Senior Advanced Cybersecurity Detection & Threat Intelligence Engineer

Posted 4 Days Ago
Be an Early Applicant
Hiring Remotely in Bengaluru, Bengaluru Urban, Karnataka, IND
In-Office or Remote
Senior level
Information Technology
The Role
Design, implement, and tune threat detections across SIEM, EDR/XDR, cloud, OT/ICS, and identity. Translate threat intelligence and IOCs into detection rules, hunt hypotheses, and SOAR automation. Manage IOC feeds and TIPs, improve telemetry coverage, onboard log sources, and own the full detection lifecycle from hypothesis through production deployment.
Summary Generated by Built In

Location: Remote
We are seeking a Sr. Advanced Cybersecurity Engineer based in India to serve as a detection and threat intelligence engineer within our Threat Detection & Response (TDR) program. This role focuses on detection engineering, threat intelligence operationalization, and SOAR automation across IT enterprises, cloud, OT/ICS, and identity environments. The ideal candidate will design and tune detection logic, drive security telemetry coverage improvements, build automated enrichment and detection workflows, and own the full detection development lifecycle from hypothesis through production deployment.

Responsibilities

Key Responsibilities

  • Design, implement, and continuously tune threat detections across SIEM, EDR/XDR, OT security platforms, and cloud-native security tooling.
  • Own the end-to-end detection engineering lifecycle — hypothesis development, rule authoring, validation, deployment, tuning, and retirement — aligned to MITRE ATT&CK across IT, OT, cloud, and identity environments.
  • Operationalize threat intelligence by translating finished intel, IOCs, and adversary TTPs into actionable detection rules, hunt hypotheses, and automated enrichment workflows.
  • Manage and maintain threat intelligence feeds and platforms, including ingestion, validation, confidence scoring, and expiration of IOC libraries.
  • Build, maintain, and improve SOAR automation playbooks, enrichment pipelines, and detection workflows to increase alert fidelity and reduce analyst toil.
  • Develop and maintain detection content for OT/ICS environments, including industrial protocol anomaly detection, Purdue model segmentation visibility, and OT-specific threat actor TTPs.
  • Improve security telemetry quality and coverage by collaborating with infrastructure, network, cloud, OT, and platform engineering teams to onboard new log sources and validate data fidelity.
Qualifications

Required Skills & Experience

  • Must reside in India — this role is approved for India-based candidates only. 
  • 7–10+ years of experience in cybersecurity with a focus on detection engineering, security operations, or threat intelligence.
  • Strong hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or QRadar — including rule authoring, query development, and data onboarding. 
  • Deep understanding of adversary tactics, techniques, and procedures with applied experience mapping detections to MITRE ATT&CK.
  • Hands-on experience developing detection rules, correlation logic, behavioral analytics, and threshold-based alerting across multiple telemetry sources. 
  • Demonstrated experience with SOAR platforms for building automated enrichment pipelines, detection workflows, and threat intel operationalization.
  • Strong scripting and automation skills in Python, PowerShell, or KQL for detection development, data parsing, and workflow automation.
  • Experience with threat intelligence platforms (TIP) for IOC lifecycle management, feed integration, and intel-to-detection operationalization. 
     

Preferred Qualifications 

  • Experience building or maturing a detection engineering program including detection backlog management, coverage gap analysis, and ATT&CK heatmap maintenance. 
  • Experience with OT/ICS security monitoring
  • Familiarity with threat intelligence integration and threat hunting methodologies
  • Familiarity with detection-as-code practices, version control for detection content, and automated rule testing pipelines
  • Knowledge of cloud-native security monitoring and identity telemetry. 
  • Relevant certifications such as GDAT, GCDE, GCIA, GCED, or equivalent credentials.
About Us

About Solstice Advanced Materials

Solstice Advanced Materials is a leading global specialty materials company that advances science for smarter outcomes. Solstice offers high-performance solutions that enable critical industries and applications, including refrigerants, semiconductor manufacturing, data center cooling, nuclear power, protective fibers, healthcare packaging and more. Solstice is recognized for developing next-generation materials through some of the industry's most renowned brands such as Solstice®, Genetron®, Aclar®, Spectra®, Fluka™, and Hydranal™. Partnering with over 3,000 customers across more than 120 countries and territories and supported by a robust portfolio of over 5,700 patents, Solstice’s approximately 4,000 employees worldwide drive innovation in materials science. For more information, visit Advanced Materials.


Skills Required

  • Must reside in India
  • 7-10+ years of experience in cybersecurity with focus on detection engineering, security operations, or threat intelligence
  • Hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or QRadar (rule authoring, query development, data onboarding)
  • Deep understanding of adversary tactics, techniques, and procedures and mapping detections to MITRE ATT&CK
  • Experience developing detection rules, correlation logic, behavioral analytics, and threshold-based alerting across multiple telemetry sources
  • Experience with SOAR platforms for building automated enrichment pipelines, detection workflows, and threat intel operationalization
  • Strong scripting and automation skills in Python, PowerShell, or KQL for detection development, data parsing, and workflow automation
  • Experience with threat intelligence platforms (TIP) for IOC lifecycle management, feed integration, and intel-to-detection operationalization
  • Experience building detection content for OT/ICS environments including industrial protocol anomaly detection
  • Experience building or maturing a detection engineering program, coverage gap analysis, and ATT&CK heatmap maintenance
  • Familiarity with threat intelligence integration, threat hunting methodologies, and detection-as-code practices
  • Familiarity with version control for detection content and automated rule testing pipelines
  • Knowledge of cloud-native security monitoring and identity telemetry
  • Relevant certifications such as GDAT, GCDE, GCIA, GCED, or equivalent
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
85 Employees
Year Founded: 2001

What We Do

Solstice, part of Kin + Carta, is a modern software engineering firm that helps Fortune 500 companies seize new opportunities through world-changing digital solutions. As strategists and consultants, we help organizations evolve their digital strategy to solve mission-critical problems. As designers and developers, we build incredible hardware and software solutions that transcend a standalone product and transform an organization’s relationship with its customers. As instructors and coaches, we help companies transform from the inside out by adopting a high-speed culture of innovation. We’re strategists, researchers, designers, and engineers hell-bent on changing the way the world does business. We’re headquartered in Chicago and have delivery offices in New York, London, and Buenos Aires. For more information about Solstice, visit solstice.com

Similar Jobs

Cloudflare Logo Cloudflare

Customer Engineer, India (Based in Mumbai)

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
India
4400 Employees

Boomi Logo Boomi

Senior Specialist - Accounts Receivable - Hyderabad

Cloud • Information Technology • Productivity • Software • Automation
Remote
India
2200 Employees

Vercel Logo Vercel

Senior Accountant

Artificial Intelligence • Cloud • Software
Easy Apply
Remote or Hybrid
India
4M-5M Annually

Vercel Logo Vercel

Sr. Manager, Accounting (India)

Artificial Intelligence • Cloud • Software
Easy Apply
Remote or Hybrid
India
7M-9M Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account