Creative ITC

Security Engineer – Security Operations (SecOps)

Creative ITC · Bengaluru, Karnataka, India

IT Services and IT Consulting · 201-500 employees

19 h ago
Mid (2-5 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Manage cyber security incidents end-to-end, including triage, containment, and recovery across email and cloud systems. Proactively hunt for threats and administer security tooling such as Microsoft E5 stack and Proofpoint to maintain organizational security.

What they look for

Security Operations Incident Response Microsoft Security Stack Proofpoint DNS Filtering Threat Hunting Microsoft Sentinel Microsoft Defender XDR Microsoft Purview Microsoft Entra ID Vulnerability Management Data Loss Prevention ITSM Network Security Application Firewalls Zero Trust

Requirements

Requires a bachelor's degree in a relevant field and CompTIA Security+ or ISC2 Certified in Cybersecurity certification. Candidates should have 3+ years of technical security experience and proficiency with Microsoft security tools.

Benefits

Fully sponsored professional certifications Structured career development pathway Continuous learning environment

Full description

POSITION SUMMARY

We are looking for a Security Engineer to join our specialist Security Operations team in Bangalore. This is a hands-on, technical role covering the day-to-day operation, administration and continuous improvement of the security tooling that protects both our clients and our own enterprise environment. The successful candidate will work a 24/7 shift rotation as part of our follow-the-sun SOC model, reporting to and managed by the Bangalore SecOps Lead. The role combines technical operations with elements of governance, risk and compliance (GRC), and offers genuine scope to build deep specialist skills across the Microsoft Security Stack, Proofpoint, DNS filtering and incident response disciplines.

This role operates on a 24/7 security shift pattern, forming part of a rotating SecOps team that provides continuous, round-the-clock monitoring and response coverage. Shifts will include a mix of days, nights, weekends and public holidays on a rota basis. The role reports directly to, and is managed day-to-day by, the Bangalore SecOps Lead, who oversees scheduling, escalation and local team performance.

What We Offer

  • Fully sponsored professional certifications, including Microsoft, ISC2 and CompTIA credentials.
  • A structured, well-defined career development pathway from analyst through to senior engineer and security architect roles.
  • The opportunity to work with, and build deep expertise in, upper-quadrant enterprise security tooling used by  UK/US based global firms.
  • Exposure to a genuinely global client base and a collaborative, specialist security team.
  • A supportive environment that invests in continuous learning and long-term career growth, which particularly welcomes women into Cyber security.

EDUCATION AND EXPERIENCE

Essential Certifications 

  • A bachelor's degree in IT Security, Computer Science, Cyber Security or a closely related discipline.
  • CompTIA Security+ or ISC2 Certified in Cybersecurity (CC) (mandatory – candidates working toward one of these at final stage will also be considered).
  • Written and spoken English, including report writing, to a minimum of IELTS 6.0 or equivalent.

Preferred Certifications

Preference will be given to candidates who currently hold one or more of the following Microsoft Associate-level certifications:

  • SC-200 – Microsoft Certified: Security Operations Analyst Associate
  • SC-300 – Microsoft Certified: Identity and Access Administrator Associate
  • SC-401 – Microsoft Certified: Information Security Administrator Associate
  • SC-500 – Microsoft Certified: Cloud and AI Security Engineer Associate

Desirable Experience and Skills 

  • 3+ years' experience in a technical security role, ideally with recent hands-on experience of the Microsoft Security Stack.
  • Practical administration or operational experience with Proofpoint (or equivalent email security platform).
  • Experience operating DNS filtering / secure web gateway tooling (e.g. Cisco Umbrella, Zscaler, or similar).
  • Experience working within an ITSM or ticketing platform (e.g. ServiceNow, Jira Service Management) to manage security queues and SLAs.
  • Experience of network and application firewalls.
  • Working knowledge of technical security frameworks such as ISO 27001, NIST, SOC 2 and Cyber Essentials Plus.
  • Experience with Privileged Access Management (PAM) tools such as CyberArk, Entra or SailPoint.
  • Additional Microsoft or wider security certifications are an advantage.
  • Ability to learn new third-party security tooling quickly and thoroughly when required.
  • Active membership and engagement with a local chapter of ISC2, ISACA or a similar professional security body.
  • Ability to mentor and support the development of more junior team members.

KEY JOB ELEMENTS 

  • Manage cyber security incidents end to end, liaising with the wider SOC provider and client-facing teams throughout triage, containment, eradication and recovery.
  • Investigate and triage security alerts across email and public, private and hybrid cloud systems.
  • Carry out proactive threat hunting to identify indicators of compromise ahead of automated detection.
  • Administer and operate Proofpoint email security tooling, including Targeted Attack Protection (TAP), Email Protection, Threat Response Auto-Pull (TRAP) and browser isolation, and manage the ongoing tuning of policies and rules.
  • Operate and administer the Microsoft E5 security stack, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview and Microsoft Entra ID, to detect, investigate and respond to threats.
  • Monitor and maintain DNS filtering and web security controls, tuning policies to block malicious domains and reduce the organisation's external attack surface.
  • Own and progress security incidents and requests through the ticketing system, ensuring accurate documentation, timely updates and adherence to SLAs.
  • Manage vulnerability findings, prioritising and driving patching workloads against internal security standards and relevant local regulatory or legal requirements.
  • Maintain, monitor and remediate alerts from Data Loss Prevention (DLP) tooling.
  • Support technical forensic readiness and insider risk management activity.
  • Contribute to security policy, compliance and user security awareness activity.
  • Produce clear incident response, investigation and reporting documentation to a high professional standard.
  • Support the organisation's drive toward Zero Trust across all areas of the business.
  • Contribute to technical security control audits and KPI/management reporting.
  • Work a 24/7 rotating shift pattern to provide continuous SOC coverage, under the day-to-day management of the Bangalore SecOps Lead.

PERSON SPECIFICATION

  • Naturally curious with strong investigative instincts.
  • High levels of personal integrity and discretion.
  • Excellent attention to detail.
  • Self-motivated with a strong sense of ownership.
  • Calm and resilient under pressure.
  • Adaptable and eager to learn.
  • Comfortable operating within a 24/7 environment.
  • Methodical and disciplined in approach.
  • Positive team player with a collaborative attitude.
  • Consistently reliable, professional and dependable.
  • Committed to continuous personal development.

We are an equal opportunity employer and value diversity in our workforce. All qualified applicants will receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic under applicable law. We are committed to creating an inclusive environment where everyone can thrive.