Design and deploy SOAR solutions to automate incident response workflows, reduce response time, and improve operational efficiency. • Develop and maintain use cases, detection rules, dashboards, and alerts within SIEM systems aligned with current threat landscapes. • Integrate multiple security tools (EDR, IDS/IPS, firewalls, cloud security tools) with SIEM/SOAR platforms for centralized visibility and response. • Oversee security incident detection, triage, investigation, and remediation processes. • Lead incident response efforts, including root cause analysis, containment, eradication, and recovery. • Continuously refine playbooks and runbooks for automated and manual response processes. • Collaborate with cross-functional teams including IT, DevOps, and compliance teams to ensure robust security controls. • Mentor and guide junior security analysts and engineers, fostering a strong security culture. • Stay updated with emerging threats, vulnerabilities, and industry best practices to enhance detection and response capabilities.

Job Requirements

  • 4–14 years of experience in cybersecurity, with significant exposure to Security Operations Center (SOC) environments.
  • Strong hands-on experience with leading SIEM tools (e.g., Splunk, QRadar, ArcSight, ELK).
  • Proven expertise in implementing and managing SOAR platforms (e.g., Cortex XSOAR, Splunk Phantom, IBM Resilient).
  • Solid understanding of log analysis, event correlation, and threat detection techniques.
  • Experience in creating and tuning SIEM correlation rules and SOAR playbooks.
  • Knowledge of common attack frameworks such as MITRE ATT&CK.
  • Familiarity with scripting or automation (Python, PowerShell, or similar) is a strong advantage.
  • Good understanding of network security, endpoint security, cloud security, and identity management.
  • Strong analytical, problem-solving, and decision-making skills.
  • Certifications such as CISSP, CISM, CEH, or GIAC are a plus.
  • Experience working in cloud environments (AWS, Azure, or GCP) with integrated security monitoring.
  • Prior experience in leading SOC teams or managing security operations.

Related Categories

Related Job Pages

More Security Engineer Jobs

Rubikal logo

Network Security Engineer

Rubikal

End-to-end custom product development company, Solve 99% of startups' problems

Full TimeRemoteTeam 51-200H1B No Sponsor

At Rubikal, we design, build, and operate human-centric digital services that help organizations navigate and succeed in their digital transformation journeys. We partner with clients ranging from governments and large enterprises to innovative startups, managing the full lifecycle of digital services—from initial concept and design to development, operations, and continuous improvement. Our culture is built on collaboration, trust, and curiosity, with diverse teams working across multiple countries and time zones. We need an Intermediate to Senior Network Security Engineer, preferred with experience in F5, PaloAlto, and Fortinet security products, such as WAF and NGFW. The candidate will implement and maintain the network and security on IaaS cloud, mainly OpenStack. He should oversee network configuration, FW rules, IPSec, and various VPN technologies.

Egypt
Job Closed
Full TimeRemoteTeam 10,001+Since 1979H1B Sponsor

• Create innovative, thought-provoking, and highly leveraged “must-have” insights focused on cybersecurity and AI in security market trends, growth strategies, and leadership practices for small and midsize providers • Develop actionable frameworks and best practices to help Tech CEOs accelerate decision-making and execution in areas such as threat intelligence, compliance, and product innovation • Analyze and predict market shifts in cybersecurity technologies (e.g., AI-driven security, cloud security, zero trust,) and competitive dynamics • Engage directly with Tech CEOs via virtual and in-person meetings, Gartner conferences, and industry events to address strategic challenges and provide tailored recommendations • Deliver compelling presentations and thought leadership content for Gartner events, client briefings, and professional associations • Collaborate with peers across Gartner’s Insights community to shape research agendas and share provocative ideas that influence the cybersecurity market

India
Job Closed
General Dynamics logo

Security Subject Matter Expert

General Dynamics

A business unit of General Dynamics, General Dynamics Information Technology (GDIT) supports some of the United States' most complex government, defense, and in

