Thank you for your application. Your profile and application details have been forwarded to our HR department.
IT Security Junior Engineer/Engineer Goa, India | Full-Time
This position is responsible for supporting the organization’s security monitoring, incident response, and vulnerability management activities. The role will primarily focus on SOC operations using Wazuh, including monitoring security alerts, reviewing logs, validating incidents, escalating risks, and supporting response actions for issues such as unauthorized access, malware, phishing, suspicious activity, and possible data exposure. You will also support application and server vulnerability assessment activities, including reviewing web applications, APIs, mobile applications, Linux and Windows servers, validating scan results, preparing remediation guidance, and verifying fixes.
Responsibilities:
- Monitor security events and alerts using Wazuh and other tools such as EDR, firewall, email security, cloud, endpoint, and network security platforms
- Analyze SIEM alerts, logs, agent data, vulnerability findings, file integrity monitoring events, authentication logs, and security events to identify suspicious activity, unauthorized access, malware, phishing attempts, data exposure, and policy violations
- Perform initial alert validation, severity assessment, false-positive review, and incident prioritization based on alert context, affected assets, risk level, and business impact
- Support incident containment and response actions such as blocking malicious indicators, disabling compromised accounts, isolating affected systems, removing malicious emails, revoking suspicious sessions, and validating remediation
- Track incidents from detection to closure and ensure timely follow-up on investigation, remediation, and preventive actions
- Perform application vulnerability assessments for web applications, APIs, and mobile applications using automated tools and manual verification where required
- Perform server vulnerability assessments on Linux and Windows servers to identify missing patches, insecure configurations, exposed services, weak protocols, and known vulnerabilities
- Review vulnerability scan results, validate findings, remove false positives, assign severity, and prepare clear remediation guidance for application and server teams
- Track vulnerability remediation status, follow up with owners, verify fixes through retesting, and maintain vulnerability assessment reports
- Support SIEM rule tuning, alert quality improvement, false-positive reduction, detection use-case creation, dashboard review, and security monitoring improvements
- Assess the security posture of third-party tools and services before adoption to identify risks and ensure compliance with organizational policies
- Research emerging security topics and new attack vectors to support continuous improvement of security monitoring and vulnerability assessment practices
- Manage assigned timelines, deadlines, and expectations, including coordination with internal teams and customer-facing stakeholders where required
Technical Qualification:
- Experience in SIEM tools for security alert monitoring, log analysis, agent monitoring, vulnerability detection, file integrity monitoring, and dashboard review
- Experience of application vulnerability assessment for web applications, APIs, and mobile applications using tools such as Burp Suite, OWASP ZAP, MobSF, and related security testing tools
- Proficient in understanding SOC operations, security monitoring, incident response, alert triage, escalation, and incident documentation
- Proficient in reviewing and analyzing logs from Windows, Linux, firewall, endpoint, email security, cloud, and network security platforms
- Proficient in validating vulnerability scan results, identifying false positives, assigning severity, preparing remediation recommendations, and verifying fixes through retesting
- Proficient in preparing clear security reports, incident summaries, vulnerability assessment reports, and remediation follow-up updates for technical and non-technical stakeholders
- Knowledge of common security events such as failed logins, privilege changes, malware alerts, suspicious process execution, phishing attempts, unauthorized access, and data exposure indicators
- Knowledge of the incident response lifecycle, including detection, analysis, containment, remediation, recovery, and lessons learned
- Knowledge of server vulnerability assessment for Linux and Windows servers using tools such as Nessus, Rapid7 InsightVM, Wazuh vulnerability detection, or similar vulnerability scanning tools
- Knowledge of OWASP Top 10, common application security issues, exploitation concepts, risk rating, and remediation guidance
- Understanding of network security concepts, including TCP/IP, DNS, HTTP/HTTPS, VPN, firewall rules, ports, protocols, and common attack techniques
- Understanding of operating system hardening, patch management, insecure configurations, exposed services, weak protocols, and secure baseline checks
- Familiarity with cloud security fundamentals for AWS, Azure, or GCP, including basic logging, identity, access, and configuration review concepts
Personal Skills:
- Ability to communicate well verbally and in writing with various levels from junior developers to executive staff
- Ability to stay calm, professional in troubleshooting and resolving support issues
- Ability to quickly learn new concepts and software
- Ability to work in a team environment
- Ability to adjust tasks and schedule and adapt to changing priorities
- Ability to analyze security issues carefully and make practical decisions based on risk and impact
- Ability to take ownership of assigned work, follow up with teams, and ensure security issues are tracked to closure
Education and Work Experience:
- Background in Computer Science, Information Technology, Cybersecurity, or a related discipline is preferred
- The candidate should have over 1 year of relevant work experience in IT security, SOC operations, vulnerability assessment, or a related area
- Certification in IT Security such as CEH, CompTIA Security+, Certified SOC Analyst (CSA), or any related certification will be an added advantage
If that's not your area, check our other 7 Open Positions
If that's not your area, check our other 7 Open Positions
IT Security Junior Engineer/Engineer
Apply online