bluedoor data·Job Postings API·bluedoor.sh ↗

HomeCompaniesIndiacareers Lennox Icims ComSr Security Analyst - Cloud Security

Sr Security Analyst - Cloud Security

Indiacareers Lennox Icims Com · Chennai, UNAVAILABLE, IN · Hybrid · Active · iCIMS

Job facts

FieldValue
CompanyIndiacareers Lennox Icims Com
TitleSr Security Analyst - Cloud Security
Normalized title-
Department / teamInformation Technology
LocationUNAVAILABLE, IN, United States
Work modelHybrid / Hybrid
Employment typeOTHER
Salary-
Statusactive
ATS provideriCIMS
Posted / first seen2026-06-02 / 2026-06-03
Changed / last seen2026-06-03 / 2026-06-06

Related slices

PageWhat it containsOpen
Company jobsActive postings from Indiacareers Lennox Icims Com.Open
Company breakdownsRole, location, ATS, and work model facets for this company.Open
ATS provider jobsActive postings observed through iCIMS.Open
Provider filtered searchThe same provider as a filtered job collection.Open
City jobsActive postings in UNAVAILABLE.Open
Department jobsActive postings in Information Technology.Open
Work model jobsActive Hybrid postings.Open
Lifecycle eventsOpen, update, close, and reopen events for this posting.Open
Original postingCanonical source or apply URL captured from the ATS.Open

Linked records

CompanyIndiacareers Lennox Icims Com
Source4cb68ff0-4996-49c1-a078-75524cdbce6c
ATS provideriCIMS