Title: Security Subject Matter Expert (SME) Location: USA TX Home Office Job Description: time type Full time job requisition id RQ211630 Type of Requisition: Regular Clearance Level Must Currently Possess: None Clearance Level Must Be Able to Obtain: None Public Trust/Other Required: MBI (T2) Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Identity Access Management (IAM), Platform Security, Single Sign-On (SSO), Vulnerability Management, Zero Trust Certifications: None Experience: 10 + years of related experience US Citizenship Required: No Job Description: The Security Subject Matter Expert (SME) is the program’s security lead for a large, hybrid enterprise (on-prem data centers and multi-cloud). You will architect, implement, and operate a Zero Trust, RMF-aligned security solutions that keep systems reliable, data protected, and the program audit-ready at all times. You will own the end-to-end security operating model, identity and access (including PIV/FIDO and PAM), vulnerability and patch orchestration, logging and SIEM/SOAR, supply-chain integrity (SBOM/provenance), backup/DR resilience, and continuous monitoring. HOW THE SECURITY SME WILL MAKE AN IMPACT: You will convert compliance into a running capability rather than a paperwork cycle. By embedding controls in automation, policy-as-code in pipelines, signed artifacts with attestations, identity-centric access, and immutable backups, you will raise assurance while reducing toil and mean time to recover. You’ll drive continuous compliance with authoritative evidence from VA systems (ITSM/CMDB, SIEM/EDR, vulnerability tools), cut vulnerability aging against CISA KEV targets, and raise control pass rates without slowing delivery. During incidents, you will lead joint “swarm” response, contain issues quickly, and turn lessons into baseline changes, POA&Ms, and updated playbooks. For executives and non-technical stakeholders, you’ll translate risk into clear narratives - what happened, what changed, how we’re safer, and publish trend lines that connect security investments to fewer outages, cleaner audits, and lower total cost of ownership. WHAT YOU’LL NEED TO SUCCEED: - 10+ years in enterprise cybersecurity engineering/operations with direct ownership of hybrid (data center + AWS/Azure) environments; 3+ years in regulated or federal programs (VA/DoD/DHS/HHS or equivalent). - Demonstrated delivery of Zero Trust architectures (per NIST SP 800-207/TIC 3.0), RMF/ATO sustainment (SP 800-53 Rev 5/53B baselines), and continuous monitoring at scale. - Hands-on leadership standing up SIEM/SOAR, EDR, vulnerability management, identity platforms (SSO/PIV/FIDO, PAM/JIT), and audited disaster recovery programs (SP 800-184). - Proven record improving outcomes: higher control pass, reduced critical vuln aging, faster MTTR, successful external assessments, and repeatable ATO renewals. - Experience operating within multi-vendor/SIAM models with cross-vendor OLAs and shared KPIs. - Education: Bachelor's Degree. In lieu of a degree, an additional four years of related experience required - Security clearance level: Public Trust - Timeline: This is a contingent posting, expected to start in August 2026 TECHNICAL PROFICIENCIES: - Identity & Access (ICAM): SSO (SAML/OIDC), PIV/CAC and FIDO2, JIT/PAM, least-privilege for human and workload identities; directory hygiene and join/move/leave automation. - Network & Platform Security: Segmentation and micro-segmentation, SASE/SD-WAN patterns aligned to TIC 3.0; hardened baselines (STIG/CIS) for OS, containers, and Kubernetes/OpenShift (admission control, policy engines). - Logging, Detection, and Response: Event logging per OMB M-21-31, SIEM content engineering, SOAR playbooks, EDR tuning; run tabletop exercises and purple-team improvements. - Vulnerability & Patch Orchestration: Toolchain proficiency (e.g., Tenable/Qualys, WSUS/Linux lifecycle), KEV-driven prioritization, SLAs by criticality, and automated compliance evidence (SCAP). - Secure SDLC & Supply Chain: SSDF (SP 800-218) practices, artifact signing and provenance/attestations (SLSA/SBOM), trusted registries, policy-as-code gates in CI/CD; secrets management (KMS/Vault). - Data & Storage Protection: Encryption in transit/at rest (FIPS-140 validated), key management, DLP patterns, immutable/object-lock backups, tested DR with objective pass/fail artifacts. - Standards & Tooling Fluency: NIST CSF 2.0, SP 800-61 (IR), SP 800-53/53B, SP 800-207, SP 800-184, TIC 3.0, FIPS-140; OSCAL for machine-readable SSP/ConMon SKILLS & ABILITIES: - Clear Communicator: Converts complex risk and telemetry into executive-ready, plain-language updates; writes crisp playbooks, runbooks, and policy one-pagers. - Outcome-Driven: Ties security work to measurable results, control pass rate, vuln aging, incident frequency/MTTR, DR test pass, and audit findings, published on a shared scorecard. - Builder’s Mindset: Designs controls that are easy to use and hard to bypass; prefers automation over manual checks; balances guardrails with delivery speed. - Facilitation & Influence: Leads cross-domain incident “swarming,” champions secure patterns with engineers, and negotiates trade-offs that protect both security and uptime. - Governance & Rigor: Runs change risk reviews, manages POA&Ms to closure, and keeps the ATO pipeline predictable with OSCAL-based evidence and scheduled assessments. - Mission Focus: Aligns security investments with VA outcomes including fewer disruptions for clinicians and staff, stronger protection of Veteran data, and demonstrable stewardship of taxpayer funds PREFERRED CERTIFICATIONS: - CISSP - CCSP - CISM - CASP+ - GIAC (GCIH/GCIA/GMON/GCSA/GPCS/GCED) - CEH - AWS/Azure security specialty - CAP or equivalent RMF credential GDIT IS YOUR PLACE: - Full-flex work week to own your priorities at work and at home - 401K with company match - Comprehensive health and wellness packages - Internal mobility team dedicated to helping you build your skills and own your career - Professional growth opportunities including paid education and certifications - Cutting-edge technology you can learn from - Rest and recharge with paid vacation and 10 company-paid holidays The likely salary range for this position is $165,750 - $224,250. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Hybrid Work Location: USA TX Home Office (TXHOME) Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most. We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.

Texas
$165.8K - $224.3K / year
Full TimeRemoteTeam 51-200Since 2009H1B No Sponsor

• Execute and document risk assessments of the cybersecurity stature of various subsystems and components within the Edison system • Guide product engineering teams to drive inherent risk remediation via documenting and implementing requirements and adoption of best practices to reduce residual risk and improve the cybersecurity stature of the Edison system • Support FDA premarket submissions by preparing cybersecurity documentation including risk management reports, threat model, MDS2 and cybersecurity whitepaper • Support cyber lifecycle management activities including vulnerability monitoring, assessment, and documentation needs • Maintain a positive, results-oriented work environment, building partnerships and modeling teamwork, communicating to team members in an open, balanced, and objective manner • Create/ maintain a clean, safe, and effective work environment.

Wisconsin
$120K - $140K / year