Jobiglo

No results.

Senior Information Security Engineer

ZinCaT Technology · Colombo

New
Senior 🇬🇧 English
Microsoft Sentinel Microsoft Defender for Endpoint SOAR KQL Python MITRE ATT&CK Azure AWS

Job description

About the role

The Senior Information Security Engineer leads advanced threat detection, investigation and major cyber‑incident response for a fast‑growing global SaaS business. Reporting to the SOC Manager, the role combines hands‑on operational work with ownership of SOC transformation, automation and analyst enablement.

Key responsibilities

  • Lead end‑to‑end response for high‑priority cyber incidents, acting as senior technical authority from triage through containment, eradication and post‑incident review.
  • Perform deep‑dive forensic, malware and log investigations, applying hypothesis‑driven analysis to uncover hidden threats.
  • Design and deliver SOC maturity initiatives, including detection engineering, use‑case development, workflow automation and tooling consolidation.
  • Build, tune and continuously improve SIEM detection logic and correlation rules (preferably Microsoft Sentinel) to reduce false positives.
  • Conduct intelligence‑led threat hunts using MITRE ATT&CK and emerging TTPs, identifying gaps before exploitation.
  • Champion automation, SOAR playbooks and AI‑assisted tooling to increase analyst efficiency.
  • Mentor Tier 1/2 analysts, coaching investigative techniques and fostering a culture of curiosity.
  • Maintain expertise across SOC tooling (SIEM, EDR, SOAR, cloud security) and contribute to tooling strategy and budget planning.

Required profile

  • 5+ years experience in a Security Operations Center or cyber‑defense function within a fast‑growth organization.
  • Proven track record of building SOC capability and delivering transformation programs (detection engineering, automation, process redesign).
  • Hands‑on experience leading major cyber‑incident responses and producing executive‑level post‑incident reports.
  • Strong analytical mindset with demonstrated curiosity for root‑cause analysis and emerging threat techniques.
  • Excellent written and verbal communication skills, able to brief technical and executive stakeholders during live incidents.

Required skills

  • Microsoft Sentinel (SIEM)
  • Microsoft Defender for Endpoint (EDR)
  • SOAR platforms and playbook development
  • KQL query language
  • Python scripting
  • MITRE ATT&CK framework
  • Cloud security (Azure and AWS)
  • Automation and AI‑enabled detection tools

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec ZinCaT Technology.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

Apply now →

By continuing, you accept our terms of use.

Already have an account? Login

A question about this job?

Ask it here: you will get the full job summary by e-mail, right away.

💬 Chat with us on Telegram

Published 4 hours ago

Expires 1 month from now

3 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

ZinCaT Technology

Colombo