Description

Company Profile Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed. Lennox is a global community that values each team member’s contributions and offers a supportive environment for career development. Come, stay, and grow with us. Job Description We are seeking a Cloud Security Analyst (IC2) to strengthen cloud security monitoring, detection engineering, and posture management across Azure environments. This position involves developing and optimizing Sentinel analytics rules, ingesting hybrid and on-premises logs, and managing Defender for Cloud operations. The analyst will partner with SOC, Cloud CoE, Infrastructure, and DevOps teams to improve Secure Score, reduce vulnerabilities, and operationalize actionable detections aligned to MITRE ATT&CK. Role Summary Develop, test, deploy, and fine‑tune Microsoft Sentinel analytics rules (scheduled/NRT), including entity mapping, incident grouping, and alert thresholds to minimize false positives and improve signal quality. Create and maintain KQL queries for detection engineering, threat hunting, and operational dashboards/workbooks; document detection logic, assumptions, and expected outcomes. Integrate and onboard data sources into Microsoft Sentinel, including Azure-native logs (Activity, Diagnostics, Azure resource logs, Entra ID/Azure AD logs, Defender alerts) and onprem/hybrid sources (Syslog/CEF/Windows events) using modern ingestion patterns. Perform data ingestion troubleshooting (missing data, parsing issues, normalization), validate data quality, and ensure appropriate retention/coverage for security investigations and audit needs. Operate Microsoft Defender for Cloud for posture management: review recommendations, prioritize remediation, track Secure Score improvement, and coordinate fixes with resource owners. Support vulnerability reduction initiatives (SQL/VM/container findings), validate remediation, and report progress with clear metrics and evidence. Conduct security investigations and triage cloud-related alerts/incidents; collect artifacts, validate user/activity context, and collaborate with SOC/IRT on containment, recovery, and lessons learned. Contribute to container security monitoring (AKS/ACR) by supporting baseline hardening, vulnerability assessment workflows, and runtime alert review in partnership with platform teams. Maintain SOPs/runbooks for Sentinel and Defender for Cloud operations (rule lifecycle, tuning, connector onboarding, investigation playbooks). Assist with periodic control checks and evidence preparation for audits (cloud governance, logging, monitoring, access controls). Align Sentinel detections with MITRE ATT&CK mapping and maintain documentation for auditability and knowledge transfer. Collaborate with infrastructure teams to ensure EDR coverage across Azure VMs and support incident investigations with endpoint telemetry. Integrate critical data sources (for example, API marketplace Front Door and Azure WAF logs) into Sentinel and transition monitoring ownership to SOC with SOPs. Enable Microsoft Defender Vulnerability Assessment for Azure SQL servers and expand coverage across all subscriptions. Drive measurable reduction in Azure SQL vulnerabilities . Qualifications Bachelor’s degree in Computer Science, Information Security, or a related discipline (or equivalent experience). 3–5 years of experience in Security Operations, Cloud Security, SIEM engineering, or related roles. Azure fundamentals knowledge with working familiarity in subscriptions, resource groups, IAM/RBAC, networking basics, and Azure logging/monitoring concepts. Certifications: AZ‑900 (required). AZ‑500 (preferred). Working knowledge of Microsoft Sentinel: analytics rules, incidents, workbooks, automation (basic), and KQL query development. Log source onboarding knowledge: Azure diagnostics/resource logs, Syslog/CEF basics, Windows Security event collection concepts, and validation of ingestion/coverage. Security investigation skills: triage, log analysis, suspicious activity identification, evidence documentation, and escalation. Basic knowledge of authentication and access controls (MFA, Conditional Access concepts, least privilege, privileged access hygiene). Compliance awareness (basic): PCI DSS expectations around logging/monitoring and access control; ability to support audit evidence collection. One-point awareness of FedRAMP: baseline controls and continuous monitoring mindset (conceptual knowledge is sufficient at IC2). Basic container security awareness: cluster hardening concepts, image vulnerability basics, and Kubernetes security hygiene. Preferred / Nice-to-have Skills Hands-on experience integrating on‑prem logs to Sentinel using Azure Arc + Azure Monitor Agent (AMA) and Data Collection Rules (DCR). Experience mapping detections to MITRE ATT&CK techniques and maintaining a detection engineering backlog. Microsoft Defender for Cloud experience across CSPM and workload protection plans (Servers, SQL, Storage, Containers). Exposure to regulatory/compliance dashboards and control evidence collection (PCI, NIST-aligned controls, FedRAMP concepts). Scripting/automation basics (PowerShell/Python) and Infrastructure-as-Code familiarity (ARM/Bicep/Terraform) for repeatable security configurations. Experience working with ITSM workflows (ServiceNow) for remediation tracking and operational reporting. Tools & Technologies Microsoft Sentinel (Analytics Rules, Incidents, Workbooks, Content Hub, Data Connectors) Kusto Query Language (KQL) Microsoft Defender for Cloud (Secure Score, Recommendations, Regulatory Compliance, Alerts) Azure Monitor / Log Analytics / Azure Monitor Agent (AMA) + Data Collection Rules (DCR) Microsoft Entra ID (Azure AD) – MFA/Conditional Access concepts Azure platform logging: Activity Logs, Diagnostic Settings, Resource Logs Security log formats: Syslog, CEF; Windows Security Events (concepts) Containers (basic): AKS, ACR and related security controls

