Senior Security Engineer
Oracle
Oracle
Join our evolving Integrated Security Operations Center (ISOC) in Bengaluru as a Security Analyst. This role focuses on continuous 24x7 alert triage, investigating security alerts, and responding to threats across our diverse technology landscape. Your expertise will be crucial in distinguishing real threats from routine activities, assessing their impact, and implementing timely actions.
As you grow, you will contribute to critical areas like incident response, detection engineering, threat intelligence, and proactive security enhancements, shaping the future of our security operations.
Monitor and triage security alerts from SIEM, EDR, identity, email, network, and cloud platforms. Correlate logs to determine alert validity, severity, and business impact.
Execute response playbooks for containment and remediation, escalating complex issues. Maintain detailed investigation records and ensure thorough shift handoffs.
Collaborate with security, IT, and business teams to resolve incidents and improve response effectiveness.
Support incident response by collecting evidence, developing timelines, and assisting with containment and recovery efforts.
Contribute to post-incident reviews, enhancing playbooks and operational knowledge. Identify patterns for workflow improvements and automation opportunities.
Assist in developing and tuning detection rules to boost coverage and reduce false positives. Utilize threat intelligence to inform investigations and detection strategies.
We seek candidates with foundational knowledge in security operations, common attack vectors, and incident investigation techniques. Familiarity with Windows, Linux, networking, authentication, and enterprise or cloud services is expected.
Practical experience with security alerts, logs, and tools like SIEM or EDR is essential. Strong analytical judgment and the ability to adhere to procedures while knowing when to escalate are key.
Excellent written and verbal communication skills, including documentation and cross-shift collaboration, are required. A willingness to work scheduled shifts, including nights, weekends, and holidays, is necessary.
Typically, 1-4 years of relevant experience in security operations, incident response, IT operations, or a related field is preferred. Strong internships, labs, or equivalent practical experience are also valued.
A degree in cybersecurity, computer science, or a related field, or equivalent practical experience, is required.
Oracle
IT Consulting