01Overview
Role description
Security Operations Engineer
We are looking for a Security Operations Engineer L1 with 45 years of experience in enterprise cybersecurity operations. The ideal candidate should have a strong foundation in networking, operating systems, endpoint security, security monitoring, and incident response.
The role will be responsible for 24x7 security monitoring, initial incident triage and investigation, security tool health monitoring, troubleshooting, ticket management, and escalation of complex incidents to L2/L3 teams. The candidate will work closely with infrastructure, network, server, application, and security teams to support timely resolution of security incidents and maintain the overall security posture of the organization.
Key Responsibilities
Monitor enterprise security tools and security events in a 24x7 shift-based environment.
Monitor and respond to security s and tickets within defined SLA and operational procedures.
Perform initial triage, investigation, troubleshooting, and escalation of security incidents.
Analyze security events across endpoint, network, email, identity, and cloud environments.
Investigate security incidents involving:
Malware and ransomware
Phishing and malicious emails
Suspicious logins and authentication activity
Unauthorized access
Endpoint security s
Indicators of Compromise (IOCs)
Perform basic log analysis and correlation using SIEM and other security monitoring platforms.
Conduct daily health checks and operational monitoring of security tools and identify issues requiring remediation.
Execute approved standard changes and operational activities in accordance with change management processes.
Create, update, and maintain security incident tickets with accurate investigation details, actions taken, and resolution information.
Maintain and update SOPs, operational runbooks, knowledge articles, and troubleshooting guides.
Coordinate with Network, Server, Infrastructure, Application, Cloud, IAM, and other IT teams during security incident investigation and resolution.
Escalate complex or high-severity incidents to L2/L3 security teams with appropriate investigation details and evidence.
Support vulnerability remediation, endpoint compliance, and security hygiene activities.
Participate in shift handovers, incident reviews, knowledge-sharing sessions, and continuous improvement initiatives.
Follow established security policies, procedures, and incident response processes.
Mandatory Technical Skills
Networking
Strong understanding of TCP/IP and OSI models.
Working knowledge of Routing, Switching, VLANs, DNS, DHCP, NAT, HTTP/HTTPS, and VPN.
Ability to perform basic network troubleshooting and understand common network security events.
Operating Systems
Strong working knowledge of Windows and Linux operating systems.
Understanding of Windows security concepts, services, event logs, processes, and basic troubleshooting.
Endpoint Security
Hands-on experience with at least one enterprise endpoint security platform such as:
Microsoft Defender for Endpoint
CrowdStrike
SentinelOne
Cortex XDR
or equivalent EDR/XDR solutions.
Security Technologies
Basic to working knowledge of:
NGFW / Firewall
WAF
Proxy
IPS/IDS
Email Security
SIEM
PAM
Identity and Access Security
Endpoint Detection and Response (EDR/XDR)
Identity & Access Security
Understanding of Active Directory and Microsoft Entra ID.
Knowledge of Group Policy, authentication, authorization, MFA, and account security.
Basic understanding of suspicious authentication and unauthorized access scenarios.
Security Monitoring & Incident Response
Basic hands-on experience with SIEM platforms and security log analysis.
Understanding of common security threats and attack techniques, including:
Malware
Ransomware
Phishing
Brute-force attacks
Suspicious authentication
Unauthorized access
Indicators of Compromise (IOC)
Basic understanding of MITRE ATT&CK framework and common attack techniques.
Ability to perform initial incident triage and determine appropriate escalation paths.
Scripting
Basic knowledge of PowerShell or Python is an added advantage.
Preferred Certifications
CompTIA Security+
Microsoft SC-900 / SC-200
CCNA
Microsoft Defender / SentinelOne security certifications or fundamentals
CEH preferred but not mandatory
Behavioral & Soft Skills
Strong analytical, troubleshooting, and problem-solving skills.
Good understanding of security operations and incident management processes.
Strong written and verbal communication skills.
Ability to work effectively in a 24x7 shift environment.
Strong attention to detail and ability to follow defined SOPs and processes.
Good documentation and ticket management skills.
Ability to work collaboratively with cross-functional .