← Back to list
Job

Cloud Security Module Lead-Service Support

Security Engineer • On-site • Full-time • 📍 Noida

About Sopra Steria
Sopra Steria, a major Tech player in Europe with 51,000 employees in nearly 30 countries, is recognised for its consulting, digital services and solutions. It helps its clients drive their digital transformation and obtain tangible and sustainable benefits. The Group provides end-to-end solutions to make large companies and organisations more competitive by combining in-depth knowledge of a wide range of business sectors and innovative technologies with a collaborative approach. Sopra Steria places people at the heart of everything it does and is committed to putting digital to work for its clients in order to build a positive future for all. In 2025, the Group generated revenues of €5.6 billion.
The world is how we shape it.

About the Role

We're looking for a Cloud Security Engineer with a strong incident response background to join our security team. You'll be on the front lines detecting, investigating, and remediating security events across our cloud infrastructure and endpoints.

What You'll Do

- Lead end-to-end incident response: triage, containment, investigation, and post-incident review

- Hunt for threats and investigate alerts using CrowdStrike Falcon (EDR, threat intelligence, and OverWatch)

- Build and tune detection logic in Splunk — write SPL queries, create dashboards, and maintain alert fidelity

- Audit and investigate events in AWS CloudTrail, CloudWatch, and native AWS security services (GuardDuty, Security Hub,

Config)

- Correlate signals across endpoint, network, and cloud layers to establish attack timelines

- Document findings and produce clear incident reports for both technical and non-technical audiences

- Contribute to runbooks, playbooks, and continuous improvement of the IR program

What You Bring

- 3+ years in a security engineering, SOC, or incident response role

- Hands-on experience with CrowdStrike (investigation workflows, RTR, detections tuning)

- Proficiency in Splunk — SPL, data onboarding, and building actionable dashboards

- Solid understanding of AWS IAM, CloudTrail log structure, and cloud-native audit trails

- Familiarity with attacker TTPs (MITRE ATT&CK) and how they map to cloud environments

- Ability to communicate technical findings clearly under pressure

Nice to Have

- GCIH, GCFE, AWS Security Specialty, or similar certifications

- Experience with IaC security tooling (Terraform, CloudFormation scanning)

- Scripting ability in Python or Bash for automation and log parsing

Total Experience Expected: 04-06 years

B.E/B.TECH/MCA (Computer Science/Electronics and related branches only)

Job requires working in shifts with standby/On-call support on weekends/out of business hours.

At our organization, we are committed to fighting against all forms of discrimination. We foster a work environment that is inclusive and respectful of all differences.

All of our positions are open to people with disabilities.

Similar jobs