ArcSight L2/L3 Engineer at Gigabit Technologies Pvt Limited · Gurugram · 3 - 6 years · ₹15L - ₹25L / yr · Profitable · Posted 28 Sep 2026

Job Summary:
We are looking for an experienced OpenText ArcSight SIEM / SOAR / UBA L2-L3 Engineer to manage and support security platforms in SOC/MSSP environment. The role involves day-to-day administration, troubleshooting, configuration and optimization of ArcSight platforms.
Key Responsibilities
- Administer and monitor OpenText ArcSight ESM/SIEM, SmartConnectors, SOAR and UBA/ArcSight Intelligence.
- Manage SIEM rules, filters, Active Lists, dashboards, reports and correlation use cases.
- Monitor EPS, event flow, connector health, system performance and log ingestion.
- Troubleshoot event collection, parsing, correlation and integration issues.
- Configure and troubleshoot ArcSight SmartConnectors and log sources.
- Manage and troubleshoot SOAR playbooks, integrations and automated workflows.
- Support UBA/Intelligence data ingestion, analytics and integration with SIEM.
- Perform L2/L3 troubleshooting, RCA and resolution of platform-related incidents.
- Support upgrades, patches, configuration changes and platform optimization.
- Coordinate with SOC, infrastructure, customer and OEM/OpenText support teams.
- Maintain technical documentation, incident records and RCA reports.
Required Skills
- 3–6 years of hands-on experience with OpenText ArcSight SIEM/ESM.
- Strong experience in ArcSight administration and troubleshooting.
- Hands-on experience with SmartConnectors, EPS, correlation rules, Active Lists and event flow.
- Working experience with ArcSight SOAR and UBA/ArcSight Intelligence.
- Good knowledge of Linux/Unix and networking fundamentals.
- Understanding of Syslog, CEF, TCP/IP, SSL/TLS and REST APIs.
- Strong analytical, troubleshooting and problem-solving skills.
- Experience in SOC/MSSP or managed security services environment preferred.
- OpenText/ArcSight certification will be an added advantage.
Candidate Profile
The candidate should be hands-on, technically strong and capable of independently handling L2/L3 production issues, platform administration, troubleshooting and escalations in a security operations environment.

About Gigabit Technologies Pvt Limited
About
Similar jobs (10)
Job Description – Tines SOAR Engineer
Job Title: Tines SOAR Engineer
Experience: 6+ Years
Employment Type: Contract
Job Location: India – Hybrid/Remote
Company: Prama.ai
About the Role
Prama.ai is looking for an experienced Tines SOAR Engineer to design, develop, and maintain security automation workflows for enterprise SOC environments. The ideal candidate should have strong hands-on experience with Tines SOAR, security operations, incident response, API integrations, and automation.
Key Responsibilities
- Design, develop, and maintain automation workflows (Tines Stories).
- Build and enhance security playbooks for incident response and alert handling.
- Develop integrations between Tines and SIEM, EDR/XDR, IAM, ITSM, and other security tools.
- Implement integrations using REST APIs, Webhooks, JSON, and OAuth.
- Automate repetitive SOC and security operations to improve incident response efficiency.
- Troubleshoot, monitor, and optimize Tines automation workflows.
- Collaborate with SOC, Security, Infrastructure, and IT teams.
- Support security automation use cases across enterprise environments.
Required Skills
- 6+ years of IT/Security experience with strong hands-on experience in Tines SOAR.
- Hands-on experience developing Tines Stories, Actions, Event Transformations, and API integrations.
- Strong understanding of SOC, Incident Response, Security Operations, and Security Automation.
- Strong knowledge of REST APIs, JSON, Webhooks, and OAuth.
- Experience with at least one SIEM:
- Microsoft Sentinel
- Splunk
- IBM QRadar
- Google Chronicle
- Experience with at least one EDR/XDR:
- Microsoft Defender
- CrowdStrike
- SentinelOne
- Cortex XDR
- Scripting experience in Python, JavaScript, or PowerShell.
- Experience with ServiceNow or Jira.
- Working knowledge of Windows/Linux environments.
- Good understanding of TCP/IP, DNS, HTTP/HTTPS.
- Knowledge of Active Directory, Entra ID, or Okta.
