Title: Sr Technical Lead-Cybersecurity
Area(s) of responsibility
We are seeking an experienced Cybersecurity professional with expertise in Security Monitoring, Detection Engineering, SIEM, EDR, Cloud Security, Threat Detection, Security Data Pipeline Management, and Security Platform Administration. The candidate will be responsible for designing, implementing, administering, and optimizing enterprise security platforms including SentinelOne, Google SecOps, Splunk Reporting, BindPlane or CRIBL, Wiz, and GitHub, while driving security visibility, threat detection, automation, reporting, cloud security governance, and operational excellence across the enterprise.
Key Responsibilities
- Lead the administration, engineering, implementation, and support of SentinelOne, Google SecOps, Splunk, BindPlane or CRIBL, Wiz, and GitHub platforms.
- Design and manage enterprise-wide security monitoring, threat detection, alerting, visibility, and response capabilities.
- Develop and optimize detection use cases, correlation rules, threat hunting strategies, and security monitoring processes.
- Administer and support Google SecOps SIEM, including log onboarding, parser management, detection engineering, dashboards, investigations, and reporting.
- Manage and optimize security log collection, normalization, filtering, routing, and ingestion through BindPlane.
- Create and maintain operational, compliance, executive, and security reporting dashboards using Splunk.
- Administer SentinelOne EDR/XDR platform, including policy management, threat detection, incident investigation, agent health monitoring, and endpoint security governance.
- Lead cloud security initiatives using Wiz, including cloud posture management, risk assessments, vulnerability management, compliance monitoring, and security recommendations across multi-cloud environments.
- Manage GitHub repositories, access controls, branch protection policies, secret scanning, code security, and DevSecOps integrations.
- Integrate security platforms with ITSM, CMDB, Cloud, IAM, EDR, CI/CD, SOAR, and vulnerability management solutions.
- Perform threat analysis, root cause investigations, security incident support, and remediation coordination.
- Drive security automation initiatives to improve operational efficiency and reduce manual effort.
- Ensure platform availability, upgrades, patching, health monitoring, and performance optimization.
- Collaborate with SOC, Cloud, Infrastructure, Application, and Security Engineering teams to enhance enterprise security posture.
- Develop SOPs, runbooks, dashboards, reporting frameworks, and operational documentation.
- Support regulatory, audit, compliance, and governance activities through evidence collection and reporting.
- Provide technical leadership, mentorship, and guidance to security analysts and engineering teams.
Required Skills
Security Platforms
- SentinelOne EDR/XDR
- Google SecOps
- Splunk (Reporting & Dashboarding)
- BindPlane, Cribl added value
- Wiz Cloud Security Platform
- GitHub Administration
Technical Expertise
- SIEM Engineering & Security Monitoring
- Detection Engineering & Threat Hunting
- EDR/XDR Administration
- Cloud Security & CNAPP
- Security Log Management
- Security Analytics & Reporting
- Incident Investigation & Threat Detection
- Vulnerability & Risk Management
- DevSecOps & Secure SDLC, CI/CD
- Security Automation & Integration
- Security Operations & Governance
- Compliance & Audit Support