Senior Security Engineer
Oracle
Oracle
Join our new Integrated Security Operations Center (ISOC) in Bengaluru as a Security Analyst. This role focuses on monitoring, investigating, and responding to security alerts across our technology landscape. You will be crucial in our 24x7 alert triage, assessing threats, and taking appropriate actions. As you grow, you'll contribute to incident response, detection engineering, threat intelligence, and security enhancement projects.
This is an exciting opportunity to shape a new security operations center while gaining hands-on experience. You will have the chance to take on more responsibility in investigations and contribute significantly to critical security initiatives.
Monitor and investigate security alerts from SIEM, EDR, identity, email, network, and cloud platforms. Assess alert validity, severity, and business impact by correlating logs and evidence. Execute response playbooks, perform containment and remediation, and escalate complex issues. Maintain detailed investigation records and ensure smooth shift handoffs. Collaborate with security, IT, and business teams to resolve incidents and improve response capabilities.
Support incident response efforts, including evidence collection, timeline development, scoping, containment, and recovery. Participate in post-incident reviews to refine playbooks and operational knowledge. Identify opportunities for automation and workflow improvements based on recurring alert patterns. Contribute to detection rule development, testing, and tuning to enhance security coverage and minimize false positives. Utilize threat intelligence to inform investigations and detection strategies.
A foundational understanding of security operations, common attack vectors, and incident investigation is essential. Familiarity with Windows, Linux, networking, authentication, and enterprise/cloud services is required. Experience with security alerts, logs, and tools such as SIEM or EDR is highly beneficial.
You'll need strong analytical judgment and the ability to follow procedures while knowing when to escalate. Excellent written and verbal communication skills are crucial for documentation and cross-shift collaboration. A willingness to work scheduled shifts, including nights, weekends, and holidays, is necessary. Typically, 1-4 years of relevant experience in security operations, incident response, or IT operations is expected; strong internships, labs, or equivalent practical experience are also valued. A degree in cybersecurity, computer science, or a related field, or equivalent practical experience, is required.
Oracle
Information Technology & Services