Preferred Skills
- Experience working with Banking/BFSI clients.
- Knowledge of Microsoft Security Stack.
- Understanding of Threat Intelligence and MITRE ATT&CK.
- Exposure to AWS or Azure Security.
- Experience with enterprise SOC automation and security integrations.
Preferred Certifications
- Tines Certification
- Microsoft SC-200
- CompTIA Security+ / CySA+
- Microsoft AZ-500
A Senior Cybersecurity Engineer is responsible for safeguarding an organization’s IT infrastructure, applications, and data against cyber threats. With 5–10 years of experience, the role demands expertise in designing, implementing, and managing advanced security solutions, conducting risk assessments, and responding to incidents. Senior Engineers also mentor junior staff and contribute to strategic security planning.
Key Responsibilities
- Design, implement, and manage enterprise-level security solutions (firewalls, IDS/IPS, SIEM, endpoint protection).
- Conduct vulnerability assessments, penetration testing, and risk analysis.
- Monitor and respond to security incidents, ensuring timely resolution and documentation.
- Develop and enforce security policies, standards, and compliance frameworks (ISO 27001, NIST, GDPR).
- Collaborate with IT and business teams to integrate security into system architecture and processes.
- Lead incident response drills and disaster recovery planning.
- Provide guidance and mentorship to junior cybersecurity staff.
- Stay updated on emerging threats, tools, and technologies.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, or related field.
- 5–10 years of proven experience in cybersecurity engineering or related roles.
- Strong knowledge of network security, cloud security (AWS, Azure, GCP), and endpoint protection.
- Hands-on experience with SIEM tools (Splunk, QRadar, ArcSight), firewalls, and intrusion detection/prevention systems.
- Certifications such as CISSP, CISM, CEH, or OSCP are highly desirable.
Skills
- Advanced problem-solving and analytical skills.
- Strong communication and leadership abilities.
- Ability to manage complex projects and handle escalations effectively.
- Proactive mindset with adaptability to evolving cyber threats.
We are looking for a Cybersecurity Engineer to protect our systems, applications and data. You will find vulnerabilities, monitor threats and strengthen our overall security posture.
Responsibilities
- Run vulnerability assessments and penetration tests (VAPT) on web apps, APIs and networks
- Monitor and respond to security events using SIEM tools as part of SOC operations
- Test application security using Burp Suite and similar tools
- Support ISO 27001 compliance, audits and security policies
- Harden network infrastructure, firewalls and access controls
- Document findings and track fixes with engineering teams
Requirements
- 1+ years of experience in VAPT, SOC or security engineering
- Hands-on experience with Burp Suite and SIEM tools
- Knowledge of the OWASP Top 10 and network security fundamentals
- Exposure to ISO 27001 or similar frameworks
- Certifications such as CEH, OSCP or CompTIA Security+ are a plus
This role will be permanent with NAM info and deploy to client location Chennai.
Work Mode: WORK FROM OFFICE
Offer salary can offer on a decent hike
Role Descriptions:
Exp Range: 6-10 years
Primary Competency : Terraform, Hashi Sentinel (IaC/PaC), Kubernetes (GKE/EKS)
City Locations: Bengaluru or Chennai
Key Responsibilities*
Experience Required: 6-10
Role Descriptions:
Security Monitoring & Incident Response
Investigate and analyze security alerts escalated by L1 SOC analysts.
Perform triage, containment, eradication, and recovery activities for security incidents.
1. Perform in-depth analysis of security alerts escalated from L1
2. Investigate suspicious activities using SIEM, EDR, and threat intelligence tools
3. Correlate events across multiple log sources (firewalls, endpoints, IAM, cloud logs)
4. Validate true positives and recommend reducing false positives
5. Lead triage and response for medium to high severity incidents
6. Coordinate with IT, network, and application teams during incidents and support deep investigations when required
7. Conduct proactive threat hunting based on TTPs (e.g., MITRE ATT&CK)
8. Fine-tuning and optimize SIEM use cases to reduce false positives
9. Develop new correlation rules and detection logic
10. Document incidents, findings, and response actions
11. Prepare weekly , monthly reports for SOC leadership and stakeholders
Desire candidate
- Candidate should have valid PF.
