Lead Cloud Security Engineer
Agentic Soc
Analytics
Application Security
Automation
Aws Cloud Security
Cloud
Cloud Infrastructure
Cloud Platform
Cloud Platforms
Cloud Security
Cloud Technology
Container Security
Cyber Security
Cybersecurity Tools
Data Platform
Data Security
DevOps
DevSecOps
Digital Marketing
Endpoint Security
Facilities Management
Identity and Access Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Infrastructure As Code
Log Management
Project Management
Risk Management
Security
Security Automation
Security Information And Event Management
Security Monitoring
Security Operations
Security Orchestration & Automation
SOAR
Software Security
Splunk
Splunk Siem
Job Description
Lead Cloud Security Engineer role in New York, NY (onsite) focused on automated containment and agentic SOC capabilities across enterprise security environments.
Responsibilities
- Design and implement automated containment workflows across SIEM, SOAR, endpoint, identity, network, and cloud security platforms
- Create incident response playbooks for endpoint isolation, account restriction, malicious IP blocking, credential containment, and cloud workload quarantine
- Define automation eligibility criteria, approval requirements, rollback procedures, exception handling, and human-in-the-loop controls
- Architect and implement an agentic SOC roadmap, including custom security agent patterns, orchestration workflows, and MCP integrations
- Build integrations between security platforms, AWS services, case-management systems, and enterprise APIs using Python and secure API patterns
- Validate automated response and containment via testing, Purple Team exercises, and incident response simulations
- Develop cloud-native security automation using AWS, EKS, Terraform, and related platform services
- Collaborate with Cyber Defense, SOC, Incident Response, Cloud Security, IAM, and infrastructure teams to operationalize response capabilities
- Create operational metrics and dashboards to track automation coverage, response times, containment success, exceptions, and operational effectiveness
- Produce architecture documentation, containment playbooks, runbooks, support procedures, and knowledge-transfer materials for transition into BAU operations
Requirements
- 8+ years of experience in Cybersecurity Engineering, Security Operations, Cloud Security, Incident Response, or Security Automation
- Strong hands-on expertise in AWS security services, cloud-native architecture, and security operations in enterprise environments
- Experience designing automated incident response and containment workflows across SIEM, SOAR, EDR, IAM, network, and cloud platforms
- Strong programming and automation skills using Python, APIs, and event-driven integration patterns
- Hands-on experience with Terraform and Infrastructure as Code for secure, repeatable deployments
- Experience with AWS EKS, containerized workloads, Kubernetes security, and cloud workload containment strategies
- Understanding of agentic SOC architectures, AI-enabled security workflows, MCP integrations, and human-in-the-loop automation controls
- Experience using Git-based development and CI/CD tools such as Bitbucket or equivalent platforms
- Strong knowledge of incident response, Purple Team testing, approval controls, rollback mechanisms, and exception-management processes
- Strong architecture, troubleshooting, documentation, stakeholder communication, and operational transition skills
Technologies
- SIEM, SOAR, EDR, IAM
- AWS, AWS EKS, Kubernetes, containerized workloads
- Python, APIs, event-driven integration patterns
- Terraform, Infrastructure as Code
- agentic SOC architectures, AI-enabled security workflows, MCP integrations
- human-in-the-loop automation controls
- Git-based development, CI/CD, Bitbucket
Benefits
- Medical/Dental/Vision/Life Insurance
- Paid holidays plus Paid Time Off
- 401(k) plan and contributions
- Long-term/Short-term Disability
- Paid Parental Leave
- Employee Stock Purchase Plan
Practice (CIS - Cloud, Infrastructure, and Security Services)
- Cognizant’s Cloud, Infrastructure, and Security Services Practice (CIS) supports digital transformation through holistic modernization across layers
- Helps customers transform infrastructure and workplace to meet evolving needs of the digital era
- Holistic approach emphasizes cloud-driven modernization and workplace and operational transformation to run the business in a secure environment
Compensation
- Annual salary: USD 114,500 - 134,000 (based on experience and other qualifications)
- Eligible for Cognizant’s discretionary annual incentive program based on performance, subject to plan terms
Similar Jobs
S