MTS-2 Security Operations Engineer

Posted 7 Days Ago
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka, IND
In-Office
Mid level
eCommerce • Retail
The Role
Monitors and investigates cybersecurity alerts in a 24x7 CSIRT environment, performing alert and phishing triage, incident response, containment, threat detection, threat intelligence, and escalation. The role analyzes SIEM and EDR data, identifies indicators of compromise, supports forensic evidence preservation, improves detection content, and helps evaluate security technologies and processes. Rotating weekend and holiday shifts are required.
Summary Generated by Built In

At eBay, we're more than a global ecommerce leader — we’re changing the way the world shops and sells. Our platform empowers millions of buyers and sellers in more than 190 markets around the world. We’re committed to pushing boundaries and leaving our mark as we reinvent the future of ecommerce for enthusiasts.

Our customers are our compass, authenticity thrives, bold ideas are welcome, and everyone can bring their unique selves to work — every day. We're in this together, sustaining the future of our customers, our company, and our planet.

Join a team of passionate thinkers, innovators, and dreamers — and help us connect people and build communities to create economic opportunity for all.

Working within eBay's Computer Security Incident Response Team (CSIRT) Operations team, you will play a critical role in protecting eBay's information assets by monitoring, investigating, and responding to cybersecurity events. As a member of the CSIRT Ops team, you will help identify potential threats, perform alert  triage, phishing triage, respond to enquiries to CSIRT, escalate potential incidents to the Incident Response team. 

You'll work in a fast-paced, highly collaborative environment where you'll contribute to the continuous monitoring, triage of the threats and malicious actions and help defend one of the world's largest e-commerce platforms.

Core job functions include:
  • Security Monitoring – Monitor global security events and alerts across enterprise security platforms in a 24x7 operational environment. Identify, classify, and prioritize security events for investigation.

  • Incident Response – Perform initial investigation, triage, and analysis of security events. Support incident response activities by documenting findings, participating in investigation calls, and escalating incidents that require additional expertise in accordance with established procedures.

  • Containment & Investigation – Execute approved containment actions to limit the impact of security incidents and assist with forensic preservation and investigation activities while maintaining appropriate chain of custody.

  • Threat Detection – Analyze security alerts, identify indicators of compromise (IOCs), and recommend improvements to detection content and alert tuning to improve monitoring effectiveness and reduce false positives.

  • Threat Intelligence – Collect, analyze, and disseminate relevant open-source intelligence (OSINT) to support investigations and improve situational awareness.

  • Technology Improvement – Participate in the testing, evaluation, implementation, and continuous improvement of security technologies, detection capabilities, and operational processes.

  • Escalations – Perform timely verbal and documented escalations to Detection & Response Engineers and on-call personnel when incidents require advanced investigation or exceed established response thresholds.

  • Coverage – Participate in a rotating 24x7 shift schedule, including weekends and holidays, as required to support continuous global security operations.

To be successful in this position, you should be familiar with:

  • Security Operations – Security event monitoring, alert triage, incident classification, and response workflows within a Security Operations Center (SOC) or CSIRT environment.

  • Incident Response – Security investigation methodologies, containment techniques, evidence preservation, and incident documentation.

  • Threat Detection – Experience working with Security Information and Event Management (SIEM) platforms to investigate alerts, analyze logs, and identify malicious activity.

  • Endpoint & System Security – Understanding of Windows, Linux, and endpoint security concepts, including basic forensic acquisition and investigation techniques.

  • Networking Fundamentals – Knowledge of TCP/IP networking protocols including HTTP, DNS, FTP, DHCP, ARP, and experience using network analysis tools such as Wireshark or tcpdump.

  • Threat Intelligence – Familiarity with indicators of compromise (IOCs), MITRE ATT&CK, and open-source intelligence (OSINT) techniques.

  • Scripting & Automation – Experience with Python or a similar scripting language to automate repetitive operational tasks and improve investigation efficiency.

  • Security Technologies – Experience with endpoint detection and response (EDR), SIEM platforms, and other enterprise security monitoring tools.