Full job record

Job IDe021b8498edd1cd2ebd34cdb78c4c2f1b6d77e42
Org ID021c8db2-07b4-4103-b74b-cefcd586b9be
Source ID4cb68ff0-4996-49c1-a078-75524cdbce6c
Board ID4cb68ff0-4996-49c1-a078-75524cdbce6c
Providericims
Provider Job Key53132
TitleSr Security Analyst - Cloud Security
Normalized Title
Statusactive
Activeyes
Location TextChennai, UNAVAILABLE, IN
DepartmentInformation Technology
Team
Employment TypeOTHER
Workplace Typehybrid
Remote Policyhybrid
CountryUnited States
RegionIN
CityUNAVAILABLE
Salary RawCompany Profile Lennox (NYSE: LII) Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed. Lennox is a global community that values each team member’s contributions and offers a supportive environment for career development. Come, stay, and grow with us. Job Description We are seeking a Cloud Security Analyst (IC2) to strengthen cloud security monitoring, detection engineering, and posture management across Azure environments. This position involves developing and optimizing Sentinel analytics rules, ingesting hybrid and on-premises logs, and managing Defender for Cloud operations. The analyst will partner with SOC, Cloud CoE, Infrastructure, and DevOps teams to improve Secure Score, reduce vulnerabilities, and operationalize actionable detections aligned to MITRE ATT&CK. Role Summary Develop, test, deploy, and fine‑tune Microsoft Sentinel analytics rules (scheduled/NRT), including entity mapping, incident grouping, and alert thresholds to minimize false positives and improve signal quality. Create and maintain KQL queries for detection engineering, threat hunting, and operational dashboards/workbooks; document detection logic, assumptions, and expected outcomes. Integrate and onboard data sources into Microsoft Sentinel, including Azure-native logs (Activity, Diagnostics, Azure resource logs, Entra ID/Azure AD logs, Defender alerts) and onprem/hybrid sources (Syslog/CEF/Windows events) using modern ingestion patterns. Perform data ingestion troubleshooting (missing data, parsing issues, normalization), validate data quality, and ensure appropriate retention/coverage for security investigations and audit needs. Operate Microsoft Defender for Cloud for posture management: review recommendations, prioritize remediation, track Secure Score improvement, and coordinate fixes with resource owners. Support vulnerability reduction initiatives (SQL/VM/container findings), validate remediation, and report progress with clear metrics and evidence. Conduct security investigations and triage cloud-related alerts/incidents; collect artifacts, validate user/activity context, and collaborate with SOC/IRT on containment, recovery, and lessons learned. Contribute to container security monitoring (AKS/ACR) by supporting baseline hardening, vulnerability assessment workflows, and runtime alert review in partnership with platform teams. Maintain SOPs/runbooks for Sentinel and Defender for Cloud operations (rule lifecycle, tuning, connector onboarding, investigation playbooks). Assist with periodic control checks and evidence preparation for audits (cloud governance, logging, monitoring, access controls). Align Sentinel detections with MITRE ATT&CK mapping and maintain documentation for auditability and knowledge transfer. Collaborate with infrastructure teams to ensure EDR coverage across Azure VMs and support incident investigations with endpoint telemetry. Integrate critical data sources (for example, API marketplace Front Door and Azure WAF logs) into Sentinel and transition monitoring ownership to SOC with SOPs. Enable Microsoft Defender Vulnerability Assessment for Azure SQL servers and expand coverage across all subscriptions. Drive measurable reduction in Azure SQL vulnerabilities . Qualifications Bachelor’s degree in Computer Science, Information Security, or a related discipline (or equivalent experience). 