Role Summary
Xeo Software is seeking a Senior Security Engineer to own and strengthen the technical security posture of its Microsoft-based environment. The role focuses on infrastructure and application security, DevSecOps, threat detection, vulnerability management, security automation, and SOC 2 readiness.
Key Responsibilities
- Infrastructure Security: Harden and secure Windows servers, VMware environments, FortiGate firewalls, and Microsoft-stack applications.
- DevSecOps: Integrate security controls and automated vulnerability scanning into CI/CD pipelines while enforcing least-privilege access.
- Threat Detection: Deploy, manage, and tune SIEM, IDS/IPS, endpoint protection, security alerts, and incident response playbooks.
- Vulnerability Management: Conduct continuous vulnerability assessments, security patching, and configuration audits across infrastructure and applications.
- SOC 2 Readiness: Implement and maintain technical security controls required for SOC 2 certification and support external audit activities.
- Security Standards: Define technical security baselines covering system hardening, password policies, patch management, and related security controls.
- Penetration Testing: Prepare infrastructure, applications, configurations, and processes for external penetration testing engagements.
- Security Leadership: Act as the primary technical security advisor for infrastructure and application security and guide engineering teams on remediation.
- Security Automation: Develop automation using technologies such as PowerShell, Python, and Terraform to improve security operations.
Key Qualifications
- 7+ years of experience in cybersecurity or systems security engineering.
- At least 3 years of experience working in a Microsoft-centric environment.
- Deep hands-on expertise with Windows Server, Active Directory, VMware, FortiGate firewalls, and Azure or Microsoft 365.
- Experience implementing DevSecOps practices and security controls in CI/CD pipelines using Azure DevOps, GitHub Actions, Jenkins, or similar technologies.
- Hands-on experience with SIEM, IDS/IPS, endpoint protection, vulnerability scanners, and threat detection technologies.
- Strong understanding of network segmentation, identity management, encryption, least-privilege access, and secure application deployment.
- Working knowledge of SOC 2 or similar security frameworks such as ISO 27001 and NIST 800-53.
- Experience conducting or preparing organizations for external penetration testing.
- Experience with security automation using PowerShell, Python, Terraform, or similar technologies is advantageous.
- Relevant certifications such as CISSP, OSCP, CEH, AZ-500, or MS-500 are preferred.
About Xeo Software
Xeo Software develops enterprise-grade software with a focus on performance, reliability, and scalability. The company is expanding its India operations and is building its security capabilities to protect infrastructure, applications, and deployment environments while supporting SOC 2 compliance.