Padmi
Perforce logo
Perforce

DevOps automation · Version control (P4)

Sr. Security Engineer (OA)

India · HybridPosted 2 months ago
SecuritySeniorFull Time
Apply at Perforce

Opens the source posting on jobs.lever.co

Source description

About the role

View original

• Lead the end to end SOC alerts workflow. • Operationalize the Regular Incident Response Plan and Major Incident Response Plan across teams. • Own SOC tools and automation (with Google SecOps as the primary SIEM, SOAR, Google Threat Intelligence, Gemini AI integrations and Jira as the authoritative system of record). • Coordinate with our managed SOC provider (Tier 1) to ensure, low noise of false positives, high quality triage, implementation of playbooks, clean escalations, and measurable MTTD/MTTR improvements. • This is a hands on leadership role: you will design workflows and playbooks, lead investigations and RCA for high impact incidents, and mentor SOC Engineers and Analysts as we scale from a lean Phase 1 SOC (~2–3 FTE) to an AI enabled mature operations. • Own the SOC alert lifecycle: Alert Ingestion → Triage → Routing → Investigation → Determination → Reporting. • Act as Major Incident Manager (MIM) for security events meetings. • Ensure strict adherence to Perforce’s Incident Response Policies for regular incidents • Maintain the SOC Charter, operating model, and guardrails as per the Operationalization Plan, Own the SOC RACI and routing matrix across SOC, CloudOps, IT, Engineering, and the provider.

Tools, Telemetry & Automation

• Lead design, configuration, and continuous tuning of Google SecOps (Chronicle SIEM + SOAR + case management, Google Threat Intelligence and Gemini integrations) as the primary detection and workflow platform. • Design and implement automation to: o Enrich alerts (asset context, user context, historical activity). o Trigger Jira tickets and playbooks based on Google SecOps cases. o Support SLA monitoring and notifications (MTTR, remediation timeframes). • Partner with the Corporate Security on CI/CD and IaC security automation where incident workflows intersect with pipelines (e.g., auto ticketing, auto asset tagging, config drift etc..).

Playbooks, IRP/MIRP Implementation & Quality

• Define and own a core set of playbooks aligned to IRP/MIRP. o Cloud misconfiguration / CSPM alerts. o Endpoint malware / suspicious activity. o Identity/credential compromise. o Application / product security alerts. o External threat reports via Security Mailbox or any other threat feeds. • Oversee False Positives and Exceptions processes. Metrics, Reporting & Continuous Improvement

• Own SOC KPIs and operational metrics • Produce and present the Monthly SOC Summary Report • Lead RCA and post incident reviews • Champion a culture of continuous improvement

Team Leadership & Stakeholder Management

• Act as day to day lead and senior escalation point for SOC Engineers and Analysts in Pune. • Coach and mentor team members on process adherence and effective alert handling. • Build strong partnerships with vendors, partners and stake holders, Serve as primary liaison with the Tier 1 provider.

More at Perforce

Related open roles

View all roles