Senior Detection Engineer - Cloud

Reposted Yesterday
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka, IND
In-Office
Mid level
Artificial Intelligence • Security • Cybersecurity
The Role
Develop, tune, and maintain network-based threat detections by analyzing network traffic, writing Suricata signatures and detection logic, simulating attacks, collaborating with data scientists and security researchers, participating in threat hunting and incident response, and continuously measuring and improving detection effectiveness.
Summary Generated by Built In

Vectra® is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises.

The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond to the most advanced cyber-attacks. With 35 patents in AI-driven threat detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai. 

Position Overview 

We are seeking an experienced Threat Detection Engineer to extend Vectra's detection capabilities across cloud and identity environments, with additional exposure to network-based threat detection. 

Vectra's Attack Signal Production Group is responsible for building Vectra's core threat detection and prioritization technology, leveraging AI and other methods to alert customers to critical threats across their cloud, identity, and network environments. 

ThreatDetection Engineers work closely with Data Scientists who are developing AI models, and Security Researchers who are researching thethreat landscapeand assisting modeling efforts. This role will focus primarily on developing detections for cloud and identity attack behaviours, including threats across AWS, Azure, GCP, and identity platforms such as Microsoft Entra ID. 

The ideal candidate has hands-on experience investigating cloud and identity threats using telemetry such as authentication and audit logs, CloudTrail, cloud platform logs, and network flow data. Familiarity with network threat models, protocols, and network-based telemetry is important, particularly as cloud detection increasingly incorporates data sources such as VPC and flow logs. 

The role is primarily focused on cloud and identity threat detection, while providing the versatility to contribute to network detection initiatives where relevant. 

 

Responsibilities and Accountabilities 

  • Research cloud and identity attack behaviours and identify opportunities for new detections. 
  • Develop, test, and maintain detection logic using Python and other appropriate detection technologies. 
  • Analyze telemetry from cloud and identity environments, including authentication activity, control-plane activity, audit logs, application logs, and network flow logs. 
  • Develop detections across common cloud platforms such as AWS, Azure as well as identity environments such as Microsoft Entra ID. 
  • Investigate malicious activity and reproduce attacker techniques to validate detection hypotheses. 
  • Collaborate with Data Scientists and Security Researchers to improve detection coverage and accuracy.  
  • Continuously assess detection effectiveness and improve detections based on real-world data. 
  • Stay current with emerging cloud, identity, and network attacker techniques and TTPs. 
  • Work with large and diverse security datasets using technologies and techniques such as Python, notebooks, SQL, Pandas, and cloud analytics platforms. 
  • Contribute to network threat detection where appropriate, including analysis of network protocols, flow data, PCAPs, and network attack behaviours. 

 

Attitudes and Behaviours 

  • Focus on impact and results; work on the right problems and drive them through to completion. 
  • Demonstrate curiosity and a strong investigative mindset when working with unfamiliar attacker behaviours, telemetry, or technologies. 
  • Show drive and resourcefulness in overcoming technical ambiguity and incomplete information. 
  • Have a track record of successfully solving complex and ambiguous problems. 
  • Balance detection coverage with detection quality, scalability, and maintainability. 
  • Demonstrate high integrity and an ability to collaborate effectively across Security Research, Data Science, Engineering, and Product teams. 

 

Qualifications and Experience 

  • 6+ years of cybersecurity experience, preferably focused on threat detection, security research, threat hunting, incident response, or detection engineering. 
  • Strong experience investigating threats in cloud and identity environments. 
  • Hands-on knowledge of AWS/Azure cloud platform. 
  • Strong understanding of identity concepts, cloud and identity attack techniques; experience with Microsoft Entra ID is preferred. 
  • Experience working with security telemetry such as CloudTrail, cloud audit logs, authentication logs, flow logs, PCAPS and network telemetry.  
  • Working proficiency in Python, including experience using Python for data analysis, automation, investigation, or detection development. 
  • Working knowledge of network security fundamentals, protocols, and network threat models. 
  • Familiarity with large-scale analytics or data platforms such as Databricks, cloud-native log analytics platforms, or equivalent technologies. 
  • Excellent technical, analytical, communication, and collaboration skills. 

 

Preferred Experience 

  • Experience building and operating production-quality cloud or identity detections, rather than solely investigating alerts generated by existing products. 
  • Experience developing detections using multiple telemetry sources or correlating activity across identity, cloud control-plane, workload, and network data. 
  • Experience with adversary simulation or offensive security techniques in AWS, Azure or identity environments. 
  • Experience analyzing network traffic using tools such as Wireshark, Zeek, Suricata, or similar technologies. 
  • Optional certifications such as OSCP, GCIA, GCDA, GSEC, cloud security certifications, or equivalent practical experience. 

Vectra provides a comprehensive total rewards package that supports the financial, physical, mental and overall health of our employees and their families. Compensation includes competitive base pay, incentive plan eligibility, and participation in the employee equity plan (stock options). Specific benefits offered varies by location, but commonly include health care insurance, income protection / life insurance, access to retirement savings plans, behavioral & emotional wellness services, generous time away from work, and a comprehensive employee recognition program.

Vectra is committed to creating a diverse environment and is proud to be an equal opportunity employer. 

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. 

 

Skills Required

  • 4-6 years of cybersecurity experience
  • Expertise in writing signatures with Suricata
  • Proficiency in Python and Bash scripting
  • Proficiency with Sigma and YARA-L
  • Experience with Linux/Unix and Wireshark
  • Familiarity with PCAPs, flow logs, and cloud logs
  • Knowledge of attacker techniques and tools (e.g., Metasploit, Cobalt Strike) and operational threat intelligence experience
  • Scripting, software development, engineering, or DevOps experience and experience with source control (preferably Git)
  • Excellent communication and teamwork skills
  • Optional certifications: OSCP, GCIA, GCDA, GSEC
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
460 Employees
Year Founded: 2011

What We Do

Vectra® is the leader in threat detection and response – from cloud and data center workloads to user and IoT devices. Its Cognito® platform accelerates threat detection and investigation using AI to enrich network metadata it collects and stores with the right context to detect, hunt and investigate known and unknown threats in real time. Vectra offers four applications on the Cognito platform to address high-priority use cases. Cognito Stream™ sends security-enriched metadata to data lakes and SIEMs. Cognito Recall™ is a cloud-based application to store and investigate threats in enriched metadata. Cognito Detect™ uses AI to reveal and prioritize hidden and unknown attackers at speed. And Cognito Detect for Office 365 and Azure AD™ finds and stops attacks in enterprise SaaS applications and the Microsoft 365 ecosystem. For more information, visit vectra.ai.

Similar Jobs

BlackLine Logo BlackLine

Cloud Engineer

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
1810 Employees

Micron Technology Logo Micron Technology

Principal Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
45000 Employees

Optum Logo Optum

Senior Manager AI/ML Engineering

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
160000 Employees

Optum Logo Optum

Senior Software Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
160000 Employees

Similar Companies Hiring

Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
New York, New York
700 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account