Senior Security Engineer
Oracle
Oracle
Join our innovative Integrated Security Operations Center (ISOC) in Bengaluru as a Security Analyst. This role is crucial for maintaining 24x7 vigilance over our technology environment.
You'll be at the forefront of monitoring, investigating, and responding to security alerts. Your primary focus will be on real-time alert triage, accurately distinguishing between genuine threats and normal activity, assessing potential impact, and executing authorized actions swiftly.
As you grow, your responsibilities will expand to include incident response, threat detection, intelligence gathering, and contributing to overall security enhancements. This is an excellent opportunity to shape a new security operations center and gain extensive hands-on experience.
Key responsibilities include monitoring and triaging alerts from various security platforms (SIEM, EDR, identity, email, network, cloud). You will analyze logs and evidence to determine alert validity, scope, and business impact, adhering to established response playbooks and escalating critical issues. Maintaining detailed investigation records and ensuring smooth shift handoffs are also vital.
Further duties involve supporting incident response by collecting evidence, developing timelines, and assisting with containment and recovery. You will contribute to post-incident reviews, identify areas for improvement in playbooks and procedures, and pinpoint opportunities for automation.
The role also includes assisting in the development and tuning of detection rules, reviewing threat intelligence to inform investigations, and supporting threat-hunting activities. Special projects may involve integrating new security data sources, evaluating tools, and developing automation scripts.
We are looking for candidates with a strong foundation in security operations, an understanding of common attack techniques, and experience in incident investigation. Familiarity with Windows, Linux, networking, authentication, and enterprise/cloud services is essential.
Practical exposure to security alerts, logs, and tools like SIEM or EDR is required. You should possess sound analytical judgment, the ability to follow procedures diligently, and know when to escalate issues. Excellent written and verbal communication skills are necessary for documentation and collaboration.
This role requires a willingness to work scheduled shifts, including nights, weekends, and holidays. Typically, 1-4 years of relevant experience in security operations, incident response, or IT operations is expected. Strong internships, academic projects, or equivalent practical experience are also considered. A degree in cybersecurity, computer science, or a related field, or equivalent practical experience, is preferred.
Oracle
Information Technology & Services