ServiceNow USEM Technical Consultant -(Offshore) Contract Role
· Location- Remote
· Contract- 6 months
Job Description
Position Description:
The ServiceNow USEM (SecOps) Technical Consultant (Security Operations) is responsible to lead the design, development, and implementation of security operations (SecOps) solutions on the ServiceNow platform. This role is responsible for integrating security workflows, enhancing automation, and optimizing security response processes to ensure robust cybersecurity operations.
Primary Responsibilities:
Design, configure, and implement ServiceNow GRC/IRM modules, focusing on Policy, Compliance, and Risk Management frameworks. Develop custom solutions utilizing Flow Designer, Business Rules, Client Scripts, UI Actions, UI Policies, and Script Includes.
Configure Service Portal/Employee Center components, Service Catalog record producers, notifications, inbound email actions, and email-actionable approvals.
Manage Access Control Lists (ACLs) and role-based access designs alongside SLA definitions and task-based SLA behaviors.
Handle update set management and oversee code promotion across development, test, and production instances.
Requirements
Qualifications:
· 5+ years hands-on ServiceNow development experience, with demonstrable delivery on client-facing implementation projects
· 2+ years working directly in ServiceNow GRC/IRM, specifically Policy and Compliance Management and/or Risk Management. Candidates whose GRC exposure is limited to a single mod
· Demonstrated experience with Flow Designer, business rules, client scripts, UI Actions, UI Policies, and script includes
· Experience configuring notifications and inbound email actions, including email-actionable approvals
· Experience with ACL configuration and understanding of role-based access design
· Experience with SLA definitions and task-based SLA behavior
· Experience with Service Catalog record producers and Employee Center / Service Portal configuration
· Proficiency with update set management and promotion across development, test, and production instances
· ServiceNow Certified System Administrator (CSA) required CIS Advanced Risk preferred
· Work Experience: 5+ years
· Industry: Technology
Cyber Toddler is inviting applications for its 6-week Cybersecurity Operations, SOC & Threat Intelligence Internship — a weekend-only practical program designed for students, fresh graduates and early-career cybersecurity professionals.
The internship focuses on the skills used across modern security operations, including SOC monitoring, SIEM and log analysis, threat intelligence, incident response, threat hunting and security detection.
Rather than focusing only on theoretical learning, selected interns will work through simulated security incidents, investigate logs and indicators, analyze threats, document findings and complete a final cybersecurity investigation project.
What you will work on:
- SOC operations and security monitoring
- SIEM concepts and log analysis
- Security alert triage
- Threat intelligence and IOC investigation
- Phishing and suspicious activity analysis
- Incident response
- MITRE ATT&CK
- Threat hunting
- Detection engineering fundamentals
- Security investigation and reporting
- Cybersecurity documentation
- End-to-end SOC investigation
Duration: 6 weeks
Mode: Remote
Schedule: Weekends
Commitment: Approximately 4–5 hours per week
Cohort: Limited seats
Enterprise Integration Engineer, ServiceNow / Splunk (Freelance)
Positions: 2
Experience: Ideally 5-9 years.
Mission
Build secure enterprise connectors and governed tool interfaces between the AI platform and IT operational systems.
Priority skills
We particularly want candidates with a combination of:
ServiceNow + Splunk + API engineering
ServiceNow experience should include REST APIs, Incidents, Problems, Changes, Knowledge, work notes, authentication/OAuth and ITSM workflows.
Splunk experience should ideally include SPL, REST/Search APIs, indexes, sourcetypes, saved searches, alerts and operational integrations.
Confluence REST API and Rally/Broadcom Agile Central experience are additional advantages.
Engineering fundamentals
- Python and/or Java
- REST APIs
- OAuth2
- Enterprise authentication
- Service identities
- Rate limiting
- API throttling
- Retry patterns
- Idempotency
- Async/event processing
- Audit logging
- Least-privilege security
A candidate who combines ServiceNow + Splunk + Python/API engineering + GenAI integration experience should be treated as a particularly strong profile.
At Shipthis, we are building a better future for freight forwarders by evolving traditional operations into fully digital, efficient, and scalable systems. We’re a fast-growing product company where every individual has the opportunity to take ownership, move fast, and create real impact. If you enjoy solving complex problems, shaping products from the ground up, and influencing technical direction, Shipthis is the place for you.
