Home › HRMS › Job roles › Information Technology › Cyber Security Engineer
Information Technology · Mid level

Cyber Security Engineer job description

A Cyber Security Engineer builds and runs the technical controls that protect a company's systems: endpoint protection, email security, vulnerability scanning, SIEM rules, hardening standards and security checks in build pipelines. They investigate alerts escalated by the SOC, fix misconfigurations with IT teams and keep security tools healthy. The position reports to the IT security manager in IT services firms, banks, fintechs and large enterprises. A good Cyber Security Engineer closes gaps before attackers find them and turns every incident into a stronger control.

DetailFor this role
DepartmentInformation Technology
LevelMid level
Reports toIT Security Manager
Direct reportsNone
Experience3 to 6 years in security operations, system administration or network security

Cyber Security Engineer job description template

Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.

Job title: Cyber Security Engineer

Department: Information Technology

Reports to: IT Security Manager

Location: [City], [office, branch or site]

About the role

A Cyber Security Engineer builds and runs the technical controls that protect a company's systems: endpoint protection, email security, vulnerability scanning, SIEM rules, hardening standards and security checks in build pipelines. They investigate alerts escalated by the SOC, fix misconfigurations with IT teams and keep security tools healthy. The position reports to the IT security manager in IT services firms, banks, fintechs and large enterprises. A good Cyber Security Engineer closes gaps before attackers find them and turns every incident into a stronger control.

Key responsibilities

  • Deploy and tune endpoint detection and response, email security and web filtering across all company devices.
  • Run scheduled vulnerability scans on servers, network devices and web applications, and validate findings before assigning them.
  • Write and tune SIEM correlation rules so real attacks raise alerts and noisy false positives are cut.
  • Harden servers, databases and cloud accounts against CIS benchmarks and company baselines, and check compliance monthly.
  • Investigate escalated alerts, analyse logs and suspicious files, and isolate affected machines or accounts.
  • Add security scanners to CI/CD pipelines and help developers fix the issues they report.
  • Manage privileged access tools, multi-factor authentication settings and service account reviews.
  • Support penetration tests and audits by preparing scope, access and evidence, and fix the findings assigned to security.
  • Write playbooks for common incidents such as phishing, ransomware alerts and lost laptops.
  • Follow new threats and vendor advisories, and apply urgent mitigations when a critical vulnerability is announced.

Requirements

  • B.E. or B.Tech in Computer Science, IT or Electronics, B.Sc or MCA
  • CEH, CompTIA Security+ or CySA+ certification
  • Microsoft SC-200 or AWS Security Specialty is an advantage
  • 3 to 6 years in security operations, system administration or network security

KRAs and KPIs for a Cyber Security Engineer

Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.

Key result areaHow to measure it
Detection coverageSIEM receiving logs from every critical server, firewall and cloud account, checked weekly
Alert qualityFalse positives from custom SIEM rules lower every quarter
Hardening complianceAt least 90 percent of servers compliant with the hardening baseline at the monthly check
Critical advisoriesMitigation in place within 48 hours of a critical advisory that affects company systems
Alert investigationEscalated alerts investigated and closed or escalated further within 4 hours
Tool healthEndpoint agents reporting from at least 98 percent of devices every week

Skills and tools

Endpoint detection and responseSIEM rule writingVulnerability scanningLinux and Windows hardeningNetwork and log analysisPython or PowerShell scriptingCloud security basicsIncident handlingCuriosityClear incident notes

Tools used day to day: Microsoft Defender or CrowdStrike, Splunk or Microsoft Sentinel, Nessus or Qualys, Wireshark, CIS-CAT or hardening scripts, Burp Suite, PowerShell and Python.

Reporting line and career path

IT Security ManagerCyber SecurityEngineer

Interview questions for a Cyber Security Engineer

  1. A laptop shows repeated connections to an unknown IP address at night. How do you investigate?
  2. How would you write a SIEM rule to detect password spraying against Microsoft 365?
  3. Walk me through hardening a new Linux server before it goes live.
  4. A critical vulnerability is announced in a library used by ten applications. What do you do on the first day?
  5. How do you cut false positives without missing real attacks?
  6. What is the difference between EDR and traditional antivirus?

Managing a Cyber Security Engineer in ZeniaHR

Hire and manage your information technology team in one place

Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.

Book a free demoSee pricing

Frequently asked questions

What does a cyber security engineer do?

A cyber security engineer builds and maintains the tools and settings that protect a company's systems. They deploy endpoint and email security, run vulnerability scans, write SIEM detection rules, harden servers and cloud accounts, investigate escalated alerts and help developers fix security issues found in pipelines.

What is the difference between a cyber security engineer and a SOC analyst?

A SOC analyst watches alerts, triages them and escalates real incidents, usually working in shifts. A cyber security engineer builds and tunes the controls behind those alerts, fixes misconfigurations and handles deeper investigations. Many engineers start as SOC analysts and move up after two or three years.

Which certifications help a cyber security engineer in India?

CompTIA Security+ and CEH are common entry points and appear often in Indian job posts. CySA+ and Microsoft SC-200 suit detection work, while AWS or Azure security certifications help in cloud-heavy companies. Practical skill with scanners, SIEM tools and scripting matters most in interviews.