About the role
The L3 Security Platform Engineer leads advanced incident investigations, threat hunting, and security platform administration to ensure robust organizational defense. They also mentor junior analysts and coordinate with cross-functional teams to maintain detection maturity and incident response capabilities.
What they look for
Requirements
Candidates must have strong hands-on experience in SOC operations, including SIEM, endpoint, and cloud security platforms. Professional security certifications and experience in regulated environments are highly preferred for this role.
Benefits
Full description
At Provido, we’re more than a technology company. We are a global hub of innovation, creativity, and engineering excellence.
Our teams design and deliver intelligent, secure, and high-performance digital solutions that help organizations modernize operations, scale their platforms, and succeed in an increasingly digital world.
As part of a dynamic international ecosystem, we bring together forward-thinking engineers, technology specialists, designers, and delivery professionals who transform ideas into scalable, real-world solutions with measurable business impact. If you are motivated by challenge, inspired by technology, and ready to grow with a company that truly invests in its people, your journey starts here.
👉 Why We Need You
L3 Security Platform Engineer is responsible for advanced security monitoring, incident investigation, threat analysis, and escalation support within the Security Operations Center. This role requires strong hands-on experience in SOC operations combined with security platform administration capabilities across SIEM, endpoint detection and response, email security, cloud security, identity security, and related monitoring technologies. The analyst will lead complex investigations, tune detection use cases, support platform health and configuration activities, mentor junior analysts, and coordinate with incident response, infrastructure, and application teams to strengthen the organization’s security monitoring and response capability. The role is based on-site in Hyderabad and supports global Security Operations in a Follow-The-Sun model.
👉 What You’ll Be Doing
•Lead advanced triage, investigation, and analysis of high-severity alerts and incidents across SIEM, endpoint, network, email, identity, and cloud security platforms.
•Perform deep-dive log analysis, event correlation, threat hunting, and root-cause analysis to identify attack patterns, indicators of compromise, and control gaps.
•Administer and maintain security platforms, including configuration updates, rule tuning, alert logic validation, data source onboarding, connector health checks, and access administration where applicable.
•Develop, refine, and maintain detection use cases, correlation rules, dashboards, playbooks, standard operating procedures, and response runbooks.
•Coordinate incident response activities with security engineering, infrastructure, cloud, network, identity, application, and business teams to ensure timely containment and remediation.
•Provide technical guidance, quality review, and mentoring to L1 and L2 SOC analysts, including escalation review and investigation coaching.
•Ensure accurate documentation of investigations, evidence, actions taken, lessons learned, and control recommendations in ticketing and case management systems for reporting and audit purposes.
•Support 24/7 SOC operations through structured handovers, shift support, service level adherence, and collaboration with global teams operating in a Follow-The-Sun model.
👉 What You Bring to the Team
•Lead advanced triage, investigation, and analysis of high-severity alerts and incidents across SIEM, endpoint, network, email, identity, and cloud security platforms.
•Perform deep-dive log analysis, event correlation, threat hunting, and root-cause analysis to identify attack patterns, indicators of compromise, and control gaps.
•Administer and maintain security platforms, including configuration updates, rule tuning, alert logic validation, data source onboarding, connector health checks, and access administration where applicable.
•Develop, refine, and maintain detection use cases, correlation rules, dashboards, playbooks, standard operating procedures, and response runbooks.
•Coordinate incident response activities with security engineering, infrastructure, cloud, network, identity, application, and business teams to ensure timely containment and remediation.
•Provide technical guidance, quality review, and mentoring to L1 and L2 SOC analysts, including escalation review and investigation coaching.
•Ensure accurate documentation of investigations, evidence, actions taken, lessons learned, and control recommendations in ticketing and case management systems for reporting and audit purposes.
•Support 24/7 SOC operations through structured handovers, shift support, service level adherence, and collaboration with global teams operating in a Follow-The-Sun model.
👉 Preferred Skills
•Professional certifications such as CompTIA Security+, CySA+, GCIA, GCIH, GCFA, CEH, SC-200, AZ-500, Microsoft Security Operations Analyst, or equivalent security operations credentials.
•Hands-on experience with Microsoft Sentinel, Microsoft Defender XDR, Splunk, QRadar, CrowdStrike, Palo Alto, Fortinet, Proofpoint, Zscaler, or comparable enterprise security technologies.
•Experience onboarding log sources, maintaining connectors, building dashboards, managing alert queues, integrating SOAR workflows, or supporting security platform upgrades.
•Exposure to cloud security monitoring across Microsoft Azure, AWS, Google Cloud, or hybrid enterprise environments.
•Experience working in regulated or compliance-focused environments with strong documentation, control adherence, evidence management, and audit support expectations.
•Ability to mentor junior analysts, lead technical escalations, and contribute to continuous improvement of SOC processes, detection maturity, and operational reporting.
👉 Why You’ll Love Working with Us
☐ Employee Benefits & Advantages
At Provido, we value our employees and nurture a culture of progress and creativity. Our team members enjoy a supportive, inclusive, and growth-focused environment.
☐ Competitive Compensation & Performance Incentives Provido offers an attractive salary package and performance-based bonuses to recognize and reward your contribution.
☐ Flexible Working Options We support remote and hybrid working models to help you maintain a healthy work-life balance.
☐ Health & Well-being Support We provide comprehensive health insurance, wellness initiatives, and resources to support both physical and mental well-being.
☐ Career Advancement & Development Programs We invest in continuous learning through training programs, mentorship, and clearly defined career development paths.
☐ Team-Oriented & Inclusive Workplace Our culture is built on diversity, inclusion, and collaboration. Every voice matters and innovation is encouraged.
☐ Team Events & Social Activities We organize regular team-building activities and social events to strengthen relationships and create a positive, connected workplace.