Roles Directory

24+ cybersecurity roles, defined for modern security orgs

Practical definitions of the cybersecurity positions we staff most often — what each role actually does, the skills hiring managers screen for, and current market demand in India and globally.

Security Operations & Detection

The teams watching production for active threats and responding to incidents.

Very high demand

SOC Analyst (Tier 1)

First line of triage in the security operations centre — reviews alerts from SIEM/EDR, validates true positives, and escalates.

Core skills

  • SIEM (Splunk, Sentinel)
  • EDR triage
  • Windows/Linux logs
  • MITRE ATT&CK basics
Very high demand

SOC Analyst (Tier 2)

Owns deeper investigation — correlates events across tools, contains compromised hosts, and tunes detections.

Core skills

  • Incident triage
  • Threat hunting basics
  • Detection engineering
  • Forensics fundamentals
High demand

Incident Responder (DFIR)

Leads response to confirmed incidents — disk and memory forensics, containment, eradication, and post-incident reports.

Core skills

  • Volatility / KAPE
  • Disk imaging
  • Malware triage
  • Chain-of-custody
High demand

Threat Hunter

Proactively searches the environment for adversary behaviour that bypassed automated detections.

Core skills

  • Hypothesis-driven hunting
  • KQL / SPL
  • ATT&CK mapping
  • Endpoint telemetry
High demand

Detection Engineer

Builds and maintains the detection content library — Sigma rules, KQL, Snort/Suricata, with measurable coverage.

Core skills

  • Sigma / KQL
  • CI/CD for detections
  • Log pipelines
  • Tuning false positives
High demand

Threat Intelligence Analyst

Tracks threat actors and campaigns relevant to the business; turns intelligence into detections and exec briefings.

Core skills

  • OSINT
  • MISP / TIP platforms
  • Actor profiling
  • Strategic & tactical reporting

Cloud & Infrastructure Security

Securing the platforms modern applications actually run on.

Very high demand

Cloud Security Engineer

Designs guardrails, IAM boundaries, and detection across AWS, Azure, or GCP environments.

Core skills

  • AWS/Azure/GCP security services
  • IaC (Terraform)
  • CSPM tooling
  • Identity-aware controls
High demand

Kubernetes Security Engineer

Hardens container platforms — admission control, runtime detection, supply-chain integrity.

Core skills

  • Kubernetes RBAC
  • OPA/Gatekeeper
  • Falco
  • Sigstore / SBOMs
Steady demand

Network Security Engineer

Operates firewalls, segmentation, VPN/ZTNA, and inspection across hybrid networks.

Core skills

  • Palo Alto / Fortinet
  • Zero Trust architecture
  • TLS inspection
  • BGP/Routing fundamentals
Very high demand

DevSecOps Engineer

Embeds security checks into CI/CD — SAST, SCA, secrets scanning, IaC policy — without slowing delivery.

Core skills

  • GitHub Actions / GitLab CI
  • Snyk / Semgrep
  • Policy as code
  • Developer enablement

Application & Product Security

Roles focused on the code, APIs, and products customers actually use.

Very high demand

Application Security Engineer

Threat-models features, runs secure code review, and partners with engineering on remediation.

Core skills

  • Threat modelling
  • OWASP Top 10 / ASVS
  • Code review (Go/Java/Python/TS)
  • API security
High demand

Product Security Engineer

Embedded in product teams to ship secure features by default — security design, paved roads, bug-bounty triage.

Core skills

  • Secure design patterns
  • SDK hardening
  • Bug-bounty triage
  • Customer-facing security
High demand

Penetration Tester

Simulates real-world attackers against web, mobile, network, and cloud targets to surface exploitable issues.

Core skills

  • Burp Suite
  • Network pentesting
  • Cloud attack paths
  • Clear written reporting
Steady demand

Red Team Operator

Runs objective-based adversary simulations, evading detection and testing the blue team end-to-end.

Core skills

  • C2 frameworks
  • Initial access tradecraft
  • OPSEC
  • Detection evasion

Identity, Data & Privacy

Where access decisions and sensitive data live.

Very high demand

IAM Engineer

Designs and operates identity, SSO, MFA, and lifecycle — the control plane for every other access decision.

Core skills

  • Okta / Entra ID / Ping
  • SAML / OIDC / SCIM
  • Privileged access
  • Joiner-mover-leaver flows
High demand

Data Security Engineer

Classifies, protects, and monitors sensitive data across warehouses, lakes, and SaaS.

Core skills

  • DLP tooling
  • Encryption / KMS
  • Data classification
  • Snowflake / BigQuery controls
Emerging demand

Privacy Engineer

Operationalises privacy — data mapping, DSR automation, privacy-by-design reviews — alongside legal.

Core skills

  • DPIAs
  • Data inventory tooling
  • Consent platforms
  • GDPR / DPDPA

Governance, Risk & Compliance

Translating regulation and risk appetite into controls the business can ship against.

Steady demand

GRC Analyst

Owns control evidence, policy reviews, and risk register updates day-to-day.

Core skills

  • ISO 27001 / SOC 2
  • Risk registers
  • Audit evidence collection
  • Vendor reviews
High demand

Security Compliance Engineer

Automates control evidence and continuous compliance against SOC 2, ISO 27001, HIPAA, PCI-DSS.

Core skills

  • Drata / Vanta / Sprinto
  • Control-as-code
  • Audit liaison
  • Infra evidence pipelines
Steady demand

Third-Party Risk Manager

Runs vendor due diligence and ongoing monitoring of the supply chain's security posture.

Core skills

  • SIG / CAIQ
  • Vendor scoring
  • Contractual security terms
  • Continuous monitoring tools

Leadership

Roles that own strategy, budget, and the security operating model.

High demand

Security Architect

Sets reference architectures across cloud, identity, and data; reviews high-impact designs before build.

Core skills

  • Reference architectures
  • Threat modelling at scale
  • Zero Trust
  • Cross-team influence
Steady demand

SOC Manager

Runs the SOC — staffing, shift rotations, MTTD/MTTR metrics, and detection roadmap.

Core skills

  • SOC operating metrics
  • People management
  • Vendor management (MSSP)
  • On-call design
Steady demand

CISO / Head of Security

Owns the overall security strategy, budget, and board-level reporting for the business.

Core skills

  • Risk quantification
  • Board reporting
  • Program leadership
  • Regulatory engagement
Emerging demand

Virtual CISO (vCISO)

Fractional security leadership for companies that need executive-level oversight without a full-time hire.

Core skills

  • Program design
  • Roadmap delivery
  • Audit & customer trust
  • Fractional engagement model

Need one of these roles filled — or filled by you?

CipherForce places vetted cybersecurity talent on contract, permanent, and managed-pod engagements. Talk to us about open roles, or join the network.