About the role
Security Engineer
HCL Software | Office of the CISO
Location: India - Bangalore / Noida / Remote
*About the Role
HCL Software is seeking a Security Engineer to build, deploy, and operate the controls that protect
our enterprise and cloud estate. This is a builder role: you will spend your time in configuration,
code, and integration work rather than in documents about future state.
You will own security platforms end to end, from design and rollout through tuning, automation, and
day-to-day health.
You will work closely with SOC, Vulnerability Management, IT, and cloud engineering teams, and
you will be expected to leave the environment measurably better instrumented than you found it.
Key Responsibilities
Security Control Engineering
- Deploy, configure, and maintain core security platforms including EDR, email security, secure
service edge, cloud security posture management, and identity controls.
- Design control rollouts that account for coverage gaps, exception handling, performance
impact, and rollback.
- Integrate security tooling with the SIEM and SOAR estate so telemetry and response actions
are usable, not just collected.
- Own control health monitoring: agent coverage, policy drift, failed enforcement, and silent
failure detection.
Cloud and Infrastructure Security
- Implement and maintain guardrails across AWS, Azure, and GCP, including preventative policy,
posture monitoring, and remediation workflows.
- Build and maintain hardened baselines for operating systems, containers, and cloud services
aligned to CIS or equivalent benchmarks.
- Engineer secrets management, key management, and certificate lifecycle controls in
partnership with platform teams.
- Support secure network design implementation including segmentation, egress control, and
remote access.
Automation and Engineering Practice
- Automate repetitive security operations work through scripting, APIs, and infrastructure as
code.
- Treat security configuration as code: version control, peer review, testing, and repeatable
deployment.
- Build and maintain integrations between security, IT, and engineering systems so data flows
without manual handling.
- Write and maintain documentation and runbooks good enough that someone else can operate
what you built.
Operations Support and Remediation
- Support incident response with rapid control changes, containment actions, and forensic data
collection.
- Partner with Vulnerability Management to engineer remediation at scale rather than ticket by
ticket.
- Participate in an on-call rotation for security platform issues and high-severity incidents.
- Contribute to control evidence collection for audit and customer assurance activity.
AI Security Engineering
- Implement security guardrails for internal AI/LLM systems, including protections against prompt
injection, model poisoning, and unauthorized data exfiltration.
Maintain and secure the enterprise AI infrastructure, ensuring secure configuration of Agentic
AI and model serving environments.
- Develop and support automation workflows that leverage AI/ML for security operations, such as
automated incident triage and investigation.
- Monitor and audit AI tool usage, ensuring adherence to governance policies for non-human
identities and autonomous agents.
- Stay current on emerging threats to AI systems and adapt security controls to defend against
AI-assisted attack vectors.
Required Qualifications:
- 5+ years in security engineering, infrastructure engineering with a security focus, or a closely
related hands-on role.
- Demonstrated ownership of at least two enterprise security platforms end to end, including
deployment, tuning, and ongoing operation.
- Strong cloud security engineering experience in at least one major provider, including native
security services and policy enforcement.
- Practical scripting and automation skill (Python, PowerShell, Go, or equivalent) and comfort
working against vendor APIs.
- Solid grounding in operating system internals, networking, and identity protocols such as
SAML, OIDC, and OAuth.
- Experience with infrastructure as code and version-controlled configuration workflows.
- Troubleshooting discipline: able to isolate root cause in complex environments without
guessing.
Preferred Qualifications
- Experience supporting a SIEM migration or large-scale telemetry pipeline rebuild.
- Container and Kubernetes security engineering experience.
- Background in a software or product company with both corporate IT and production cloud
environments in scope.
- Detection engineering exposure, including writing and testing detection content.
- Experience building security automation with SOAR platforms or custom orchestration.
- Certifications valued but not required: cloud security certifications (AWS, Azure, GCP), GCED,
GCIA, GDSA, or CISSP.
Millions of jobs, with real people getting hired every day
Questions, answered
Click "Apply with JobAssist" – we tailor your resume and application to this role and submit it for your approval.
Yes. This role at HCLTech was screened before publishing – we confirmed the employer before listing it.
The employer didn't disclose a salary range for this listing. JobAssist shows pay whenever it's available.
This position can be done from anywhere, with no in-office requirement.
Yes – every application is tailored from your profile and this job's requirements, and you can review and edit before it's sent.
