Atos
Atos
Atos provides digital transformation services and technology solutions for organizations across consulting, healthcare, logistics, and other industries. Its work spans cloud and infrastructure, digital business platforms, technology consulting, cybersecurity, user experience, and enterprise digital transformation. The company also supports major international events as an official IT partner, including UEFA and the Olympic Games, while advancing innovation and sustainability across its technology services.

Identity Threat and Exposure Service Architect - Atos, Bangalore Onsite

Design and develop identity threat detection and exposure management services for Atos in Bangalore. Focus on ITDR, ISPM, attack-path analysis, detection engineering, and SOC containment.

Description

  • Design and develop identity security services
  • Create reference architectures and assess and select supporting platforms
  • Define ITDR and ISPM service offerings
  • Model identity attack paths as graphs, including escalation through cloud roles
  • Relate identity attack techniques and telemetry to the MITRE ATT&CK framework
  • Build detections and behavioural baselines
  • Measure detection coverage against MITRE ATT&CK and reduce false positives
  • Create SOAR playbooks and containment actions through APIs
  • Define models governing containment authority
  • Deploy detection content or containment authority processes within a SOC
  • Contribute to discussions on alert quality

Requirements

  • Experience architecting and developing identity security services, including reference architecture, platform assessment and selection, and service definition rather than implementation alone
  • Understanding of Active Directory and Microsoft Entra ID security internals, including Kerberos, ACLs, delegation, tiering, conditional access, and token models; Okta knowledge is advantageous
  • Practical-depth knowledge of identity attack techniques mapped to MITRE ATT&CK credential access, privilege escalation, lateral movement, and persistence, including Kerberoasting, pass-the-hash or pass-the-ticket, DCSync, ADCS abuse, token theft and replay, MFA fatigue, OAuth abuse, consent abuse, and related telemetry
  • Experience treating attack-path analysis as a graph problem, including cloud role escalation, with tools such as BloodHound, PingCastle, and Purple Knight
  • Hands-on experience with at least one ITDR platform: Microsoft Defender for Identity, CrowdStrike Falcon Identity Protection, Silverfort, Semperis, or Vectra AI
  • Hands-on experience with at least one ISPM platform: Radiant Logic, Semperis, Veza, Tenable Identity Exposure, or Silverfort
  • Experience in detection engineering and behavioural baselining with Sentinel and KQL, Splunk, or Sigma, including MITRE ATT&CK coverage mapping and false-positive management
  • Experience designing response automation and containment through SOAR playbooks, API-based actions, and containment authority models
  • Strong security operations knowledge, including introducing detection content or containment authority into a SOC and participating in alert-quality discussions
  • Threat hunting and deception design experience, including honeytokens and decoy accounts, is desirable
  • Experience with exposure management platforms such as Tenable One, Microsoft Security Exposure Management, or Wiz is desirable
  • API-level PAM platform experience with Idira or CyberArk, or BeyondTrust, is desirable
  • Knowledge of NIS2 and DORA incident-reporting obligations and GDPR constraints affecting behavioural monitoring is desirable

Benefits

  • A workplace where diversity and inclusion are central to the company culture
  • A fair and equitable working environment
  • A stated commitment to ESG and corporate social responsibility

Related Jobs

Ambush

Senior Machine Learning and AI Engineer

Ambush

Build production-grade generative AI and agent workflows for Ambush’s financial services clients. Develop Python and FastAPI services, SQL data workflows, retrieval-augmented generation, and cloud-based AI systems.

Open