3–5 years of experience in Security Operations, Cloud Security, SIEM engineering, or related roles. Azure fundamentals knowledge with working familiarity in subscriptions, resource groups, IAM/RBAC, networking basics, and Azure logging/monitoring concepts. Certifications: AZ‑900 (required). AZ‑500 (preferred). Working knowledge of Microsoft Sentinel: analytics rules, incidents, workbooks, automation (basic), and KQL query development. Log source onboarding knowledge: Azure diagnostics/resource logs, Syslog/CEF basics, Windows Security event collection concepts, and validation of ingestion/coverage. Security investigation skills: triage, log analysis, suspicious activity identification, evidence documentation, and escalation. Basic knowledge of authentication and access controls (MFA, Conditional Access concepts, least privilege, privileged access hygiene). Compliance awareness (basic): PCI DSS expectations around logging/monitoring and access control; ability to support audit evidence collection. One-point awareness of FedRAMP: baseline controls and continuous monitoring mindset (conceptual knowledge is sufficient at IC2). Basic container security awareness: cluster hardening concepts, image vulnerability basics, and Kubernetes security hygiene. Preferred / Nice-to-have Skills Hands-on experience integrating on‑prem logs to Sentinel using Azure Arc + Azure Monitor Agent (AMA) and Data Collection Rules (DCR). Experience mapping detections to MITRE ATT&CK techniques and maintaining a detection engineering backlog. Microsoft Defender for Cloud experience across CSPM and workload protection plans (Servers, SQL, Storage, Containers). Exposure to regulatory/compliance dashboards and control evidence collection (PCI, NIST-aligned controls, FedRAMP concepts). Scripting/automation basics (PowerShell/Python) and Infrastructure-as-Code familiarity (ARM/Bicep/Terraform) for repeatable security configurations. Experience working with ITSM workflows (ServiceNow) for remediation tracking and operational reporting. Tools & Technologies Microsoft Sentinel (Analytics Rules, Incidents, Workbooks, Content Hub, Data Connectors) Kusto Query Language (KQL) Microsoft Defender for Cloud (Secure Score, Recommendations, Regulatory Compliance, Alerts) Azure Monitor / Log Analytics / Azure Monitor Agent (AMA) + Data Collection Rules (DCR) Microsoft Entra ID (Azure AD) – MFA/Conditional Access concepts Azure platform logging: Activity Logs, Diagnostic Settings, Resource Logs Security log formats: Syslog, CEF; Windows Security Events (concepts) Containers (basic): AKS, ACR and related security controls
Salary Min
Salary Max
Salary Currency
Salary Period
Source URLhttps://indiacareers-lennox.icims.com/jobs/53132/sr-security-analyst---cloud-security/job
Apply URLhttps://indiacareers-lennox.icims.com/jobs/53132/sr-security-analyst---cloud-security/job
First Seen At2026-06-03 14:02:33Z
Last Seen At2026-06-06 20:12:52Z
Last Checked At2026-06-06 20:12:52Z
Last Changed At2026-06-03 14:02:33Z
Inactive At
Source Posted At2026-06-02 04:00:00Z
Source Updated At2026-06-03 10:58:19Z
Raw Payload Uris3://job-postings-prod-raw-590183727216/raw/provider=icims/board=indiacareers-lennox.icims.com/date=2026-06-06/2026-06-06T20-12-50-074Z-eaf4e384f0807c5ff9c0674577209d57e66f61ddb7bf4cb95deb894286fb2dfd.json
Event Fields
{
  "content_hash": "d080046051c763f57bab3e628abb7086053d815ca606fc41edf73b9dd5a4a264",
  "source_hash": "1c573f3c078aa4cdc9231af99e8db42a0ebebaa225dcd12129106080118aa057",
  "last_changed_at": "2026-06-03T14:02:33.905Z",
  "active_status": "active"
}
Parsed Structured
{
  "language": "en",
  "location": {
    "raw": "Chennai, UNAVAILABLE, IN",
    "city": "UNAVAILABLE",
    "region": "IN",
    "country": "United States",
    "is_remote": false,
    "confidence": 0.9
  },
  "salary_max": null,
  "salary_min": null,
  "inferred_at": "2026-06-06T20:12:52.127Z",
  "launch_scope": {
    "reason": "english_us_canada",
    "included": true,
    "language": "en",
    "location": {
      "raw": "Chennai, UNAVAILABLE, IN",
      "city": "UNAVAILABLE",
      "region": "IN",
      "country": "United States",
      "is_remote": false,
      "confidence": 0.9
    },
    "countries": [
      "United States"
    ]
  },
  "remote_policy": "hybrid",
  "salary_period": null,
  "workplace_type": "hybrid",
  "salary_currency": null
}
Extensions
{}
Native Structured
{
  "json_ld": {
    "url": "https://indiacareers-lennox.icims.com/jobs/53132/sr-security-analyst---cloud-security/job",
    "@type": "JobPosting",
    "title": "Sr Security Analyst - Cloud Security",
    "@context": "http://schema.org",
    "datePosted": "2026-06-02T04:00:00.000Z",
