D
DTICI_Cloud App Security Engineer (MDCA)_T9_consultant
Daimler Truck
Bengaluru
Full-Time
0-3 Years experience
Description
Key Tasks & Responsibilities:
- Monitor and investigate cloud‑application‑related security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes.
- Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.
- Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.
- Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams.
- Escalate complex or high‑risk cloud‑app security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.
- Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.
- Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.
- Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.
- Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.
- Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.
- Maintain accurate investigation notes, incident documentation, and response records.
- Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.
- Support audit and compliance activities related to cloud application security controls when required.
Responsibilities
Key Skills:
- Hands‑on experience with Microsoft Defender for Cloud Apps (MDCA).
- Understanding of cloud application risks, SaaS security concepts, and user activity monitoring.
- Basic working knowledge of the Microsoft Defender ecosystem (MDE, MDO, Sentinel – awareness level).
- Understanding of SOC operations, alert triage, investigation workflows, and escalation models.
- Familiarity with incident response lifecycle and CSOC processes.
- Basic experience correlating cloud‑app alerts with identity, endpoint, or email‑based signals.
- Foundational knowledge of cybersecurity concepts such as access control, identity security, data protection, malware, phishing, and attack chains.
- Awareness of frameworks such as MITRE ATT&CK and basic threat‑actor techniques.
- Understanding of risks related to cloud usage, OAuth permissions, and SaaS data exposure.
- Basic understanding of cloud identity concepts (users, roles, permissions).
- Familiarity with authentication, authorization, and session‑based access risks in cloud apps.
- Ability to analyze logs, user activity, and audit events for investigation purposes.
Qualifications
-
Bachelor's degree in computer science, Information Technology, Cybersecurity, or Engineering.
-
2 – 4 years of cybersecurity experience, with exposure to SOC operations, cloud security, or security monitoring roles.
-
Hands‑on experience or operational exposure to Microsoft Defender for Cloud Apps is required.
-
Experience supporting low to medium‑severity cloud or SaaS security incidents in enterprise environments is preferred.
-
Certifications:
- SC‑200: Microsoft Security Operations Analyst
About Daimler Truck
-
