Senior Security Engineer
Oracle
Oracle
Join our innovative Integrated Security Operations Center (ISOC) in Bengaluru as a Security Analyst. This role focuses on monitoring, investigating, and responding to security alerts across our diverse technology landscape. You will be at the forefront of 24x7 alert triage, discerning critical threats from routine activity, assessing impact, and executing swift, authorized actions. As your skills and the operational needs grow, you'll also contribute to critical areas like incident response, detection engineering, threat intelligence, and proactive security enhancements.
Oracle is a leader in AI and cloud solutions, impacting billions of lives globally. We foster an environment where everyone is empowered to contribute, offering competitive benefits and supporting flexible work arrangements. We are dedicated to inclusivity and provide accommodations for individuals with disabilities throughout the employment process.
As a Security Analyst, you will: - Conduct vigilant security monitoring, triage, and response across SIEM, EDR, identity, email, network, and cloud security platforms. - Analyze logs and evidence to validate alert severity, scope, and business impact, adhering to response playbooks. - Execute authorized containment and remediation actions, escalating complex issues as needed. - Maintain meticulous investigation records and ensure seamless shift handoffs. - Collaborate with security, IT, and business teams to resolve incidents and enhance response capabilities. - Support incident response efforts, including evidence collection, timeline development, and recovery phases. - Contribute to post-incident reviews, refining playbooks and improving operational knowledge. - Identify opportunities for automation and workflow optimization. - Assist in developing, testing, and tuning detection rules to boost coverage and minimize false positives. - Integrate threat intelligence into investigations and detection strategies. - Support threat hunting activities and indicator validation. - Participate in special projects, such as onboarding new security data sources and evaluating tools. - Contribute to the development and execution of business continuity and disaster recovery plans.
We are looking for candidates with: - A solid understanding of security operations, common attack vectors, and incident investigation principles. - Familiarity with Windows, Linux, networking concepts, authentication protocols, and enterprise/cloud services. - Practical experience or exposure to security alerts, logs, and tools like SIEM or EDR. - Strong analytical skills and the ability to follow procedures while knowing when to escalate. - Excellent written and verbal communication, with a knack for documentation and cross-team collaboration. - A willingness to work scheduled shifts, including nights, weekends, and holidays. - Typically 1-4 years of relevant experience in security operations, incident response, IT operations, or related fields. Internships, labs, or equivalent practical experience are also highly valued. - A degree in cybersecurity, computer science, or a related field, or equivalent practical experience.
Additionally, helpful skills include experience investigating phishing or malware, familiarity with MITRE ATT&CK, basic scripting (Python, PowerShell, SQL, KQL, SPL), exposure to SOAR platforms, or relevant certifications like Security+ or CySA+.
Oracle
IT Consulting