Learn more at www.shipthis.co
Role Overview
We are looking for an associate-level SecOps Engineer to support security operations, compliance, endpoint management, cloud infrastructure, and DevOps engineering. The role will work closely with the CTO/CISO and engineering team. Security and compliance are core responsibilities; when those priorities are lighter, the engineer will focus on CI/CD, infrastructure automation, reliability, monitoring, performance, and cloud cost optimization.
What You’ll be Doing
Security Operations
- Monitor infrastructure, application, and security alerts and assist with incident investigation.
- Review access controls, privileged accounts, service accounts, permissions, and periodic access reviews.
- Support infrastructure hardening, logging, monitoring, backup, recovery, and other security controls.
- Track security issues and corrective actions through closure.
Vulnerability Management
- Run and review application and infrastructure vulnerability scans.
- Maintain a vulnerability register and coordinate remediation with engineering teams.
- Support VAPT and penetration-testing exercises and validate closure of findings.
- Monitor dependencies, containers, operating systems, and cloud infrastructure for known vulnerabilities and patching needs.
Compliance & Governance
- Support ongoing ISO/IEC 27001, SOC 2, GDPR, customer-security, and internal-policy requirements.
- Maintain audit evidence, control registers, security policies, procedures, risk items, and remediation records.
- Assist with internal/external audits, vendor assessments, customer security questionnaires, and asset inventories.
- Maintain evidence for access reviews, vulnerability management, incidents, onboarding/offboarding, backups, and infrastructure changes.
MDM & Endpoint Security
- Administer the company MDM platform and enroll/manage company laptops, desktops, and mobile devices.
- Maintain device inventory and monitor endpoint compliance.
- Enforce approved controls such as disk encryption, screen locks, password requirements, patching, and endpoint protection.
- Support employee device onboarding/offboarding, approved application deployment, lost/stolen-device procedures, and remote wipe where authorized.
- Maintain endpoint security and MDM evidence required for audits and troubleshoot enrollment or policy issues.
DevOps, CI/CD & Cloud
- Maintain and improve CI/CD pipelines, deployment workflows, build times, caching, and rollback processes.
- Support production and non-production cloud infrastructure, networking, DNS, TLS certificates, IAM, and secrets.
- Automate repetitive deployment, infrastructure, security, and compliance tasks.
- Improve monitoring, logging, alerting, reliability, resource utilization, and cloud costs.
- Troubleshoot pipeline, deployment, and infrastructure issues and participate in root-cause analysis.
Required Fundamentals
- Basic knowledge of Linux, networking, HTTP/HTTPS, DNS, TLS, Git, Docker, cloud computing, APIs, and web applications.
- Understanding of IAM, MFA, least privilege, vulnerabilities/CVEs, encryption, logging, patching, and secrets management.
- Strong troubleshooting, ownership, attention to detail, and willingness to learn.
Desired Qualifications
- 1–2 years of experience with strong fundamentals are welcome.
- Basic scripting knowledge in Python, Bash, or similar.
- Interest in cybersecurity, cloud infrastructure, automation, and troubleshooting.
- Exposure to AWS/GCP/Azure, Terraform, GitHub Actions, Cloudflare, OWASP, vulnerability scanners, MDM, ISO 27001, or SOC 2 is a plus, not mandatory.
We Welcome Candidates:
- Who can join immediately
- Female candidates returning to work after a career break are strongly encouraged.
We are an equal opportunity employer and are committed to fostering diversity and inclusivity. We do not discriminate based on race, religion, color, gender, sexual orientation, age, marital status, or disability status.
Job Synopsys
Location: Bangalore
Job Type: Full-time, Permanent
Experience: 1-2 years
Industry: Software Product
Hi Folks, we are currently Hiring for Security Engineer.
Gemini said
Hiring: Security Engineer
Company : Pentabay Softwares
Location : Anna salai, Mount Road
Mode: Fulltime
Pentabay Softwares INC is looking for a proactive Security Engineer (2–7 Years Exp) to fortify our global digital solutions. As we scale our footprint in the Healthcare IT sector, you will play a critical role in safeguarding sensitive data (ePHI) and ensuring our cloud-native architectures are resilient against evolving threats.
