| Detail | For this role |
|---|---|
| Department | Information Technology |
| Level | Mid level |
| Reports to | IT Security Manager |
| Direct reports | None |
| Experience | 3 to 6 years in security operations, system administration or network security |
Cyber Security Engineer job description template
Copy this job description, replace the text in square brackets and post it on your careers page or a job portal.
Job title: Cyber Security Engineer
Department: Information Technology
Reports to: IT Security Manager
Location: [City], [office, branch or site]
About the role
A Cyber Security Engineer builds and runs the technical controls that protect a company's systems: endpoint protection, email security, vulnerability scanning, SIEM rules, hardening standards and security checks in build pipelines. They investigate alerts escalated by the SOC, fix misconfigurations with IT teams and keep security tools healthy. The position reports to the IT security manager in IT services firms, banks, fintechs and large enterprises. A good Cyber Security Engineer closes gaps before attackers find them and turns every incident into a stronger control.
Key responsibilities
- Deploy and tune endpoint detection and response, email security and web filtering across all company devices.
- Run scheduled vulnerability scans on servers, network devices and web applications, and validate findings before assigning them.
- Write and tune SIEM correlation rules so real attacks raise alerts and noisy false positives are cut.
- Harden servers, databases and cloud accounts against CIS benchmarks and company baselines, and check compliance monthly.
- Investigate escalated alerts, analyse logs and suspicious files, and isolate affected machines or accounts.
- Add security scanners to CI/CD pipelines and help developers fix the issues they report.
- Manage privileged access tools, multi-factor authentication settings and service account reviews.
- Support penetration tests and audits by preparing scope, access and evidence, and fix the findings assigned to security.
- Write playbooks for common incidents such as phishing, ransomware alerts and lost laptops.
- Follow new threats and vendor advisories, and apply urgent mitigations when a critical vulnerability is announced.
Requirements
- B.E. or B.Tech in Computer Science, IT or Electronics, B.Sc or MCA
- CEH, CompTIA Security+ or CySA+ certification
- Microsoft SC-200 or AWS Security Specialty is an advantage
- 3 to 6 years in security operations, system administration or network security
KRAs and KPIs for a Cyber Security Engineer
Key result areas for the appraisal form, each with a KPI you can measure every month or quarter.
| Key result area | How to measure it |
|---|---|
| Detection coverage | SIEM receiving logs from every critical server, firewall and cloud account, checked weekly |
| Alert quality | False positives from custom SIEM rules lower every quarter |
| Hardening compliance | At least 90 percent of servers compliant with the hardening baseline at the monthly check |
| Critical advisories | Mitigation in place within 48 hours of a critical advisory that affects company systems |
| Alert investigation | Escalated alerts investigated and closed or escalated further within 4 hours |
| Tool health | Endpoint agents reporting from at least 98 percent of devices every week |
Skills and tools
Tools used day to day: Microsoft Defender or CrowdStrike, Splunk or Microsoft Sentinel, Nessus or Qualys, Wireshark, CIS-CAT or hardening scripts, Burp Suite, PowerShell and Python.
Reporting line and career path
Next roles: Security Architect, IT Security Manager, Penetration Tester
Interview questions for a Cyber Security Engineer
- A laptop shows repeated connections to an unknown IP address at night. How do you investigate?
- How would you write a SIEM rule to detect password spraying against Microsoft 365?
- Walk me through hardening a new Linux server before it goes live.
- A critical vulnerability is announced in a library used by ten applications. What do you do on the first day?
- How do you cut false positives without missing real attacks?
- What is the difference between EDR and traditional antivirus?
Managing a Cyber Security Engineer in ZeniaHR
Hire and manage your information technology team in one place
Post the role, onboard the new hire, and track attendance, leave and KRAs in ZeniaHR. Free for your first 50 employees.
Book a free demoSee pricingFrequently asked questions
What does a cyber security engineer do?
A cyber security engineer builds and maintains the tools and settings that protect a company's systems. They deploy endpoint and email security, run vulnerability scans, write SIEM detection rules, harden servers and cloud accounts, investigate escalated alerts and help developers fix security issues found in pipelines.
What is the difference between a cyber security engineer and a SOC analyst?
A SOC analyst watches alerts, triages them and escalates real incidents, usually working in shifts. A cyber security engineer builds and tunes the controls behind those alerts, fixes misconfigurations and handles deeper investigations. Many engineers start as SOC analysts and move up after two or three years.
Which certifications help a cyber security engineer in India?
CompTIA Security+ and CEH are common entry points and appear often in Indian job posts. CySA+ and Microsoft SC-200 suit detection work, while AWS or Azure security certifications help in cloud-heavy companies. Practical skill with scanners, SIEM tools and scripting matters most in interviews.