    "description": "<h2>Company Profile</h2>\n<p><strong>Lennox (NYSE: LII)</strong> Driven by 130 years of legacy, HVAC and refrigeration success, Lennox provides our residential and commercial customers with industry-leading climate-control solutions. At Lennox, we win as a team, aiming for excellence and delivering innovative, sustainable products and services. Our culture guides us and creates a workplace where all employees feel heard and welcomed. Lennox is a global community that values each team member’s contributions and offers a supportive environment for career development. Come, stay, and grow with us.</p>\n<h2>Job Description</h2>\n<p>We are seeking a Cloud Security Analyst (IC2) to strengthen cloud security monitoring, detection engineering, and posture management across Azure environments. This position involves developing and optimizing Sentinel analytics rules, ingesting hybrid and on-premises logs, and managing Defender for Cloud operations.  The analyst will partner with SOC, Cloud CoE, Infrastructure, and DevOps teams to improve Secure Score, reduce vulnerabilities, and operationalize actionable detections aligned to MITRE ATT&CK.<strong>Role Summary</strong></p>\n<ul>\n <li>Develop, test, deploy, and fine‑tune Microsoft Sentinel analytics rules (scheduled/NRT), including entity mapping, incident grouping, and alert thresholds to minimize false positives and improve signal quality.</li>\n <li>Create and maintain KQL queries for detection engineering, threat hunting, and operational dashboards/workbooks; document detection logic, assumptions, and expected outcomes.</li>\n <li>Integrate and onboard data sources into Microsoft Sentinel, including Azure-native logs (Activity, Diagnostics, Azure resource logs, Entra ID/Azure AD logs, Defender alerts) and onprem/hybrid sources (Syslog/CEF/Windows events) using modern ingestion patterns.</li>\n <li>Perform data ingestion troubleshooting (missing data, parsing issues, normalization), validate data quality, and ensure appropriate retention/coverage for security investigations and audit needs.</li>\n <li>Operate Microsoft Defender for Cloud for posture management: review recommendations, prioritize remediation, track Secure Score improvement, and coordinate fixes with resource owners.</li>\n <li>Support vulnerability reduction initiatives (SQL/VM/container findings), validate remediation, and report progress with clear metrics and evidence.</li>\n <li>Conduct security investigations and triage cloud-related alerts/incidents; collect artifacts, validate user/activity context, and collaborate with SOC/IRT on containment, recovery, and lessons learned.</li>\n <li>Contribute to container security monitoring (AKS/ACR) by supporting baseline hardening, vulnerability assessment workflows, and runtime alert review in partnership with platform teams.</li>\n <li>Maintain SOPs/runbooks for Sentinel and Defender for Cloud operations (rule lifecycle, tuning, connector onboarding, investigation playbooks).</li>\n <li>Assist with periodic control checks and evidence preparation for audits (cloud governance, logging, monitoring, access controls).</li>\n <li>Align Sentinel detections with MITRE ATT&CK mapping and maintain documentation for auditability and knowledge transfer.</li>\n <li>Collaborate with infrastructure teams to ensure EDR coverage across Azure VMs and support incident investigations with endpoint telemetry.</li>\n <li>Integrate critical data sources (for example, API marketplace Front Door and Azure WAF logs) into Sentinel and transition monitoring ownership to SOC with SOPs.</li>\n <li>Enable Microsoft Defender Vulnerability Assessment for Azure SQL servers and expand coverage across all subscriptions.</li>\n <li>Drive measurable reduction in Azure SQL vulnerabilities .</li>\n</ul>\n<h2>Qualifications</h2>\n<ul>\n <li>Bachelor’s degree in Computer Science, Information Security, or a related discipline (or equivalent experience).</li>\n <li>3–5 years of experience in Security Operations, Cloud Security, SIEM engineering, or related roles.</li>\n <li>Azure fundamentals knowledge with working familiarity in subscriptions, resource groups, IAM/RBAC, networking basics, and Azure logging/monitoring concepts.</li>\n <li>Certifications: AZ‑900 (required). AZ‑500 (preferred).</li>\n <li>Working knowledge of Microsoft Sentinel: analytics rules, incidents, workbooks, automation (basic), and KQL query development.