Skip to content

IT Security Engineer

Rootquotient TechnologiesChennai, TN, IndiaSeptember 25, 2026
On-site
Full-time
Endpoint Security
Mid · 2–4 yrs

IT Security Engineer

Location: Chennai, India     |     Experience: 2–4 years

About the Role

Rootquotient is hiring its first dedicated security team member to own day-to-day security operations and strengthen our existing EDR/XDR setup. You’ll investigate threats, keep endpoints secure, improve cloud and identity security, and maintain audit readiness while helping engineering teams ship securely.

You’ll also explore practical AI-assisted and agentic workflows for alert investigation, evidence collection, and routine security checks, with human oversight for critical actions.

Reporting to [IT/Engineering Head], you’ll work closely with engineering, IT, external auditors, and our security vendors. Your scope and level of ownership will reflect your experience, as outlined below.

Role Expectations

  • Independently manage SentinelOne EDR operations across approximately 150 macOS endpoints, ensuring endpoint compliance.
  • Tune SentinelOne policies with vendor support, create custom S1QL detection rules, and manage exceptions to reduce false positives without weakening threat detection.
  • Investigate security alerts and reconstruct incident timelines using SentinelOne Deep Visibility, Entra sign-in logs, and AWS CloudTrail.
  • Lead first-level response to credential compromises, account takeovers, and malware, coordinating device isolation, session revocation, and credential rotation with IT and engineering.
  • Audit and harden IAM permissions across 160 AWS accounts, enforcing least-privilege access.
  • Review KMS key policies, inspect VPC flow logs, and monitor Secrets Manager for security gaps and suspicious activity.
  • Monitor S3 public access and dangling Route53 records, tracking remediation to closure.
  • Manage Cloudflare WAF rules and rate limits using real traffic patterns to block attacks while preserving legitimate access.
  • Connect Cloudflare WAF, GuardDuty, and Entra logs into centralized monitoring and unified alerting.
  • Support engineering security reviews by explaining findings, severity, remediation, and delivery impact without unnecessarily blocking releases.
  • Support dependency scanning, secret scanning, and PR-level security checks to identify vulnerable dependencies, hardcoded secrets, missing encryption, and exposed APIs before release.
  • Define SOC 2 Type 2 and ISO audit evidence requirements, collection cadence, gap tracking, and escalation paths.
  • Prepare structured audit evidence packages and explain how the evidence demonstrates control implementation to leadership and external auditors.
  • Maintain security operating procedures, incident response checklists, and CIS/NIST control documentation.
  • Build automations for repeatable security checks, GuardDuty-to-Lambda alert routing, ticket enrichment, guided remediation, daily attendance reporting, and evidence collection.
  • Help define required compliance evidence, collection frequency, ownership, gap reporting, and escalation paths.
  • Support early security automation use cases such as alert enrichment, ticket enrichment, incident summaries, evidence preparation, and guided remediation checklists.
  • Contribute to product/security automation discussions by validating practical security workflows and guardrails.
  • Work closely with vendors, IT, engineering, delivery teams, leadership, and customer audit teams to improve security practices continuously.

What You Will Do

  1. Manage endpoint security across macOS and Windows devices, including EDR policies, encryption, hardening, access controls, patch posture, and endpoint compliance.
  2. Operate and tune EDR/XDR and DLP tools such as SentinelOne, CrowdStrike, Check Point, Microsoft Defender, and related security products.
  3. Monitor and investigate EDR, DLP, and endpoint alerts, reduce false positives, and escalate suspicious activities, policy violations, and security exceptions as per the defined incident management process.
  4. Support incident response activities, including alert triage, endpoint isolation, evidence collection, ticket creation, escalation, and closure tracking.
  5. Track endpoint and vulnerability gaps, including patch status, endpoint health, device compliance, and security exceptions, and coordinate remediation to closure.
  6. Maintain security policies, procedures, checklists, and standards aligned with NIST, ISO 27001, SOC 2, CIS Controls, and customer security expectations.
  7. Support internal and customer audits by collecting evidence, preparing control documentation, and tracking gap closure, and help define evidence, check frequency, and ownership for automated compliance evidence collection.
  8. Assist in XDR/SIEM implementation by helping connect endpoint, identity, cloud, and application signals into a centralized monitoring model.
  9. Act as a security SME for project and product teams, supporting dependency scanning, secret scanning, code security checks, configuration review, PR-level security review, and release-readiness checks.
  10. Explain security findings clearly to engineering, project teams, vendors, leadership, and customer audit teams, including risk, severity, recommended fix, and release impact.
  11. Explore AI-assisted security workflows such as alert summarization, evidence preparation, ticket enrichment, and guided remediation, and help define guardrails for AI-assisted or agentic security workflows.
  12. Provide security-related IT support for device setup, software installation, access issues, endpoint agent health, encryption, VPN, and compliance checks.

Future Security Responsibilities

  • XDR/SIEM adoption and centralized security monitoring.
  • Automated compliance evidence collection for audits and customer security reviews.
  • AI-assisted alert triage to improve speed, consistency, and quality of investigations.
  • Continuous compliance monitoring for endpoint, access, cloud, and security controls.
  • DevSecOps security checks including dependency scanning, secret scanning, SAST/SCA, container scanning, and IaC scanning.
  • Release security readiness for project and product teams.
  • Controlled remediation workflows with clear ownership, approvals, evidence, and closure tracking.
  • Product-facing security automation exposure where relevant, especially around security workflows, policy checks, evidence collection, and AI-assisted security operations.

Your Impact and Growth in Year One

  • Every company laptop has a healthy EDR agent, encryption enabled, and up-to-date patches.
  • Alerts are triaged consistently, using AI-assisted investigation where useful, with documented response actions and tested recovery procedures.
  • Audit evidence stays ready, and compliance findings are addressed within agreed timelines.
  • Security gaps have a named owner, target closure date, and clear escalation path.
  • Engineering teams involve security early and resolve critical findings before release.
  • Real ownership as the first dedicated security hire, with established infrastructure to improve.
  • Hands-on experience across AWS, SentinelOne, Entra ID, M365, incident response, compliance, and AI-assisted security operations.
  • Opportunities to build agentic workflows for alert enrichment, evidence collection, and guided remediation, with human approval for critical actions.
  • Close collaboration with engineering, product, IT, leadership, and external auditors to protect company data and help teams ship securely.
  • Autonomy to make decisions and grow through deeper expertise, new security initiatives, and future team-building opportunities.

Job Details

Salary

₹800,000 – ₹1,400,000/yr

Experience

Mid · 2–4 yrs

Tools & Tech

AWS
Cloudflare
CloudTrail
CrowdStrike
Entra ID
GuardDuty
Lambda
macOS
Microsoft Defender
S3
SentinelOne
Windows