Senior Security Engineer / Tool Automation

F5 F5 · Enterprise · Hyderabad, India

Senior Security Engineer / Threat Hunter responsible for leading threat hunting engagements, performing proactive threat hunting and forensics across various environments, automating manual processes, and collaborating with other teams to implement security standards. Requires strong experience in cybersecurity, DFIR, SIEM/SOAR/EDR tools, MITRE ATT&CK, and scripting for automation.

What you'd actually do

  1. Lead threat hunting engagements for the Global Cyber Security Detections and Investigations team across enterprise and product environments.
  2. Lead and guide team members in threat hunting and digital forensics practices, including mentoring and upskilling efforts.
  3. Perform proactive threat hunting and host/cloud forensics (AWS, Azure, GCP, Linux, Windows, macOS), including acquisition and analysis of endpoint, network, and cloud artifacts.
  4. Automate manual processes to reduce operational toil and improve response times, including automation of common forensic and hunting workflows.
  5. Utilize security tooling (EDR, NG‑SIEM, SOAR, DLP, vulnerability scanners, posture management) to detect, investigate, and contain threats.

Skills

Required

  • 8+ years in cybersecurity
  • hands-on threat hunting
  • digital forensics and incident response (DFIR)
  • security engineering
  • designing and executing hypothesis-driven threat hunts
  • endpoint and cloud forensics
  • SIEM and NG-SIEM platforms (e.g., CrowdStrike Falcon, Splunk, Microsoft Sentinel)
  • SOAR
  • EDR/XDR tools
  • MITRE ATT&CK
  • threat actor TTPs
  • scripting or utilizing automation tools (Python, PowerApps, Power Automate, or similar)
  • cloud security (AWS, Azure, GCP)
  • infrastructure as code (Terraform, Ansible)
  • UNIX/Linux systems
  • networking protocols
  • firewall architecture
  • vulnerability management
  • penetration testing
  • secure architecture design
  • communication skills

Nice to have

  • GCIH, GCFR, GCFA, or equivalent SANS DFIR / threat hunting training
  • ServiceNow, ADO, or similar ticketing/case management systems
  • container orchestration (Kubernetes, Docker)
  • CI/CD pipelines
  • FedRAMP, eDiscovery, and DLP casework
  • interpersonal skills
  • collaborative mindset
  • lead and mentor junior engineers and analysts
  • drive strategic long-term initiatives
  • present technical investigations to executive leadership

What the JD emphasized

  • hands-on threat hunting
  • threat hunting
  • threat hunting