Creative ITC
Posted 1w ago

Security Engineer – Security Operations (SecOps)

Creative ITC
Bengaluru, Karnataka, India
OnsiteFull Time
Responsibilities
  • managing incidents
  • investigating alerts
  • administering tooling
Requirements
  • Bachelor's degree in a related field
  • Security+ or ISC2 CC
  • English proficiency, and 3+ years of technical security experience
  • Microsoft Security Stack
  • Proofpoint
  • DNS filtering, and incident response experience preferred
Technical tools mentioned
Microsoft Security StackProofpointCisco UmbrellaZscalerServiceNowJira Service ManagementCyberArkEntraSailPointMicrosoft SentinelMicrosoft Defender XDRMicrosoft PurviewMicrosoft Entra IDData Loss Prevention (DLP)Microsoft E5

Job description

POSITION SUMMARY


We are looking for a Security Engineer to join our specialist Security Operations team in Bangalore. This is a hands-on, technical role covering the day-to-day operation, administration and continuous improvement of the security tooling that protects both our clients and our own enterprise environment. The successful candidate will work a 24/7 shift rotation as part of our follow-the-sun SOC model, reporting to and managed by the Bangalore SecOps Lead. The role combines technical operations with elements of governance, risk and compliance (GRC), and offers genuine scope to build deep specialist skills across the Microsoft Security Stack, Proofpoint, DNS filtering and incident response disciplines.


This role operates on a 24/7 security shift pattern, forming part of a rotating SecOps team that provides continuous, round-the-clock monitoring and response coverage. Shifts will include a mix of days, nights, weekends and public holidays on a rota basis. The role reports directly to, and is managed day-to-day by, the Bangalore SecOps Lead, who oversees scheduling, escalation and local team performance.


What We Offer

  • Fully sponsored professional certifications, including Microsoft, ISC2 and CompTIA credentials.
  • A structured, well-defined career development pathway from analyst through to senior engineer and security architect roles.
  • The opportunity to work with, and build deep expertise in, upper-quadrant enterprise security tooling used by  UK/US based global firms.
  • Exposure to a genuinely global client base and a collaborative, specialist security team.
  • A supportive environment that invests in continuous learning and long-term career growth, which particularly welcomes women into Cyber security.


EDUCATION AND EXPERIENCE


Essential Certifications 

  • A bachelor's degree in IT Security, Computer Science, Cyber Security or a closely related discipline.
  • CompTIA Security+ or ISC2 Certified in Cybersecurity (CC) (mandatory – candidates working toward one of these at final stage will also be considered).
  • Written and spoken English, including report writing, to a minimum of IELTS 6.0 or equivalent.


Preferred Certifications

Preference will be given to candidates who currently hold one or more of the following Microsoft Associate-level certifications:

  • SC-200 – Microsoft Certified: Security Operations Analyst Associate
  • SC-300 – Microsoft Certified: Identity and Access Administrator Associate
  • SC-401 – Microsoft Certified: Information Security Administrator Associate
  • SC-500 – Microsoft Certified: Cloud and AI Security Engineer Associate


Desirable Experience and Skills 

  • 3+ years' experience in a technical security role, ideally with recent hands-on experience of the Microsoft Security Stack.
  • Practical administration or operational experience with Proofpoint (or equivalent email security platform).
  • Experience operating DNS filtering / secure web gateway tooling (e.g. Cisco Umbrella, Zscaler, or similar).
  • Experience working within an ITSM or ticketing platform (e.g. ServiceNow, Jira Service Management) to manage security queues and SLAs.
  • Experience of network and application firewalls.
  • Working knowledge of technical security frameworks such as ISO 27001, NIST, SOC 2 and Cyber Essentials Plus.
  • Experience with Privileged Access Management (PAM) tools such as CyberArk, Entra or SailPoint.
  • Additional Microsoft or wider security certifications are an advantage.
  • Ability to learn new third-party security tooling quickly and thoroughly when required.
  • Active membership and engagement with a local chapter of ISC2, ISACA or a similar professional security body.
  • Ability to mentor and support the development of more junior team members.


KEY JOB ELEMENTS 

  • Manage cyber security incidents end to end, liaising with the wider SOC provider and client-facing teams throughout triage, containment, eradication and recovery.
  • Investigate and triage security alerts across email and public, private and hybrid cloud systems.
  • Carry out proactive threat hunting to identify indicators of compromise ahead of automated detection.
  • Administer and operate Proofpoint email security tooling, including Targeted Attack Protection (TAP), Email Protection, Threat Response Auto-Pull (TRAP) and browser isolation, and manage the ongoing tuning of policies and rules.
  • Operate and administer the Microsoft E5 security stack, including Microsoft Sentinel, Microsoft Defender XDR, Microsoft Purview and Microsoft Entra ID, to detect, investigate and respond to threats.
  • Monitor and maintain DNS filtering and web security controls, tuning policies to block malicious domains and reduce the organisation's external attack surface.
  • Own and progress security incidents and requests through the ticketing system, ensuring accurate documentation, timely updates and adherence to SLAs.
  • Manage vulnerability findings, prioritising and driving patching workloads against internal security standards and relevant local regulatory or legal requirements.
  • Maintain, monitor and remediate alerts from Data Loss Prevention (DLP) tooling.
  • Support technical forensic readiness and insider risk management activity.
  • Contribute to security policy, compliance and user security awareness activity.
  • Produce clear incident response, investigation and reporting documentation to a high professional standard.
  • Support the organisation's drive toward Zero Trust across all areas of the business.
  • Contribute to technical security control audits and KPI/management reporting.
  • Work a 24/7 rotating shift pattern to provide continuous SOC coverage, under the day-to-day management of the Bangalore SecOps Lead.