The Mission
You will be the architect of our defense, bridging the gap between high-speed development and rigorous security standards. Your day-to-day will involve "shifting security left" by embedding DevSecOps practices into our CI/CD pipelines and leading our compliance efforts for SOC 2, ISO 27001, and HIPAA.
Key Responsibilities
Defense & Architecture: Design and maintain secure cloud (AWS/Azure/GCP) and on-prem environments. Implement IAM policies, Zero Trust frameworks, and robust secrets management.
Offensive Testing: Conduct regular vulnerability assessments (VAPT), penetration testing, and code reviews using tools like Burp Suite and Nessus.
DevSecOps & Automation: Integrate SAST/DAST/SCA scanning into engineering workflows. Automate security tasks using Python or Bash.
Incident Response: Monitor SIEM tools (Splunk/CrowdStrike), respond to threats, and develop risk mitigation strategies.
Healthcare Compliance (Plus): Ensure data integrity for HL7/FHIR APIs and maintain HIPAA/HITECH audit readiness for healthcare clients.
What You Bring
Experience: 2–7 years in Information/Application Security with a strong grasp of the OWASP Top 10 and threat modeling (STRIDE).
Technical Depth: Proficiency in network/endpoint security, PKI, encryption standards (TLS/SSL), and container security (Docker/Kubernetes).
Compliance Knowledge: Familiarity with NIST, GDPR, and SOC 2 frameworks.
Tools: Hands-on experience with Metasploit, Wireshark, and Infrastructure-as-Code (Terraform).
Bonus Points: Industry certifications like OSCP, CISSP, or CEH, and experience in Healthcare IT workflows.
Auditing space like ISO27001 , ISO9001 prefered
Why Pentabay?
At Pentabay, we offer more than just a job; we offer a security-first engineering culture.
Growth: A dedicated learning budget for certifications and conferences.
Impact: Work on cutting-edge Healthcare projects that demand the highest levels of data privacy.
Send resumes to : sandhiya.m at pentabay.com
Responsibilities
- Execute and support application vulnerability assessments (SAST, DAST, SCA, and manual code review), ensuring findings are accurate, actionable, and relevant to application risk.
- Validate scanner results, perform false-positive analysis, and track findings through remediation, including retesting to confirm effective fixes.
- Manage multiple application security initiatives concurrently while meeting strict timelines in a fast‑paced environment.
- Prioritize vulnerabilities based on business impact, exploitability, exposure, and likelihood, using industry best practices (e.g., CVSS scoring).
- Develop and maintain dashboards and reports tracking vulnerability metrics such as severity distribution, remediation SLAs, and mean time to remediation (MTTR).
- Support the integration of security scanning and vulnerability workflows into CI/CD pipelines, leveraging existing tooling and automation.
- Facilitate remediation planning by providing actionable recommendations and coordinating root cause analysis.
- Support threat modeling and application risk assessments, with a focus on discovering insecure design patterns.
- Participate in high‑severity or zero‑day vulnerability response activities, including impact analysis and coordinated remediation efforts, as needed.
- Provide input into policies and standards related to application and cloud security controls.
Qualifications and Education Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, or related discipline—or equivalent professional experience.
- 5-7 years of relevant experience in application security and/or vulnerability management.
- Solid understanding of common vulnerability classes (e.g., OWASP Top 10) and secure architecture principles.
- Proficiency in using Burp Suite for manual security testing of web applications and APIs, including validation of automated findings and identification of complex authentication, authorization, and business‑logic vulnerabilities.
- Hands-on experience with tools such as Burp Suite, Fortify, Checkmarx, SonarQube, Black Duck, Tenable, and common network discovery tools (e.g., Nmap).
- Familiarity with NIST, MITRE ATT&CK, and CIS benchmarks.
- Programming/scripting proficiency in languages such as Python, Java, .NET, or similar.
- Excellent documentation, communication, and stakeholder engagement skills.
Desired Skills
- Professional certifications (e.g., Security+, SSCP, GWAPT, or pursuing CISSP, OSCP).
- Experience using the ServiceNow platform for vulnerability or incident tracking.
- Proficiency in Azure cloud and Azure DevOps environments.
- Experience using Power BI or similar tools to visualize vulnerability metrics and remediation trends for technical and non-technical stakeholders.






