hirly

Apply with hirly

IT Security Engineer

Rootquotient Technologies · Chennai, India

Upload your resume to see how well you match this job — free, in seconds, no account needed.

Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.

IT Security Engineer Location: Chennai, India | Experience: 2–4 years About the Role Rootquotient is hiring its first dedicated security team member to own day-to-day security operations and strengthen our existing EDR/XDR setup. You’ll investigate threats, keep endpoints secure, improve cloud and identity security, and maintain audit readiness while helping engineering teams ship securely. You’ll also explore practical AI-assisted and agentic workflows for alert investigation, evidence collection, and routine security checks, with human oversight for critical actions. Reporting to [IT/Engineering Head], you’ll work closely with engineering, IT, external auditors, and our security vendors. Your scope and level of ownership will reflect your experience, as outlined below. Role Expectations

  • Independently manage SentinelOne EDR operations across approximately 150 macOS endpoints, ensuring endpoint compliance.
  • Tune SentinelOne policies with vendor support, create custom S1QL detection rules, and manage exceptions to reduce false positives without weakening threat detection.
  • Investigate security alerts and reconstruct incident timelines using SentinelOne Deep Visibility, Entra sign-in logs, and AWS CloudTrail.
  • Lead first-level response to credential compromises, account takeovers, and malware, coordinating device isolation, session revocation, and credential rotation with IT and engineering.
  • Audit and harden IAM permissions across 160 AWS accounts, enforcing least-privilege access.
  • Review KMS key policies, inspect VPC flow logs, and monitor Secrets Manager for security gaps and suspicious activity.
  • Monitor S3 public access and dangling Route53 records, tracking remediation to closure.
  • Manage Cloudflare WAF rules and rate limits using real traffic patterns to block attacks while preserving legitimate access.
  • Connect Cloudflare WAF, GuardDuty, and Entra logs into centralized monitoring and unified alerting.
  • Support engineering security reviews by explaining findings, severity, remediation, and delivery impact without unnecessarily blocking releases.
  • Support dependency scanning, secret scanning, and PR-level security checks to identify vulnerable dependencies, hardcoded secrets, missing encryption, and exposed APIs before release.
  • Define SOC 2 Type 2 and ISO audit evidence requirements, collection cadence, gap tracking, and escalation paths.
  • Prepare structured audit evidence packages and explain how the evidence demonstrates control implementation to leadership and external auditors.
  • Maintain security operating procedures, incident response checklists, and CIS/NIST control documentation.
  • Build automations for repeatable security checks, GuardDuty-to-Lambda alert routing, ticket enrichment, guided remediation, daily attendance reporting, and evidence collection.
  • Help define required compliance evidence, collection frequency, ownership, gap reporting, and escalation paths.
  • Support early security automation use cases such as alert enrichment, ticket enrichment, incident summaries, evidence preparation, and guided remediation checklists.
  • Contribute to product/security automation discussions by validating practical security workflows and guardrails.
  • Work closely with vendors, IT, engineering, delivery teams, leadership, and customer audit teams to improve security practices continuously. What You Will Do
  • Manage endpoint security across macOS and Windows devices, including EDR policies, encryption, hardening, access controls, patch posture, and endpoint compliance.
  • Operate and tune EDR/XDR and DLP tools such as SentinelOne, CrowdStrike, Check Point, Microsoft Defender, and related security products.
  • Monitor and investigate EDR, DLP, and endpoint alerts, reduce false positives, and escalate suspicious activities, policy violations, and security exceptions as per the defined incident management process.
  • Support incident response activities, including alert triage, endpoint isolation, evidence collection, ticket creation, escalation, and closure tracking.
  • Track endpoint and vulnerability gaps, including patch status, endpoint health, device compliance, and security exceptions, and coordinate remediation to closure.
  • Maintain security policies, procedures, checklists, and standards aligned with NIST, ISO 27001, SOC 2, CIS Controls, and customer security expectations.
  • Support internal and customer audits by collecting evidence, preparing control documentation, and tracking gap closure, and help define evidence, check frequency, and ownership for automated compliance evidence collection.
  • Assist in XDR/SIEM implementation by helping connect endpoint, identity, cloud, and application signals into a centralized monitoring model.
  • Act as a security SME for project and product teams, supporting dependency scanning, secret scanning, code security checks, configuration review, PR-level security review, and release-readiness checks.
  • Explain security findings clearly to engineering, project teams, vendors, leadership, and customer audit teams, including risk, severity, recommended fix, and release impact.
  • Explore AI-assisted security workflows such as alert summarization, evidence preparation, ticket enrichment, and guided remediation, and help define guardrails for AI-assisted or agentic security workflows.
  • Provide security-related IT support for device setup, software installation, access issues, endpoint agent health, encryption, VPN, and compliance checks. Future Security Responsibilities
  • XDR/SIEM adoption and centralized security monitoring.
  • Automated compliance evidence collection for audits and customer security reviews.
  • AI-assisted alert triage to improve speed, consistency, and quality of investigations.
  • Continuous compliance monitoring for endpoint, access, cloud, and security controls.
  • DevSecOps security checks including dependency scanning, secret scanning, SAST/SCA, container scanning, and IaC scanning.
  • Release security readiness for project and product teams.
  • Controlled remediation workflows with clear ownership, approvals, evidence, and closure tracking.
  • Product-facing security automation exposure where relevant, especially around security workflows, policy checks, evidence collection, and AI-assisted security operations. Your Impact and Growth in Year One
  • Every company laptop has a healthy EDR agent, encryption enabled, and up-to-date patches.
  • Alerts are triaged consistently, using AI-assisted investigation where useful, with documented response actions and tested recovery procedures.
  • Audit evidence stays ready, and compliance findings are addressed within agreed timelines.
  • Security gaps have a named owner, target closure date, and clear escalation path.
  • Engineering teams involve security early and resolve critical findings before release.
  • Real ownership as the first dedicated security hire, with established infrastructure to improve.
  • Hands-on experience across AWS, SentinelOne, Entra ID, M365, incident response, compliance, and AI-assisted security operations.
  • Opportunities to build agentic workflows for alert enrichment, evidence collection, and guided remediation, with human approval for critical actions.
  • Close collaboration with engineering, product, IT, leadership, and external auditors to protect company data and help teams ship securely.
  • Autonomy to make decisions and grow through deeper expertise, new security initiatives, and future team-building opportunities.