PERSON SPECIFICATION

  • Naturally curious with strong investigative instincts.
  • High levels of personal integrity and discretion.
  • Excellent attention to detail.
  • Self-motivated with a strong sense of ownership.
  • Calm and resilient under pressure.
  • Adaptable and eager to learn.
  • Comfortable operating within a 24/7 environment.
  • Methodical and disciplined in approach.
  • Positive team player with a collaborative attitude.
  • Consistently reliable, professional and dependable.
  • Committed to continuous personal development.


We are an equal opportunity employer and value diversity in our workforce. All qualified applicants will receive consideration for employment without regard to race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, age, disability, veteran status, or any other protected characteristic under applicable law. We are committed to creating an inclusive environment where everyone can thrive.

About Creative ITC

Provides managed cloud infrastructure and cybersecurity for complex IT environments.

Year founded
2006
Employees
166
Organization type
Private
Latest investment
Private Equity (2024) — led by LDC
Headquarters
GB

Similar jobs

Security Engineer roles near Bengaluru, Karnataka
11h
Save
Mark Applied
Hide
Security Engineer II (AI)
Bengaluru, Karnataka, India
HybridFull Time
SIXT
SIXTFrankfurt Stock Exchange: SIX2: Global provider of vehicle rental and car sharing services.
3+ YOEBachelor's or Master's degree in computer science or related field; 3–5 years of security engineering experience; AI security, risk assessment, communication, collaboration, and observability experience.
regular expressions, CVSS, LLMs, RAG, EU AI Act, GDPR
16h
Save
Mark Applied
Hide
Security Engineer
Bengaluru or Bangalore
HybridFull Time
The Walt Disney Company
The Walt Disney CompanyNYSE: DIS: Produces media content and operates global theme parks.
8+ YOE8+ years engineering large-scale Active Directory environments; expertise in architecture, trusts, replication, DNS, PKI, multi-forest design, security hardening, RadiantLogic, RBAC, PIM, and PAM. Bachelor's degree or equivalent experience.
Active Directory, RadiantLogic Virtual Directory Services, RBAC, Privileged Identity Management (PIM), Privileged Access Management (PAM), Entra ID, Azure AD, DNS, PKI, Privileged Access Workstations (PAW)
16h
Save
Mark Applied
Hide
Senior Security Engineer
Bengaluru, Karnataka, India
HybridFull Time
Thomson Reuters
Thomson ReutersNASDAQ: TRI: Provides professional software, data, and news services globally.
5+ YOE5+ years in security, software, or DevSecOps engineering; bachelor's degree or equivalent; multi-cloud and on-premises experience; hands-on vulnerability remediation, security controls, and process optimization.
AWS, Azure, GCP, OCI, SAST, SCA, CVSS, EPSS, CISA KEV, CI/CD, WAF
16h
Save
Mark Applied
Hide
Security Engineer – AWS Security Incident Response, Cloud Security, AI Security, EDR & SIEM
Bangalore, Karnataka, India
OnsiteFull Time
Alcon
AlconNYSE: ALC: Manufactures ophthalmic surgical equipment and vision care products.
5+ YOERequires 5–7 years in SOC, incident response, cloud security, SIEM, or EDR/XDR; AWS security expertise; Microsoft Sentinel and Defender XDR experience; scripting or query skills; and strong incident documentation.
AWS, GuardDuty, Security Hub, CloudTrail, Config, IAM, CloudWatch, Inspector, Microsoft Sentinel, MITRE ATT&CK, Microsoft Defender XDR, Microsoft Security Copilot, SOAR, KQL, PowerShell, Python
1d
Save
Mark Applied
Hide
Sr. Security Engineer, Stores Application Security
Bengaluru, Karnataka, India
OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOERequires 5+ years in application or systems security, a BS in Computer Science or Information Security, programming skills, threat modeling, code review, AWS, and technical leadership experience.
Java, Python, JavaScript, Perl, Bash, Ruby, PowerShell, AWS, Microsoft?
1d
Save
Mark Applied
Hide
Senior Security Engineer - Customer Engineering
Bengaluru, Karnataka, India
OnsiteFull Time
Harness
Harness: AI-powered platform for automating software delivery and DevOps.
4+ YOERequires 4–6 years in security engineering or related work, coding and automation skills, API and AI security expertise, black-box penetration testing, threat hunting, and enterprise customer communication.
ModSecurity, WAF, REST, GraphQL, gRPC, OAuth 2.0, OIDC, JWT, Burp Suite, Postman, OWASP ZAP, Python, Akamai, Cloudflare, LLMs, MITRE ATT&CK, MITRE ATLAS
1d
Save
Mark Applied
Hide
Senior Security Engineer II - Confluent
Bangalore, Karnataka, India
RemoteFull Time
IBM
IBMNew York Stock Exchange: IBM: Global technology providing enterprise software, cloud, and consulting.
8+ YOEBachelor's degree and 8+ years of relevant experience in security detection and response, telemetry, incident response, logging, security event management, distributed teams, and scripting.
AWS, GCP, Azure
1d
Save
Mark Applied
Hide
Sr. Engineer – Security Engineering
Bengaluru, Karnataka, India
HybridFull Time
CBTS
CBTS: Provider of managed cloud, infrastructure, and cybersecurity services.
Cybersecurity experience with technical ownership of security solutions across applications, cloud, and infrastructure; ability to manage security tools, assess vulnerabilities, respond to incidents, and mentor engineers.
IDS/IPS, SIEM