← Back to jobs
DDaimler Truck

DTICI_Cloud App Security Engineer (MDCA)_T9_consultant

Daimler Truck

Bengaluru
Full-Time
0-3 Years experience

Description

Key Tasks & Responsibilities:

  • Monitor and investigate cloud‑application‑related security alerts generated by Microsoft Defender for Cloud Apps (MDCA) under defined CSOC processes.
  • Perform alert triage and initial investigation to determine scope, user impact, risk level, and business relevance.
  • Support investigation of incidents involving risky cloud apps, OAuth abuse, data exposure, suspicious user activity, and abnormal cloud access patterns.
  • Assist in containment and remediation activities in coordination with Identity, Endpoint, Email, and IT platform teams.
  • Escalate complex or high‑risk cloud‑app security findings to L2/L3 specialists or Incident Managers with structured analysis and evidence.
  • Analyze user behavior, activity logs, and cloud telemetry to identify anomalies and suspicious activity.
  • Support policy tuning, alert refinement, and basic detection improvements to reduce false positives and improve signal quality.
  • Assist with shadow IT discovery, cloud app risk assessments, and enforcement of cloud app governance policies.
  • Support CSOC playbooks, runbooks, and response procedures related to cloud application security incidents.
  • Participate in post‑incident reviews and RCA discussions, contributing operational findings and improvement ideas.
  • Maintain accurate investigation notes, incident documentation, and response records.
  • Work closely with CSOC L1/L2 analysts, Identity, Endpoint, Email Security, and IT operations teams.
  • Support audit and compliance activities related to cloud application security controls when required.

Responsibilities

Key Skills:

  • Hands‑on experience with Microsoft Defender for Cloud Apps (MDCA).
  • Understanding of cloud application risks, SaaS security concepts, and user activity monitoring.
  • Basic working knowledge of the Microsoft Defender ecosystem (MDE, MDO, Sentinel – awareness level).
  • Understanding of SOC operations, alert triage, investigation workflows, and escalation models.
  • Familiarity with incident response lifecycle and CSOC processes.
  • Basic experience correlating cloud‑app alerts with identity, endpoint, or email‑based signals.
  • Foundational knowledge of cybersecurity concepts such as access control, identity security, data protection, malware, phishing, and attack chains.
  • Awareness of frameworks such as MITRE ATT&CK and basic threat‑actor techniques.
  • Understanding of risks related to cloud usage, OAuth permissions, and SaaS data exposure.
  • Basic understanding of cloud identity concepts (users, roles, permissions).
  • Familiarity with authentication, authorization, and session‑based access risks in cloud apps.
  • Ability to analyze logs, user activity, and audit events for investigation purposes.

Qualifications

  • Bachelor's degree in computer science, Information Technology, Cybersecurity, or Engineering.

  • 2 – 4 years of cybersecurity experience, with exposure to SOC operations, cloud security, or security monitoring roles.

  • Hands‑on experience or operational exposure to Microsoft Defender for Cloud Apps is required.

  • Experience supporting low to medium‑severity cloud or SaaS security incidents in enterprise environments is preferred.

  • Certifications:

    • SC‑200: Microsoft Security Operations Analyst

About Daimler Truck

-

Industry: no-mentionEmployees: 104416+Website