Cyber Security Engineer
About this role
- Manage and optimize policies in CrowdStrike
- Investigate and respond to endpoint alerts (malware, suspicious behaviour, lateral movement)
- Perform root cause analysis and prevent recurrence
- Improve detection coverage using behavioural rules and threat intelligence
- Secure user lifecycle management via JumpCloud
- Enforce:
- MFA across all systems
- Least privilege access
- Device trust policies
- Design and execute periodic access reviews
- Investigate identity-related incidents (account compromise, privilege misuse)
- Audit and secure SaaS platforms (Google Workspace, Slack, Zoom, etc.)
- Identify and remediate:
- Over-permissioned users
- Risky OAuth integrations
- Public data exposure
- Define SaaS security baselines and governance controls
- Own the full incident lifecycle:
- Detection → Triage → Containment → Recovery → RCA
- Build and maintain incident response playbooks
- Partner with Service Desk for rapid containment actions
- Continuously improve response time and accuracy
- Automate:
- User offboarding (access revocation + device lockdown)
- Alert-driven responses (via EDR and identity tools)
- Access reviews and compliance checks
- Reduce manual effort and improve consistency across security operations
- Correlate signals from: CrowdStrike (endpoint) , ManageEngine OpManager (infra/network) and SaaS audit logs
- Build meaningful dashboards and alerts
- Improve signal-to-noise ratio (reduce alert fatigue)
- Define and enforce:
- Endpoint hardening standards
- Identity and access policies
- Incident response procedures
- Support audits (ISO/SOC2 if applicable)
- Ensure continuous improvement of security posture
Requirements
- Strong hands-on experience with:
CrowdStrike (or similar EDR like SentinelOne, Defender)
JumpCloud / Okta / Azure AD - Real-world incident response experience (not just theoretical SOC work)
- Deep understanding of:
Endpoint attack techniques
Identity-based attacks
SaaS security risks
- Experience with scripting (Python / Bash / PowerShell)
- Ability to automate workflows and integrate tools
- Strong problem-solving and system thinking approach
- MITRE ATT&CK framework understanding
- Endpoint detection and response concepts
- Identity & access management principles (SSO, MFA, RBAC)
- 6-10 years in Security Engineering / Blue Team / Endpoint Security
- Experience in SaaS-heavy or cloud-first environments preferred
Company at a glance
We are one of India’s most exciting & fast-growing mobile gaming companies. Founded in 2014, and creating a global mobile gaming landscape in partnership
with Modern Times Group (MTG), our vision is to create simple, impactful casual
game experiences at a massive scale. Since our inception, we have built a worldwide network of chart-topping games, and powerful tech & analytics infrastructure to turbocharge their growth. Our product portfolio consists of evergreen hits like Daily Themed Crossword, WordTrip, WordJam, WordWars, WordTrek, TileMatch, Jigsaw and many more.
Visit us at www.playsimple.in to know more.
Recent news about PlaySimple: shorturl.at/gwABJ
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?