Security Engineer – AWS Security Incident Response, Cloud Security, AI Security, EDR & SIEM
Job Summary
Summary of Position:
Responsible forplanning managing and implementingcybersecurity and IT compliancetoensure effective enterprise protection and innovation intheorganization.
We are looking for an intermediate-level Security Engineer who can support Alcons Cyber Incident Response and Threat Management function across AWS cloud security SIEM monitoring EDR/XDR operations cloud incident response and emerging AI security risks. This person should be hands-on practical and comfortable working with SOC Cloud Infrastructure Identity and application teams to improve threat detection response and security posture.
Role Expectations:
- Monitor investigate and respond to security alerts across cloud endpoint identity email SaaS and enterprise environments.
- Take ownership of assigned incidents from triage through containment remediation support documentation and lessons learned.
- Work with internal teams and external SOC partners to ensure incidents are handled consistently and within defined operational expectations.
- Contribute to detection improvements playbook maturity operational documentation and knowledge sharing across the SOC team.
Key Responsibilities:
1. AWS Security Incident Response & Cloud Security
- Investigate AWS security alerts suspicious activity misconfigurations and potential compromise scenarios using available cloud logs and security tooling.
- Review AWS security findings from services such as GuardDuty Security Hub CloudTrail Config IAM CloudWatch Inspector and related monitoring sources.
- Support containment and remediation activities for cloud security incidents in coordination with Cloud Engineering and application owners.
- Identify gaps in cloud logging monitoring alerting access control and security posture and recommend practical improvements.
- Assist in building and maintaining cloud incident response runbooks investigation steps and escalation procedures.
- Enhance incident detection and response capabilities for Cloud platforms.
2. SIEM Monitoring & Detection Engineering
- Work on Microsoft Sentinel and other SIEM-related monitoring activities to detect investigate and correlate threats across multiple data sources.
- Create review and tune SIEM use cases to improve alert quality and reduce false positives.
- Support onboarding and validation of important log sources including cloud identity endpoint email firewall SaaS and application logs.
- Develop dashboards basic reporting and operational metrics to improve visibility for SOC and leadership stakeholders.
- Map detections and investigation logic to common attacker behaviors using MITRE ATT&CK where applicable.
3. EDR / XDR Operations
- Investigate EDR/XDR alerts from platforms such as Microsoft Defender XDR and other endpoint security tools.
- Perform endpoint triage device isolation support IOC validation malware investigation and remediation coordination.
- Identify endpoints missing security coverage and work with responsible teams to support remediation and visibility improvement.
- Support policy tuning alert validation and operational improvements to strengthen endpoint detection and response.
- Coordinate with Infrastructure Desktop Engineering and Vulnerability Management teams where endpoint issues require ownership outside SOC.
4. AI Security & Secure AI Operations
- Support security monitoring and investigation of AI-related risks such as unauthorized AI usage data leakage prompt injection model misuse risky plugins/connectors and AI-assisted phishing or social engineering.
- Assist in defining practical AI security guardrails for SOC usage including access control logging acceptable use data handling and escalation criteria.
- Contribute to AI security incident response workflows and help document how AI-related security events should be triaged and escalated.
- Support secure use of Microsoft Security Copilot and other AI-enabled security tools by helping validate use cases risks controls and operational logging needs.
- Stay current on AI threat trends and translate them into practical SOC monitoring and response actions.
5. Incident Response Threat Hunting & Continuous Improvement
- Perform structured incident analysis including scope identification timeline review evidence collection containment recommendations and post-incident documentation.
- Participate in threat hunting and proactive detection improvement activities across cloud endpoint identity and SIEM data.
- Create and maintain SOC knowledge articles incident handling guides detection notes and runbooks.
- Support internal and external audit requests by providing clear operational evidence where applicable.
- Identify automation opportunities using SOAR scripting KQL PowerShell Python or cloud-native capabilities to reduce repetitive manual effort.
Key Requirements/Minimum Qualifications:
- 57 years of experience in SOC operations incident response cloud security SIEM engineering EDR/XDR operations or a related cybersecurity role.
- Hands-on experience with AWS security concepts including IAM logging monitoring network security encryption and incident investigation.
- Working knowledge of AWS security services such as GuardDuty Security Hub CloudTrail Config Inspector IAM and CloudWatch.
- Experience with SIEM tools preferably Microsoft Sentinel including alert investigation KQL/log analysis rule tuning and dashboard/reporting support.
- Experience with EDR/XDR platforms preferably Microsoft Defender XDR including endpoint investigation containment and remediation coordination.
- Support secure adoption of AI capabilities by identifying security risks monitoring misuse scenarios and helping define security guardrails.
- Good understanding of incident response lifecycle threat hunting common attack techniques and MITRE ATT&CK.
- Basic scripting or query skills using KQL PowerShell Python or similar technologies.
- Good written communication skills with the ability to document incidents actions taken findings and recommendations clearly.
Preferred Qualifications
- AWS Certified Security Specialty AWS Solutions Architect Associate or equivalent cloud security certification.
- Microsoft SC-200 SC-100 AZ-500 GCIH GCIA or similar security certifications.
- Experience working in a global SOC or managed security operations model.
- Exposure to Microsoft Security Copilot SOAR platforms threat intelligence platforms or automation workflows.
- Experience in regulated environments such as healthcare life sciences or global enterprise operations.
Work hours: 4 PM to 1 AM IST
Relocation assistance: Yes
Employment Scams:Alcon is aware of employment scams which make false use of our company name or leaders names to defraud job seekers. Alcon does not offer any positions without interview and never asks candidates for money. All our current job openings are displayed here on the Careers section of our website where you can search for open positions and apply directly.
If you have encountered a job posting or been approached with a job offer that you suspect may be fraudulent we strongly recommend you do not respond send money or personal information and check our website for current job openings.
ATTENTION: Current Alcon Employee/Contingent Worker
If you are currently an active employee/contingent worker at Alcon please click the appropriate link below to apply on the Internal Career site.
Find Jobs for Contingent Worker
Alcon is an Equal Opportunity Employer and takes pride in maintaining a diverse environment. We do not discriminate in recruitment hiring training promotion or other employment practices for reasons of race color religion gender national origin age sexual orientation gender identity marital status disability or any other reason.
Required Experience:
IC
About Company
Our mission is to provide innovative vision products that enhance quality of life by helping people see better. From vision research to eye health, learn more at Alcon.com.