Engineer II, Cybersecurity Incident Response
Schneider Electric · Bengaluru, Karnataka, India
Automation Machinery Manufacturing · 10,001+ employees
About the role
The role involves identifying and mitigating cyber risks while supporting the incident response lifecycle for critical digital assets. You will also contribute to process automation and the implementation of AI-assisted security tools to enhance detection and reporting workflows.
What they look for
Requirements
Candidates must have 3-5 years of professional experience in cybersecurity, risk management, or incident response. A technical background in computer science, information technology, or engineering is required, along with proficiency in English.
Full description
Cyber Risk and Incident Response
Engineer II, Cybersecurity Incident Response
Exp 3-5 yrs
Bengaluru, India
Position Summary
We are looking for a motivated Cyber Risk & Incident Response engineer to join the Enterprise IT Infrastructure Security team in Bengaluru. The position supports the mitigation of cyber risks and response to incidents impacting Schneider Electric digital assets and population.
The role is intentionally generalist: it combines cyber risk analysis, incident response, threat awareness, IT/infrastructure understanding, and practical automation skills.
The successful candidate will help identify risk scenario impacting Schneider Electric, support mitigation strategies, assist in incident response investigations, and contribute to automate processes and implementing AI tooling to scale up services within the team.
Role Mission
Help identify, assess, and reduce cyber risks affecting critical assets within Schneider Electric.
- Support investigations and incident response activities related to executive account, identity, device, phishing, credential theft, and social engineering scenarios.
- Contribute to the definition of practical mitigation strategies, controls, playbooks, and follow-up actions.
- Use scripting, data analysis, and AI-assisted automation to improve detection, triage, reporting, and risk monitoring workflows.
Key Responsibilities
Cyber Risk Management
- Support the assessment and monitoring of cyber risks affecting critical digital assets and population.
- Identify recurring risk patterns, exposure scenarios.
- Assist in defining and tracking mitigation actions to reduce likelihood and impact on critical assets and population.
- Prepare structured risk summaries, observations, and recommendations for internal stakeholders.
Incident Response Support
- Support the incident response lifecycle, including triage, analysis, containment support, recovery coordination, and post-incident actions.
- Assist with the collection and analysis of evidence, indicators of compromise, suspicious sign-in activity, phishing artefacts, endpoint alerts, and relevant security telemetry.
- Coordinate with SOC, Cyber Defense, Identity, Infrastructure, Forensics, Threat Intelligence, and regional security teams as needed.
- Document investigation steps, findings, decisions, and lessons learned in a clear and structured manner.
Security Analysis & Threat Awareness
- Analyze common attack vectors.
- Monitor relevant threat intelligence and translate it into practical risk observations and recommended actions.
- Support proactive reviews, hunting hypotheses, and control validation activities.
Automation, Coding & AI Enablement
- Develop and maintain simple scripts, queries, or workflows to automate repetitive security and reporting tasks.
- Contribute to the adoption of AI-assisted security operations capabilities, including Copilot-based summaries, workflow automation, and investigation support use cases.
- Propose pragmatic improvements to reduce manual effort and increase consistency in risk identification, triage, and reporting.
Collaboration & Communication
- Work effectively with global teams, regional CISOs, Digital Risk Leaders, SOC, Identity, Infrastructure, and other stakeholders.
- Communicate technical observations in clear English to both technical and non-technical audiences.
- Maintain discretion and professionalism when working on sensitive cases involving company leaders.
- Contribute to playbooks, knowledge articles, lessons learned, and continuous improvement activities.
Desired Technical Skills
- Cybersecurity Risk Management (Intermediate)
- Master cyber risk scenarios, impact, likelihood, controls, and mitigation plans.
- Incident Response (Beginner)
- Understand triage, analysis, containment, recovery, evidence gathering, and post-incident action tracking.
- Security Monitoring / SIEM (Beginner)
- Ability to use security monitoring tools and understand alerts, events, queries, and investigation timelines.
- Identity & Access Security (Beginner)
- Understand account compromise, MFA, privileged access, suspicious sign-ins, and executive identity protection scenarios.
- Network Security (Beginner)
- Understand firewalls, proxies, IDS/IPS, WAF, network protocols, and common network security concepts.
- Windows Administration (Beginner)
- Understand Windows environments, users, services, logs, endpoints, and basic administration concepts.
- Linux Administration (Beginner)
- Understand basic Linux operating system concepts and command-line usage.
