Posted on: 17/08/2026
Security Engineer - Senior Associate
Job Summary:
Asset Management Firm is building out its information security function to protect the firm's investment, operations, and technology platforms. Our environment is Microsoft-centric end to end Windows endpoints, Microsoft 365, Entra ID, Intune, and Azure with security tooling built natively on that stack. We are seeking a hands-on Senior Security Engineer to serve as the primary point of triage and remediation across email security alerts, phishing simulation, vulnerability and penetration test findings, and technical configuration auditing. This role works closely with the Head of Information Security and the infrastructure team.
Core Requirements:
Security Operations & Alert Triage:
- Serve as primary triage point for escalated MDR alerts determine scope, severity, and appropriate response.
- Monitor and respond to email security alerts: malware/spam detections, threat intelligence matches, and policy violations.
- Coordinate alert routing between email security tooling and the MDR provider as vendor relationships evolve.
- Investigate employee-reported phishing; confirm true/false positive and drive remediation (blocking, takedown, user notification).
Email & Web Security Policy:
- Co-manage web content filtering policy (Defender for Cloud Apps) with the Head of Information Security: category blocking, domain exceptions, indicator management. Policy ownership only network/proxy infrastructure stays with the infrastructure team.
- Administer and tune email security configuration, including filter policies and quarantine.
Phishing Simulation Program:
- Own phishing simulation campaigns end-to-end: design, targeting, scheduling, and reporting.
Vulnerability & Penetration Test Management:
- Triage penetration test and vulnerability scan findings; prioritize by severity and exploitability.
- Remediate findings within the role's technical access; for others (infrastructure, app owners, vendors), identify the owner and drive the handoff.
- Track all findings to closure, including re-testing/validation.
Technical Configuration & IT Posture Auditing:
- Periodically audit security configurations and broader IT posture against target state - including patch compliance across endpoints and servers, not just security tooling (Defender for Endpoint, Defender for Office 365, Conditional Access, Exchange transport rules, Defender for Cloud Apps).
- Flag configuration drift, undocumented changes, and posture gaps (e.g., unpatched systems); remediation of infrastructure-owned findings is driven by the infrastructure team.
Knowledge, Skills and Abilities:
- Breadth over narrow depth solid exposure across email/endpoint/identity/cloud rather than deep specialization in one area. A candidate who is world-class in one niche but weak elsewhere is not a fit; the role moves between email triage, config audit, identity, and pentest remediation in the same week.
- Hands-on with the Microsoft Defender suite (Endpoint, Office 365, Cloud Apps) - operational on day one, not learning it from scratch. Comparable XDR/email experience in a Mac/Linux environment is a weaker substitute given how Microsoft-specific our stack is.
- Analytical/investigative mindset works from ambiguous signals (an alert, a user report, a scan finding) to a defensible conclusion and knows when to escalate vs. close out.
- Genuine curiosity about how systems work and how attackers think, and comfort learning unfamiliar tools on the fly willingness to figure things out matters more than deep prior experience in any one tool.
- Strong written and verbal communication explains findings to stakeholders clearly and honestly (what happened, what I'm unsure about, what I recommend), which matters as much as the finding itself.
- Solid IT/security fundamentals how email flows, what malicious URLs/attachments look like, basic networking, how identity and access work a working mental model, not certification-level depth.
Qualifications:
- 6-10+ years in security engineering, operations, SOC, or a comparable hands-on role (flexible on years if judgment and curiosity are strong a sharp, less senior candidate beats a senior one who has mostly done rote triage).
Hiring Process:
- The interview process will involve multiple rounds across teams based in Mumbai and the US.
- Position is in Goregaon Office, WFO, 5 days a week.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1663570