Senior Security Engineer
Oracle
Oracle
Join our pioneering Integrated Security Operations Center (ISOC) in Bengaluru as a Security Analyst. This role is crucial for maintaining our 24x7 security posture, focusing on monitoring, investigating, and responding to alerts across our diverse technology landscape. You'll be the first line of defense, expertly identifying and handling security events.
As you grow, opportunities will emerge to contribute to critical areas such as incident response, advanced detection engineering, threat intelligence gathering, and implementing strategic security improvements. This is a chance to shape a new security operation while developing deep investigative skills.
We are committed to fostering an inclusive environment where diverse perspectives drive innovation. At Oracle, you'll be part of a company dedicated to AI and cloud solutions that positively impact billions of lives worldwide.
Key responsibilities include:
- Performing comprehensive security monitoring and alert triage across SIEM, EDR, identity, email, network, and cloud security platforms. - Analyzing logs and evidence to accurately assess alert validity, severity, scope, and business impact. - Executing response playbooks, performing authorized containment and remediation, and escalating complex issues. - Maintaining meticulous investigation records and ensuring thorough shift handoffs. - Collaborating with security, IT, and business teams to resolve incidents and enhance response capabilities. - Supporting incident response by collecting evidence, developing timelines, and aiding in containment and recovery. - Contributing to post-incident reviews and driving improvements in playbooks and operational knowledge. - Identifying opportunities for automation and workflow enhancements. - Assisting in the development, testing, and tuning of detection rules. - Applying threat intelligence to investigations and detection strategies. - Contributing to special projects like data source onboarding, tool evaluation, and automation building.
We are looking for individuals with:
- Foundational knowledge of security operations, common attack techniques, and incident investigation methodologies. - Familiarity with Windows, Linux, networking fundamentals, authentication protocols, and enterprise/cloud services. - Practical exposure to security alerts, logs, and tools such as SIEM or EDR. - Strong analytical judgment with the ability to adhere to procedures and recognize when escalation is necessary. - Excellent written and verbal communication skills, essential for documentation and cross-team collaboration. - A willingness to work scheduled shifts, including nights, weekends, and holidays. - Approximately 1-4 years of relevant experience in security operations, incident response, IT operations, or a related field. Internships, labs, or equivalent practical experience are highly valued. - A degree in cybersecurity, computer science, or a related field, or equivalent practical experience.
Nice to have: - Experience investigating phishing, malware, suspicious authentication, endpoint, or cloud security events. - Familiarity with MITRE ATT&CK framework and threat-informed investigations. - Basic scripting or query skills in Python, PowerShell, SQL, KQL, or SPL. - Exposure to SOAR platforms, detection development, or incident response exercises. - Relevant certifications like Security+, CySA+.
Oracle
IT Consulting