SR Security Operations Engineer
onsemi Bengaluru, Karnataka, India
Semiconductor Manufacturing · 10,001+ employees
About the role
The role involves leading the monitoring, investigation, and response to cybersecurity threats while driving incident lifecycles from detection to remediation. Additionally, the engineer will perform proactive threat hunting and develop automation workflows to enhance security operations and detection capabilities.
What they look for
Requirements
Candidates must have at least 5 years of experience in cybersecurity disciplines such as incident response, threat hunting, or security engineering. A bachelor's degree in a related field is required, along with strong technical knowledge of enterprise security controls and cloud environments.
Benefits
Full description
Job Summary:
The ideal candidate is a self-motivated security professional who consistently delivers high-quality results, demonstrates strong ownership of investigations and operational outcomes, proactively identifies opportunities for improvement, mentors team members, and effectively leverages automation and AI technologies to enhance security operations, threat detection, and incident response capabilities.
Apply if you are looking for a challenging opportunity to drive direction and participate in the dynamic growth in IT security at onsemi, voted the World’s Most Ethical Company for 5 years in a row.
Performance Objectives
Security Operations, Detection & Incident Response
- Lead the monitoring, analysis, investigation, and response of cybersecurity threats and security incidents across enterprise environments.
- Perform advanced triage and investigation of alerts generated by SIEM, EDR, DLP, IAM, cloud security, email security, network security, and other enterprise security technologies.
- Conduct comprehensive incident investigations, including threat validation, scope determination, timeline reconstruction, impact assessment, root cause analysis, and containment recommendations.
- Serve as an escalation point for junior analysts and assist with complex incidents requiring advanced analytical and technical expertise.
- Coordinate response activities across Security Operations, Infrastructure, Security Engineering, Legal, and business stakeholders.
- Drive incidents through the complete lifecycle from detection through remediation, recovery, documentation, and lessons learned.
- Maintain situational awareness of the evolving threat landscape, emerging risks, and active incidents affecting the organization.
Threat Hunting, Analysis & Detection Engineering
- Perform proactive threat hunting across endpoint, identity, network, cloud, application, and emerging technology environments to identify malicious activity beyond alert-driven detection.
- Leverage threat intelligence, behavioral analytics, telemetry correlation, and adversary tradecraft analysis to identify indicators of compromise (IOCs) and attacker tactics, techniques, and procedures (TTPs).
- Investigate sophisticated attack techniques including credential theft, ransomware, insider threats, business email compromise, cloud compromise, and living-off-the-land activity.
- Design, develop, tune, validate, and maintain detection content, analytics rules, dashboards, correlation logic, and threat-driven use cases.
- Continuously improve detection coverage through threat modeling, attack simulation findings, incident lessons learned, and intelligence-driven prioritization.
- Utilize frameworks such as MITRE ATT&CK, NIST 800-61, Cyber Kill Chain, and adversary emulation methodologies to improve detection and response effectiveness.
- Identify gaps in telemetry, monitoring coverage, and response capabilities while recommending improvements to increase operational maturity.
Digital Forensics & Advanced Investigation
- Support digital forensic investigations involving enterprise collaboration and communication.
- Assist with malware triage, indicator extraction, timeline development, and root cause determination.
- Develop investigative methodologies that improve repeatability, consistency, and overall investigative effectiveness.
Security Engineering, Automation & AI-Enabled Operations
- Lead efforts to enhance and optimize security tools, telemetry pipelines, integrations, and monitoring capabilities.
- Support onboarding of new data sources, cloud platforms, applications, and infrastructure services into enterprise security monitoring solutions.
- Develop and maintain automation workflows, orchestration capabilities, and machine-driven response processes using SOAR and related technologies.
- Leverage scripting, query languages, and security automation techniques to improve detection, investigation, reporting, and operational efficiency.
- Utilize artificial intelligence, machine learning technologies, large language models (LLMs), agentic frameworks, and AI-assisted workflows to accelerate investigations and improve analyst effectiveness.
- Contribute to secure AI adoption by helping evaluate AI-related risks, controls, governance requirements, and monitoring capabilities.
- Identify opportunities to increase operational efficiency through automation, AI augmentation, and process optimization.
Leadership, Mentorship & Operational Excellence
- Act as a senior resource and mentor for junior and mid-level analysts.
- Provide investigative guidance, technical coaching, and peer review of incident investigations and response activities.
- Demonstrate ownership and accountability for operational outcomes while consistently contributing to team objectives and strategic initiatives.
- Serve as a trusted advisor during major incidents and provide actionable recommendations to leadership.
- Lead or participate in tabletop exercises, purple-team engagements, operational readiness testing, and post-incident reviews.
- Drive continual improvement of security operations processes, playbooks, detection content, threat hunting methodologies, and incident response procedures.
- Maintain a strong commitment to operational excellence, continuous learning, and technical leadership within the team.
Documentation & Communication
- Produce high-quality investigation reports, executive summaries, incident briefings, and post-incident analyses.
- Communicate technical findings, risk implications, and recommended actions to both technical and executive audiences.
- Develop and maintain operational procedures, playbooks, runbooks, standards, and knowledge management documentation.
- Contribute to security metrics, reporting, operational dashboards, and program maturity assessments.
#LI-RT1
onsemi (Nasdaq: ON) is driving disruptive innovations to help build a better future. With a focus on automotive and industrial end-markets, the company is accelerating change in megatrends such as vehicle electrification and safety, sustainable energy grids, industrial automation, and 5G and cloud infrastructure. With a highly differentiated and innovative product portfolio, onsemi creates intelligent power and sensing technologies that solve the world’s most complex challenges and leads the way in creating a safer, cleaner, and smarter world.
More details about our company benefits can be found here:
https://www.onsemi.com/careers/career-benefits
We are committed to sourcing, attracting, and hiring high-performance innovators, while providing all candidates a positive recruitment experience that builds our brand as a great place to work.