- Manage and optimize policies in CrowdStrike
- Investigate and respond to endpoint alerts (malware, suspicious behaviour, lateral movement)
- Perform root cause analysis and prevent recurrence
- Improve detection coverage using behavioural rules and threat intelligence
- Secure user lifecycle management via JumpCloud
- Enforce:
- MFA across all systems
- Least privilege access
- Device trust policies
- Design and execute periodic access reviews
- Investigate identity-related incidents (account compromise, privilege misuse)
- Audit and secure SaaS platforms (Google Workspace, Slack, Zoom, etc.)
- Identify and remediate:
- Over-permissioned users
- Risky OAuth integrations
- Public data exposure
- Define SaaS security baselines and governance controls
- Own the full incident lifecycle:
- Detection → Triage → Containment → Recovery → RCA
- Build and maintain incident response playbooks
- Partner with Service Desk for rapid containment actions
- Continuously improve response time and accuracy
- Automate:
- User offboarding (access revocation + device lockdown)
- Alert-driven responses (via EDR and identity tools)
- Access reviews and compliance checks
- Reduce manual effort and improve consistency across security operations
- Correlate signals from: CrowdStrike (endpoint) , ManageEngine OpManager (infra/network) and SaaS audit logs
- Build meaningful dashboards and alerts
- Improve signal-to-noise ratio (reduce alert fatigue)
- Define and enforce:
- Endpoint hardening standards
- Identity and access policies
- Incident response procedures
- Support audits (ISO/SOC2 if applicable)
- Ensure continuous improvement of security posture
Requirements
- Strong hands-on experience with:
CrowdStrike (or similar EDR like SentinelOne, Defender)
JumpCloud / Okta / Azure AD - Real-world incident response experience (not just theoretical SOC work)
- Deep understanding of:
Endpoint attack techniques
Identity-based attacks
SaaS security risks
- Experience with scripting (Python / Bash / PowerShell)
- Ability to automate workflows and integrate tools
- Strong problem-solving and system thinking approach
- MITRE ATT&CK framework understanding
- Endpoint detection and response concepts
- Identity & access management principles (SSO, MFA, RBAC)
- 6-10 years in Security Engineering / Blue Team / Endpoint Security
- Experience in SaaS-heavy or cloud-first environments preferred
Skills Required
- Strong hands-on experience with CrowdStrike or a similar EDR such as SentinelOne or Microsoft Defender
- Strong hands-on experience with JumpCloud, Okta, or Azure AD
- Real-world incident response experience
- Deep understanding of endpoint attack techniques
- Deep understanding of identity-based attacks
- Deep understanding of SaaS security risks
- Scripting experience with Python, Bash, or PowerShell
- Ability to automate workflows and integrate security tools
- Understanding of the MITRE ATT&CK framework
- Understanding of endpoint detection and response concepts
- Understanding of identity and access management principles, including SSO, MFA, and RBAC
- 6-10 years of experience in Security Engineering, Blue Team, or Endpoint Security
- Experience in SaaS-heavy or cloud-first environments
What We Do
We are one of India’s most exciting & fast-growing mobile gaming companies. Founded in 2014, and creating a global mobile gaming landscape in partnership with Modern Times Group (MTG), our vision is to create simple, impactful casual game experiences at a massive scale. Since our inception, we have built a worldwide network of chart-topping games, and powerful tech & analytics infrastructure to turbocharge their growth. Our product portfolio consists of evergreen hits like Daily Themed Crossword, WordTrip, WordJam, WordWars, WordTrek and Solitaire. Visit us at www.playsimple.in to know more. Recent news about PlaySimple: https://techcrunch.com/2021/07/02/swedish- gaming-giant-acquires-indiaplaysimple-for-360-million/









