Security Engineer III -SOC
Anaplan · Gurugram, India
Anaplan · Gurugram, India
At Anaplan, we are a team of innovators focused on optimizing business decision-making through our leading AI-infused scenario planning and analysis platform so our customers can outpace their competition and the market. What unites Anaplanners across teams and geographies is our collective commitment to our customers’ success and to our Winning Culture. Our customers rank among the who’s who in the Fortune 50. Coca-Cola, LinkedIn, Adobe, LVMH and Bayer are just a few of the 2,400+ global companies who rely on our best-in-class platform. Our Winning Culture is the engine that drives our teams of innovators. We champion diversity of thought and ideas, we behave like leaders regardless of title, we are committed to achieving ambitious goals, and we love celebrating our wins – big and small. Supported by operating principles of being strategy-led, values-based and disciplined in execution, you’ll be inspired, connected, developed and rewarded here. Everything that makes you unique is welcome; join us and let’s build what’s next - together! What you’ll be doing: As a Senior Security Engineer on the Security Operations team, you will design, build, and enhance our technical capabilities for threat detection, investigation, and response. Your role bridges engineering and operations, transforming security challenges into scalable, automated solutions. Your core responsibilities include: • SIEM Engineering: Manage our SIEM platform, onboard and normalize log sources, build and maintain parsers, and ensure high-fidelity data pipelines for detection and investigation. Focus on improving log coverage, data quality, and platform performance. • Detection Engineering: Develop and maintain a library of high-quality detections using a Detection as Code approach, managing content through version control, peer review, and automated testing. Align detections with the MITRE ATT&CK framework to enhance coverage, precision, and resilience. • SOAR & Automation: Create and maintain automated workflows and playbooks using SOAR platforms to optimize alert triage, enrichment, and response. Identify and automate manual processes within security operations to enhance scalability. • AI-Augmented Security Operations: Investigate and implement AI and machine learning to boost security operations, including alert triage, incident response, threat intelligence analysis, and detection content enrichment. Assess emerging AI tools for responsible integration into workflows. • Threat Intelligence Integration: Utilize threat intelligence from various sources, integrating indicators and adversary context into detection logic, SOAR playbooks, and hunting activities. Ensure actionable intelligence is timely and structured. • Threat Hunting: Conduct proactive, hypothesis-driven threat hunts to uncover attacker activity that bypasses existing detections. Document findings to inform and enhance detection engineering and tools. • Incident Response Support: Provide engineering support during security incidents, aiding in investigation, containment, and recovery. Contribute to post-incident reviews, translating lessons into improved detections and playbooks. What you’ll bring to the role: We seek a technically proficient security professional with hands-on experience in security capabilities within complex environments. The ideal candidate will have: • Technical Security Experience: Extensive experience in security engineering, DevSecOps, or a similar role, particularly in securing cloud-native environments and modern application stacks. • Detection & Response Skills: Practical experience in developing and tuning SIEM detections, writing threat hunting queries, and engaging in incident response. • SecOps Tooling: Proficiency in administering and operating core security tools like SIEM platforms (e.g., Splunk, Microsoft Sentinel), EDR/XDR solutions, and vulnerability scanners, with experience integrating these tools for detection and response workflows. • Threat Intelligence & Threat Hunting: Familiarity with threat intelligence platforms and feeds (e.g., MISP, Recorded Future, VirusTotal), and the ability to integrate intelligence into security tooling and detection logic. Knowledge of threat hunting methodologies is highly desirable. • Scripting & Automation: Proficiency in scripting or programming languages (e.g., Python, Go, Bash) for building security tools and automating workflows. • Application Security Knowledge: Understanding of secure development practices, OWASP top risks, and experience in code reviews or collaboration with developers to address security findings. • Security Frameworks & Standards: Knowledge of relevant security frameworks (e.g., NIST CSF, CIS Benchmarks, MITRE ATT&CK) and compliance standards like SOC 2 or ISO 27001. • Communication & Collaboration: Strong ability to communicate technical security risks and recommendations to diverse stakeholders and work cross-functionally to achieve security objectives. • Incident Response & Digital Forensics: Experience leading or supporting security incident investigations, including evidence preservation, log analysis, timeline reconstruction, and root cause identification. Familiarity with forensic tools and methodologies is highly valued. Our Commitment