Solstice Logo

Solstice

Senior Advanced Cybersecurity Detection & Threat Intelligence Engineer

Posted 7 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Bengaluru, Bengaluru Urban, Karnataka
Senior level
In-Office or Remote
Hiring Remotely in Bengaluru, Bengaluru Urban, Karnataka
Senior level
Design, implement, and tune threat detections across SIEM, EDR/XDR, cloud, OT/ICS, and identity. Translate threat intelligence and IOCs into detection rules, hunt hypotheses, and SOAR automation. Manage IOC feeds and TIPs, improve telemetry coverage, onboard log sources, and own the full detection lifecycle from hypothesis through production deployment.
The summary above was generated by AI

Location: Remote
We are seeking a Sr. Advanced Cybersecurity Engineer based in India to serve as a detection and threat intelligence engineer within our Threat Detection & Response (TDR) program. This role focuses on detection engineering, threat intelligence operationalization, and SOAR automation across IT enterprises, cloud, OT/ICS, and identity environments. The ideal candidate will design and tune detection logic, drive security telemetry coverage improvements, build automated enrichment and detection workflows, and own the full detection development lifecycle from hypothesis through production deployment.

Responsibilities

Key Responsibilities

  • Design, implement, and continuously tune threat detections across SIEM, EDR/XDR, OT security platforms, and cloud-native security tooling.
  • Own the end-to-end detection engineering lifecycle — hypothesis development, rule authoring, validation, deployment, tuning, and retirement — aligned to MITRE ATT&CK across IT, OT, cloud, and identity environments.
  • Operationalize threat intelligence by translating finished intel, IOCs, and adversary TTPs into actionable detection rules, hunt hypotheses, and automated enrichment workflows.
  • Manage and maintain threat intelligence feeds and platforms, including ingestion, validation, confidence scoring, and expiration of IOC libraries.
  • Build, maintain, and improve SOAR automation playbooks, enrichment pipelines, and detection workflows to increase alert fidelity and reduce analyst toil.
  • Develop and maintain detection content for OT/ICS environments, including industrial protocol anomaly detection, Purdue model segmentation visibility, and OT-specific threat actor TTPs.
  • Improve security telemetry quality and coverage by collaborating with infrastructure, network, cloud, OT, and platform engineering teams to onboard new log sources and validate data fidelity.
Qualifications

Required Skills & Experience

  • Must reside in India — this role is approved for India-based candidates only. 
  • 7–10+ years of experience in cybersecurity with a focus on detection engineering, security operations, or threat intelligence.
  • Strong hands-on experience with SIEM platforms such as Microsoft Sentinel, Splunk, Elastic, or QRadar — including rule authoring, query development, and data onboarding. 
  • Deep understanding of adversary tactics, techniques, and procedures with applied experience mapping detections to MITRE ATT&CK.
  • Hands-on experience developing detection rules, correlation logic, behavioral analytics, and threshold-based alerting across multiple telemetry sources. 
  • Demonstrated experience with SOAR platforms for building automated enrichment pipelines, detection workflows, and threat intel operationalization.
  • Strong scripting and automation skills in Python, PowerShell, or KQL for detection development, data parsing, and workflow automation.
  • Experience with threat intelligence platforms (TIP) for IOC lifecycle management, feed integration, and intel-to-detection operationalization. 
     

Preferred Qualifications 

  • Experience building or maturing a detection engineering program including detection backlog management, coverage gap analysis, and ATT&CK heatmap maintenance. 
  • Experience with OT/ICS security monitoring
  • Familiarity with threat intelligence integration and threat hunting methodologies
  • Familiarity with detection-as-code practices, version control for detection content, and automated rule testing pipelines
  • Knowledge of cloud-native security monitoring and identity telemetry. 
  • Relevant certifications such as GDAT, GCDE, GCIA, GCED, or equivalent credentials.
About Us

About Solstice Advanced Materials

Solstice Advanced Materials is a leading global specialty materials company that advances science for smarter outcomes. Solstice offers high-performance solutions that enable critical industries and applications, including refrigerants, semiconductor manufacturing, data center cooling, nuclear power, protective fibers, healthcare packaging and more. Solstice is recognized for developing next-generation materials through some of the industry's most renowned brands such as Solstice®, Genetron®, Aclar®, Spectra®, Fluka™, and Hydranal™. Partnering with over 3,000 customers across more than 120 countries and territories and supported by a robust portfolio of over 5,700 patents, Solstice’s approximately 4,000 employees worldwide drive innovation in materials science. For more information, visit Advanced Materials.


Similar Jobs

An Hour Ago
Easy Apply
Remote or Hybrid
Easy Apply
Entry level
Entry level
Cloud • Information Technology • Security • Software • Cybersecurity
Lead strategic technical engagements for enterprise cybersecurity accounts, analyze customer environments for security risks, and provide tailored mitigation strategies. Develop expertise in security data fabric and vulnerability management products, deliver technical consulting and training, manage executive stakeholders, and coordinate with Sales, Support, and Product teams to resolve escalations. Use data modeling, SQL, ETL, security analytics, and AI tools to deliver actionable insights and improve customer outcomes.
Top Skills: Ai ToolsData Fabric For SecurityData ModelingETLSecurity AnalyticsSQLUnified Vulnerability ManagementZero Trust Exchange
An Hour Ago
Remote or Hybrid
2 Locations
Senior level
Senior level
Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Provides client-facing fund accounting services for global hedge, private equity, and debt fund clients. Responsibilities include maintaining books, processing capital activities, preparing NAV and investor reports, calculating management fees, preferred returns and carried interest, applying waterfall methodologies, and handling complex fund structures and instruments. The role also involves client issue resolution, financial analysis, and collaboration across jurisdictions while working UK shifts.
2 Hours Ago
Remote or Hybrid
India
Senior level
Senior level
Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Designs and maintains Alteryx workflows for regulatory data extraction, transformation, validation, reporting, and audit trails. Integrates SQL databases and legacy systems, develops Python and SQL automation scripts, implements process controls, and embeds error logging. Partners with reporting and IT teams to deploy Tableau, Power BI, or QlikSense dashboards for variance analysis. Trains nontechnical teams on Alteryx and translates regulatory requirements into technical solutions.
Top Skills: AlteryxPower BIPythonQliksenseSQLTableau

What you need to know about the Mumbai Tech Scene

From haggling for the best price at Chor Bazaar to the bustle of Crawford Market, the energy of Mumbai's traditional markets is a key part of the city's charm. And while these markets will always have their place, the city also boasts a thriving e-commerce scene, ranking among the largest in the region. Driven by online sales in everything from snacks to licensed sports merchandise to children's apparel, the local industry is worth billions, with companies actively recruiting to meet the demands of continued growth.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account