</li>\n <li>Log source onboarding knowledge: Azure diagnostics/resource logs, Syslog/CEF basics, Windows Security event collection concepts, and validation of ingestion/coverage.</li>\n <li>Security investigation skills: triage, log analysis, suspicious activity identification, evidence documentation, and escalation.</li>\n <li>Basic knowledge of authentication and access controls (MFA, Conditional Access concepts, least privilege, privileged access hygiene).</li>\n <li>Compliance awareness (basic): PCI DSS expectations around logging/monitoring and access control; ability to support audit evidence collection.</li>\n <li>One-point awareness of FedRAMP: baseline controls and continuous monitoring mindset (conceptual knowledge is sufficient at IC2).</li>\n <li>Basic container security awareness: cluster hardening concepts, image vulnerability basics, and Kubernetes security hygiene.</li>\n</ul>\n<p><strong>Preferred / Nice-to-have Skills</strong></p>\n<ul>\n <li>Hands-on experience integrating on‑prem logs to Sentinel using Azure Arc + Azure Monitor Agent (AMA) and Data Collection Rules (DCR).</li>\n <li>Experience mapping detections to MITRE ATT&CK techniques and maintaining a detection engineering backlog.</li>\n <li>Microsoft Defender for Cloud experience across CSPM and workload protection plans (Servers, SQL, Storage, Containers).</li>\n <li>Exposure to regulatory/compliance dashboards and control evidence collection (PCI, NIST-aligned controls, FedRAMP concepts).</li>\n <li>Scripting/automation basics (PowerShell/Python) and Infrastructure-as-Code familiarity (ARM/Bicep/Terraform) for repeatable security configurations.</li>\n <li>Experience working with ITSM workflows (ServiceNow) for remediation tracking and operational reporting.</li>\n</ul>\n<p><strong>Tools & Technologies</strong></p>\n<ul>\n <li>Microsoft Sentinel (Analytics Rules, Incidents, Workbooks, Content Hub, Data Connectors)</li>\n <li>Kusto Query Language (KQL)</li>\n <li>Microsoft Defender for Cloud (Secure Score, Recommendations, Regulatory Compliance, Alerts)</li>\n <li>Azure Monitor / Log Analytics / Azure Monitor Agent (AMA) + Data Collection Rules (DCR)</li>\n <li>Microsoft Entra ID (Azure AD) – MFA/Conditional Access concepts</li>\n <li>Azure platform logging: Activity Logs, Diagnostic Settings, Resource Logs</li>\n <li>Security log formats: Syslog, CEF; Windows Security Events (concepts)</li>\n <li>Containers (basic): AKS, ACR and related security controls</li>\n</ul>\n<p> </p>",
    "directApply": true,
    "jobLocation": [
      {
        "@type": "Place",
        "address": {
          "@type": "PostalAddress",
          "postalCode": "600113",
          "addressRegion": "UNAVAILABLE",
          "streetAddress": "UNAVAILABLE",
          "addressCountry": "IN",
          "addressLocality": "Chennai",
          "postOfficeBoxNumber": "UNAVAILABLE"
        }
      }
    ],
    "validThrough": "2027-06-02T04:00:00.000Z",
    "employmentType": "OTHER",
    "hiringOrganization": {
      "name": "Lennox International",
      "@type": "Organization",
      "sameAs": "www.lennoxinternational.com"
    },
    "occupationalCategory": "Information Technology"
  },
  "detail_meta": {
    "url": "https://indiacareers-lennox.icims.com/jobs/53132/sr-security-analyst---cloud-security/job?in_iframe=1",
    "http_status": 200,
    "content_type": "text/html;charset=UTF-8",
    "response_bytes": 45395,
    "compact_response_bytes": 7979,
    "original_response_bytes": 45395
  },
  "sitemap_job": {
    "id": "53132",
    "url": "https://indiacareers-lennox.icims.com/jobs/53132/sr-security-analyst---cloud-security/job",
    "slug": "sr-security-analyst---cloud-security",
    "lastmod": "2026-06-03T06:58:19-04:00"
  },
  "detail_errors": []
}
Get this page with API

Rendered from the bluedoor Job Postings API. Reproduce it:

GET https://api.bluedoor.sh/job-postings/v1/jobs/e021b8498edd1cd2ebd34cdb78c4c2f1b6d77e42?include=descriptionJSON
GET https://api.bluedoor.sh/job-postings/v1/orgs/021c8db2-07b4-4103-b74b-cefcd586b9beJSON
GET https://api.bluedoor.sh/job-postings/v1/sources/4cb68ff0-4996-49c1-a078-75524cdbce6cJSON
GET https://api.bluedoor.sh/job-postings/v1/jobs/e021b8498edd1cd2ebd34cdb78c4c2f1b6d77e42/eventsJSON