- Cloud Security (Azure / AWS) (Beginner)
- Understand basic cloud concepts and common security controls in Azure and AWS.
- Vulnerability Management (Intermediate)
- Understand vulnerability impact, prioritization, remediation tracking, and risk-based decision making.
- Threat Intelligence (Beginner)
- Understand how to gather and interpret threat information relevant to executive-targeted risks.
- Digital Forensics (Beginner)
- Understand basic evidence handling, artifact review, and forensic investigation concepts.
- Coding & Automation (Beginner)
- Use Python, PowerShell, Bash, KQL, Power Automate, APIs, or similar tools to automate data processing, reporting, and investigation tasks.
- AI-Assisted Security Operations (Beginner)
- Understand how AI and copilots can support summaries, enrichment, workflow automation, and repetitive security tasks.
Experience & Education
Required
- 3-5 years of professional experience in Cybersecurity, risk management, security operations, or incident response.
- Technical background in computer science, information technology, cybersecurity, engineering, or related discipline.
- Good understanding of enterprise IT environments and ability to connect technical facts with business risk.
- Working proficiency in English, both written and spoken.
Preferred
- Exposure to security risk management, incident response, vulnerability management, identity security, or cloud security.
- Experience with scripting, data analysis, automation workflows, or API-based integrations.
- Familiarity with Microsoft security technologies, KQL, Power Automate, Copilot Studio, or similar automation platforms.
- Security certifications such as CISSP, CISM, CISA, Security+, GCEH, or equivalent are a plus, but not mandatory.
Soft Skills & Behaviors
- Curious, proactive, and willing to learn across multiple cybersecurity and IT domains.
- Structured and organized, with the ability to document facts, analysis, decisions, and follow-up actions clearly.
- Able to operate calmly in time-sensitive or high-pressure situations.
- Strong analytical mindset and ability to identify practical, risk-based recommendations.
- Team player able to collaborate across regions, functions, and technical domains.
- Comfortable working with sensitive information and maintaining confidentiality.
- Able to translate technical observations into clear business-oriented messages.
Rewards designed for you
Our Total Rewards is our way of saying: We see you and we value you. It’s more than just pay and benefits—it’s a meaningful investment in you. It is designed to help you perform, grow, feel safe, and elevate your potential. The package helps you care for yourself and your family, plan your future, grow your skills and career, collaborate in an inclusive workplace, and contribute to your community. At Schneider Electric, we’re here for what matters most to you. Discover more at our Career Page.
* Country-specific programs and initiatives may be available.
Looking to make an IMPACT with your career?
When you are thinking about joining a new team, culture matters. At Schneider Electric, our values and behaviors are the foundation for creating a great culture to support business success. We believe that our IMPACT values – Inclusion, Mastery, Purpose, Action, Curiosity, Teamwork – starts with us.
IMPACT is also your invitation to join Schneider Electric where you can contribute to turning sustainability ambition into actions, no matter what role you play. It is a call to connect your career with the ambition of achieving a more resilient, efficient, and sustainable world.
We are looking for IMPACT Makers; exceptional people who turn sustainability ambitions into actions at the intersection of automation, electrification, and digitization. We celebrate IMPACT Makers and believe everyone has the potential to be one.
Become an IMPACT Maker with Schneider Electric – apply today!
€40 billion global revenue +9% organic growth 150 000+ employees in 100+ countries
You must submit an online application to be considered for any position with us. This position will be posted until filled.
Schneider Electric aspires to be the most inclusive and caring company in the world, by providing equitable opportunities to everyone, everywhere, and ensuring all employees feel uniquely valued and safe to contribute their best. We mirror the diversity of the communities in which we operate, and ‘inclusion’ is one of our core values. We believe our differences make us stronger as a company and as individuals and we are committed to championing inclusivity in everything we do.
At Schneider Electric, we uphold the highest standards of ethics and compliance, and we believe that trust is a foundational value. Our Trust Charter is our Code of Conduct and demonstrates our commitment to ethics, safety, sustainability, quality and cybersecurity, underpinning every aspect of our business and our willingness to behave and respond respectfully and in good faith to all our stakeholders. You can find out more about our Trust Charter here
Schneider Electric is an Equal Opportunity Employer. It is our policy to provide equal employment and advancement opportunities in the areas of recruiting, hiring, training, transferring, and promoting all qualified individuals regardless of race, religion, color, gender, disability, national origin, ancestry, age, military status, sexual orientation, marital status, or any other legally protected characteristic or conduct.