Apply now »

Principal Engineer

Gurugram Gurgaon HR, IN

Requisition Number: 105835 

Principal Engineer
Location: This is a hybrid opportunity in Delhi NCR, Bangalore, Hyderabad, Gurugram, Pune and Trivandrum area.

 

Insight at a Glance

  • 14,000+ engaged teammates globally with operations in 25 countries across the globe.
  • Received 35+ industry and partner awards in the past year
  • $9.2 billion in revenue
  • #20 on Fortune’s World's Best Workplaces™ list
  • #14 on Forbes World's Best Employers in IT – 2023
  • #23 on Forbes Best Employers for Women in IT- 2023
  • $1.4M+ total charitable contributions in 2023 by Insight globally

 

Now is the time to bring your expertise to Insight. We are not just a tech company; we are a people-first company. We believe that by unlocking the power of people and technology, we can accelerate transformation and achieve extraordinary results. As a Fortune 500 Solutions Integrator with deep expertise in cloud, data, AI, cybersecurity, and intelligent edge, we guide organisations through complex digital decisions.

 

About the role

 

Insight’s Managed Security Service is seeking a Security Operations Engineer with deep expertise in the Cisco security stack, Cisco XDR, and Splunk to join our growing MSSP practice. This individual will serve as a technical cornerstone within our Security Operations Center, responsible for engineering and operationalizing threat detection, automated response workflows, and client onboarding across the Cisco and Splunk ecosystems.

This is a highly client-facing role. The ideal candidate is not only technically proficient but also an excellent communicator who can translate complex security architectures into clear, actionable guidance for clients and internal stakeholders. You will work hand-in-hand with Client Success Managers to ensure seamless onboarding experiences and ongoing service excellence, serving as a positive ambassador of the Insight Managed Security brand.

 

Key Responsibilities:

  • Cisco  & Security Stack Engineering 
    • Build and maintain Cisco XDR correlation rules, investigation playbooks, and automated response actions tailored to each client’s threat landscape and risk profile. 
    • Engineer cross-product telemetry ingestion and normalization across the Cisco stack and third-party data sources — including non-Cisco EDR, DLP, identity and access management, email security, and other threat-detection-relevant platforms — to maximize XDR detection efficacy and end-to-end visibility across multi-vendor client environments. 
    • Serve as the subject matter expert (SME) for the Cisco security portfolio within the SOC, advising on architecture decisions and integration best practices. 
  • Splunk Administration & Detection Engineering 
    • Administer Splunk Enterprise or Splunk Cloud deployments supporting MSSP operations, including index management, data onboarding, role-based access controls, and performance tuning. 
    • Develop custom SPL-based threat detections, correlation searches, and notable event rules within Splunk Enterprise Security (ES) aligned to MITRE ATT&CK and client-specific use cases. 
    • Build and maintain Splunk dashboards, reports, and visualizations for client-facing security reviews and internal SOC operational metrics. 
    • Manage Technology Add-ons (TAs) and data source integrations — including third-party EDR, DLP, identity providers, cloud security platforms, and other detection-relevant telemetry sources — to ensure consistent log ingestion, field extraction, and CIM compliance across diverse client technology stacks. 
  • Automation & Response Playbooks 
    • Design, develop, and maintain automated security workflows using Splunk SOAR (Phantom), Cisco XDR Automate, or equivalent orchestration platforms. 
    • Author and operationalize incident response playbooks covering detection, triage, containment, eradication, and recovery across client environments. 
    • Continuously evaluate and improve playbook effectiveness through post-incident reviews, tabletop exercises, and mean-time-to-respond (MTTR) analysis. 
    • Collaborate with the SOC analyst team to ensure runbooks and automated actions are properly documented, tested, and maintainable. 
  • Client Onboarding & Advisory 
    • Lead the technical onboarding of new MSSP clients onto Cisco XDR and Splunk platforms, including scoping, requirements gathering, deployment, integration validation, and go-live support. 
    • Conduct client-facing kickoff meetings, architecture workshops, and readiness reviews as a primary technical point of contact during the onboarding lifecycle. 
    • Partner closely with Client Success Managers (CSMs) on a routine basis to ensure alignment between technical delivery and client expectations, escalating risks and providing proactive service improvement recommendations. 
    • Represent the Insight Managed Security Service with professionalism and enthusiasm in all client interactions, reinforcing trust and long-term partnership value. 
    • Contribute to the development of onboarding templates, runbooks, and knowledge base articles that scale the MSSP practice. 

 

What we’re looking for

  • 8+ years of experience in security operations, security engineering, or a managed security services role. 
  • Hands-on production experience on at least three products within the Cisco security stack (e.g., Secure Endpoint, Secure Firewall, Umbrella, Duo, Secure Email, Stealthwatch). 
  • Strong proficiency in Splunk Enterprise and Splunk Enterprise Security, including SPL query development, dashboard creation, data onboarding, and correlation search authoring. 
  • Demonstrated experience creating custom threat detection rules, tuning alert logic, and reducing false positive rates at scale. 
  • Proven experience building automated response playbooks using Splunk SOAR, or similar SOAR platforms. 
  • Direct experience onboarding clients or business units onto security monitoring platforms in an MSSP, MDR, or enterprise SOC environment. 
  • Excellent verbal and written communication skills with a track record of successful client-facing engagement, including leading technical workshops and presenting to non-technical audiences. 
  • Solid understanding of MITRE ATT&CK framework, common threat actor TTPs, and incident response methodologies. 
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent professional experience. 

 

 

What you can expect

We’re legendary for taking care of you, your family and to help you engage with your local community. We want you to enjoy a full, meaningful life and own your career at Insight. Some of our benefits include:

  • Freedom to work from another location—even an international destination—for up to 30 consecutive calendar days per year.
  • Medical Insurance
  • Health Benefits
  • Professional Development: Learning Platform and Certificate Reimbursement
  • Shift Allowance

 

But what really sets us apart are our core values of Hunger, Heart, and Harmony, which guide everything we do, from building relationships with teammates, partners, and clients to making a positive impact in our communities.

 

Join us today, your ambITious journey starts here.

 

When you apply, please tell us the pronouns you use and any reasonable adjustments you may need during the interview process.

At Insight, we celebrate diversity of skills and experience so even if you don’t feel like your skills are a perfect match - we still want to hear from you!

Today's talent leads tomorrow's success. Learn more about Insight: 
https://www.linkedin.com/company/insight/

 

Insight does not accept unsolicited resumes from recruiters or employment agencies. Unsolicited resumes will be treated as direct applications from the candidate, and recruiters or agencies who submit candidates for this position without a prior, written vendor agreement will not be eligible for any form of compensation, even if the candidate is hired.

Insight is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, sexual orientation or any other characteristic protected by law.

 

Insight India Location:Level 16, Tower B, Building No 14, Dlf Cyber City In It/Ites Sez, Sector 24 &25 A Gurugram Gurgaon Hr 122002 India


Job Segment: Computer Science, Cisco, Social Media, Cyber Security, Engineer, Technology, Marketing, Security, Engineering

Apply now »