Skip to content

Cyber Security Engineer I

Sabre International LLCBengaluru, KA, IndiaJuly 26, 2026
Hybrid
Full-time
Incident Response
Mid · 2–3 yrs

Powering the agentic revolution in travel. Sabre is an AI-native technology leader, backed by one of the world’s largest travel data clouds. Built on an open, modular, cloud-native architecture, Sabre serves as the backbone for both established leaders and bold, new disruptors, guiding them to the next age of travel retailing through intelligent, connected, and personalized experiences. With AI at its core and operating at unparalleled scale, Sabre transforms insights into innovation, empowering airlines, hoteliers, agencies and other partners to retail, distribute and fulfill travel worldwide.

Cyber Security Engineer – Threat Detection and Incident Response 

Location: Flexible / Hybrid 
Department: Risk & Security – Cyber Threat Management (CTM) 
Reports To: Manager, Cyber Threat Management 

Position Overview 

Sabre is seeking a self-motivated Cyber Security Engineer with 2-3 yrs’ experience, to join our Cyber Threat Management (CTM) team. This role is responsible for identifying, investigating, responding to, and helping prevent cybersecurity threats across Sabre's global technology environment. 

The ideal candidate is enthusiastic about cybersecurity, has experience working in a Security Operations Center (SOC), Incident Response, Threat Hunting, or related security function, and possesses strong analytical and critical thinking skills. This individual will serve as a key contributor to Sabre's Cyber Incident Response Team (CIRT), participate in initiative-taking threat hunting activities, help improve detection capabilities, and support the ongoing evolution of Sabre's security operations program. 

Primary Responsibilities 

Threat Detection & Monitoring 

  • Monitor, investigate, and respond to security alerts generated from enterprise security platforms. 

  • Analyze suspicious events and recommend appropriate response actions. 

  • Identify indicators of compromise (IOCs), attacker tactics, techniques, and procedures (TTPs), and emerging threats. 

  • Assist in the development and tuning of detection logic, alerting rules, and automated response workflows. 

  • Collaborate with Managed Detection and Response (MDR) providers and internal stakeholders to validate and respond to potential threats.  

Incident Response 

  • Serve as a member of Sabre's Cyber Incident Response Team (CIRT). 

  • Participate in cybersecurity incident investigations throughout the incident response lifecycle, including identification, analysis, containment, eradication, recovery, and lessons learned. 

  • Perform security investigations independently while collaborating with senior team members on complex or high-severity incidents. 

  • Coordinate with infrastructure, cloud, application, and business teams during incident response activities. 

  • Document investigative findings, evidence, response actions, and remediation recommendations. 

  • Participate in tabletop exercises and post-incident reviews to strengthen organizational preparedness.  

Threat Hunting 

  • Conduct initiative-taking threat hunting activities to identify malicious activity that may evade automated detection. 

  • Analyze endpoint, network, identity, cloud, and security telemetry to identify anomalous or suspicious behavior. 

  • Research emerging cyber threats and assist in translating intelligence into actionable detection content. 

  • Develop and execute threat hunting hypotheses based on current threat intelligence and attack trends.  

Detection Engineering & Operational Improvement 

  • Create and optimize security detections within SIEM (Cortex XSIAM), endpoint protection, and other security monitoring platforms. 

  • Assist with improving automation and operational efficiency across security processes. 

  • Partner with engineering and infrastructure teams to improve security visibility and telemetry collection. 

  • Contribute to the evaluation and implementation of new security capabilities and technologies.  

Vulnerability & Risk Collaboration 

  • Partner with Vulnerability Management teams to assess emerging threats and critical vulnerabilities. 

  • Participate in threat-based vulnerability analysis and prioritization activities. 

  • Assist with providing risk-based recommendations to technology teams and system owners.  

Collaboration & Communication 

  • Communicate technical findings clearly to both technical and non-technical audiences. 

  • Prepare investigation summaries, incident documentation, and after-action reports. 

  • Build productive working relationships with security, infrastructure, cloud, application development, and business teams. 

  • Contribute to team knowledge sharing and continuous improvement initiatives. 

  • Demonstrate professionalism and composure during security incidents and operational escalations. 

Required Qualifications 

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent practical experience). 

  • 2–3+ years of experience in Cyber Security, Security Operations, Threat Hunting, Incident Response, Vulnerability Management, or a related security discipline. 

  • Experience investigating cybersecurity events or security alerts in an enterprise environment. 

  • Working knowledge of common attack techniques and threat actor behaviors. 

  • Familiarity with SIEM technologies, endpoint security platforms, log analysis, and incident response processes. 

  • Fundamental understanding of networking, operating systems, cloud technologies, authentication, and enterprise security concepts. 

  • Strong analytical and troubleshooting skills. 

  • Excellent written and verbal communication skills with strong command of the English language. 

  • Ability to work effectively both independently and as part of a collaborative team. 

Preferred Qualifications 

Candidates with one or more of the following will receive strong consideration: 

  • Experience with Palo Alto Networks Cortex XSIAM

  • Experience with Microsoft Defender

  • Experience with Google Cloud Platform (GCP) or AWS 

  • Experience with ServiceNow

  • Experience with threat intelligence, threat hunting, or detection engineering activities. 

  • Experience working in a 24x7 security operations environment. 

  • Experience with scripting or automation technologies such as Python or PowerShell. 

  • Industry certifications such as:  

  • CompTIA Security+ 

  • CompTIA CySA+ 

  • ISC2 SSCP or CISSP Associate 

  • GIAC certifications 

  • Cloud Security Certifications 

Soft Skills & Professional Competencies 

Success in this role requires both technical capability and strong people skills. 

The ideal candidate will demonstrate: 

  • Exceptional written and verbal communication skills. 

  • Ability to communicate effectively with technical teams, leadership, and business stakeholders. 

  • Strong teamwork, collaboration, and relationship-building skills. 

  • A positive attitude and willingness to learn. 

  • Sound judgment and professionalism when handling security incidents. 

  • Strong organizational skills and attention to detail. 

  • Intellectual curiosity and a desire to stay current on emerging cybersecurity threats and technologies. 

  • Ability to balance multiple priorities in a fast-paced operational environment. 

On-Call Expectations 

This position participates in the Cyber Threat Management on-call rotation and is expected to provide support during assigned coverage periods, including after-hours investigation and response activities when necessary. Team members work closely with internal stakeholders and external security partners to ensure timely response to identified threats and security incidents.  

We will give careful consideration to your application and review your details against the position criteria. You will receive separate notification as your application progresses.

Please note that only candidates who meet the minimum criteria for the role will proceed in the selection process.

Job Details

Experience

Mid · 2–3 yrs

Tools & Tech

AWS
GCP
Microsoft Defender
Palo Alto
PowerShell
Python
ServiceNow

Preferred Certs

CISSP
SSCP