IT Security Engineer

Rootquotient TechnologiesChennai, Tamil NaduOn-siteFull-timeMid level, 2–5 yearsListed 1 hour ago

Apply now

About this role

# IT Security Engineer
Location: Chennai, India | Experience: 2–4 years
## About the Role
Rootquotient is hiring its first dedicated security team member to own day-to-day security operations and strengthen our existing EDR/XDR setup. You’ll investigate threats, keep endpoints secure, improve cloud and identity security, and maintain audit readiness while helping engineering teams ship securely. You’ll also explore practical AI-assisted and agentic workflows for alert investigation, evidence collection, and routine security checks, with human oversight for critical actions. Reporting to [IT/Engineering Head], you’ll work closely with engineering, IT, external auditors, and our security vendors. Your scope and level of ownership will reflect your experience, as outlined below.
## Role Expectations

- Independently manage SentinelOne EDR operations across approximately 150 macOS endpoints, ensuring endpoint compliance.
- Tune SentinelOne policies with vendor support, create custom S1QL detection rules, and manage exceptions to reduce false positives without weakening threat detection.
- Investigate security alerts and reconstruct incident timelines using SentinelOne Deep Visibility, Entra sign-in logs, and AWS CloudTrail.
- Lead first-level response to credential compromises, account takeovers, and malware, coordinating device isolation, session revocation, and credential rotation with IT and engineering.
- Audit and harden IAM permissions across 160 AWS accounts, enforcing least-privilege access.
- Review KMS key policies, inspect VPC flow logs, and monitor Secrets Manager for security gaps and suspicious activity.
- Monitor S3 public access and dangling Route53 records, tracking remediation to closure.
- Manage Cloudflare WAF rules and rate limits using real traffic patterns to block attacks while preserving legitimate access.
- Connect Cloudflare WAF, GuardDuty, and Entra logs into centralized monitoring and unified alerting.
- Support engineering security reviews by explaining findings, severity, remediation, and delivery impact without unnecessarily blocking releases.
- Support dependency scanning, secret scanning, and PR-level security checks to identify vulnerable dependencies, hardcoded secrets, missing encryption, and exposed APIs before release.
- Define SOC 2 Type 2 and ISO audit evidence requirements, collection cadence, gap tracking, and escalation paths.
- Prepare structured audit evidence packages and explain how the evidence demonstrates control implementation to leadership and external auditors.
- Maintain security operating procedures, incident response checklists, and CIS/NIST control documentation.
- Build automations for repeatable security checks, GuardDuty-to-Lambda alert routing, ticket enrichment, guided remediation, daily attendance reporting, and evidence collection.
- Help define required compliance evidence, collection frequency, ownership, gap reporting, and escalation paths.
- Support early security automation use cases such as alert enrichment, ticket enrichment, incident summaries, evidence preparation, and guided remediation checklists.
- Contribute to product/security automation discussions by validating practical security workflows and guardrails.
- Work closely with vendors, IT, engineering, delivery teams, leadership, and customer audit teams to improve security practices continuously.

What You Will Do

- Manage endpoint security across macOS and Windows devices, including EDR policies, encryption, hardening, access controls, patch posture, and endpoint compliance.
- Operate and tune EDR/XDR and DLP tools such as SentinelOne, CrowdStrike, Check Point, Microsoft Defender, and related security products.
- Monitor and investigate EDR, DLP, and endpoint alerts, reduce false positives, and escalate suspicious activities, policy violations, and security exceptions as per the defined incident management process.
- Support incident response activities, including alert triage, endpoint isolation, evidence collection, ticket creation, escalation, and closure tracking.
- Track endpoint and vulnerability gaps, including patch status, endpoint health, device compliance, and security exceptions, and coordinate remediation to closure.
- Maintain security policies, procedures, checklists, and standards aligned with NIST, ISO 27001, SOC 2, CIS Controls, and customer security expectations.
- Support internal and customer audits by collecting evidence, preparing control documentation, and tracking gap closure, and help define evidence, check frequency, and ownership for automated compliance evidence collection.
- Assist in XDR/SIEM implementation by helping connect endpoint, identity, cloud, and application signals into a centralized monitoring model.
- Act as a security SME for project and product teams, supporting dependency scanning, secret scanning, code security checks, configuration review, PR-level security review, and release-readiness checks.
- Explain security findings clearly to engineering, project teams, vendors, leadership, and customer audit teams, including risk, severity, recommended fix, and release impact.
- Explore AI-assisted security workflows such as alert summarization, evidence preparation, ticket enrichment, and guided remediation, and help define guardrails for AI-assisted or agentic security workflows.
- Provide security-related IT support for device setup, software installation, access issues, endpoint agent health, encryption, VPN, and compliance checks.

Future Security Responsibilities

- XDR/SIEM adoption and centralized security monitoring.
- Automated compliance evidence collection for audits and customer security reviews.
- AI-assisted alert triage to improve speed, consistency, and quality of investigations.
- Continuous compliance monitoring for endpoint, access, cloud, and security controls.
- DevSecOps security checks including dependency scanning, secret scanning, SAST/SCA, container scanning, and IaC scanning.
- Release security readiness for project and product teams.
- Controlled remediation workflows with clear ownership, approvals, evidence, and closure tracking.
- Product-facing security automation exposure where relevant, especially around security workflows, policy checks, evidence collection, and AI-assisted security operations.

Your Impact and Growth in Year One

- Every company laptop has a healthy EDR agent, encryption enabled, and up-to-date patches.
- Alerts are triaged consistently, using AI-assisted investigation where useful, with documented response actions and tested recovery procedures.
- Audit evidence stays ready, and compliance findings are addressed within agreed timelines.
- Security gaps have a named owner, target closure date, and clear escalation path.
- Engineering teams involve security early and resolve critical findings before release.
- Real ownership as the first dedicated security hire, with established infrastructure to improve.
- Hands-on experience across AWS, SentinelOne, Entra ID, M365, incident response, compliance, and AI-assisted security operations.
- Opportunities to build agentic workflows for alert enrichment, evidence collection, and guided remediation, with human approval for critical actions.
- Close collaboration with engineering, product, IT, leadership, and external auditors to protect company data and help teams ship securely.
- Autonomy to make decisions and grow through deeper expertise, new security initiatives, and future team-building opportunities.

#