Qualifications:
  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.

  • Minimum of three (3) years of professional experience in Security Operations, Security Incident Response, Threat Detection, Digital Forensics, or a related cybersecurity discipline.

  • Experience investigating security events and responding to cybersecurity incidents in an enterprise environment.

  • Experience working with SIEM, EDR, or other enterprise security monitoring technologies.

Must have at least one of the following certifications:
  • SANS GIAC (GCIA, GCIH, GCED, GCFA, GCFE, GMON, GNFA, GREM, or equivalent)

  • ISC2 (CISSP, CCSP)

  • CompTIA Security+

  • Cisco (CCNA, CCNP)

  • EC-Council (CEH, ECIH, CHFI)

  • Offensive Security (OSCP)

In addition, a minimum of three (3) years of specialised experience in one or more of the following areas:

  • Security Operations Center (SOC) or Computer Security Incident Response Team (CSIRT)

  • Security Incident Response and Investigation

  • Threat Detection and Monitoring

  • Digital Forensics and Evidence Preservation

  • Cyber Threat Intelligence

Additional Details

eBay is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, veteran status, and disability, or other legally protected status. If you have a need that requires accommodation, please contact us at [email protected]. We will make every effort to respond to your request for accommodation as soon as possible. View our accessibility statement to learn more about eBay's commitment to ensuring digital accessibility for people with disabilities.


We use cookies to enhance your experience and may use AI tools for administrative tasks in the hiring process. To learn how we handle your personal data and use AI responsibly, please visit our Talent Privacy Notice, Privacy Center, and AI Hiring Guidelines.

Skills Required

  • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, a related field, or equivalent practical experience
  • At least three years of professional experience in security operations, security incident response, threat detection, digital forensics, or a related cybersecurity discipline
  • Experience investigating security events and responding to cybersecurity incidents in an enterprise environment
  • Experience working with SIEM, EDR, or other enterprise security monitoring technologies
  • At least one approved certification, including SANS GIAC, ISC2, CompTIA Security+, Cisco, EC-Council, or Offensive Security certifications
  • At least three years of specialized experience in SOC or CSIRT operations, incident response and investigation, threat detection and monitoring, digital forensics and evidence preservation, or cyber threat intelligence

eBay Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about eBay and has not been reviewed or approved by eBay.

  • Healthcare Strength Medical, dental, and vision coverage begin on the date of hire, complemented by mental health resources, an EAP, disability coverage, FSAs, and wellness initiatives.
  • Leave & Time Off Breadth A robust mix of PTO, paid holidays, flexible work styles, parental leave, and a four‑week paid sabbatical after five years supports work‑life balance.
  • Equity Value & Accessibility Total compensation commonly includes stock components, with access to an employee stock purchase plan at a discount and stock awards enhancing overall packages.

eBay Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, CA
26,035 Employees

What We Do

eBay Inc. is a global commerce leader that connects millions of buyers and sellers around the world. We exist to enable economic opportunity for individuals, entrepreneurs, businesses and organizations of all sizes. Our portfolio of brands includes eBay Marketplace and eBay Classifieds Group, operating in 190 markets around the world. We offer sellers the ability to grow a business with little barrier to entry regardless of size, background or geographic location. We never compete with our sellers. We win when our sellers succeed. Buyers who shop on our Marketplace and Classifieds platforms enjoy a highly personalized experience with an unparalleled selection at great value.

Similar Jobs

Toast Logo Toast

Staff Software Engineer

Cloud • Fintech • Food • Information Technology • Software • Hospitality
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
5000 Employees
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
289097 Employees

Flywire Logo Flywire

Senior Security Engineer

Fintech • Payments • Software
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
1200 Employees

Ericsson Logo Ericsson

Cloud Architect

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
88000 Employees

Similar Companies Hiring

PRIMA Thumbnail
Travel • Software • Marketing Tech • Hospitality • eCommerce
US
15 Employees
Scotch Thumbnail
Artificial Intelligence • eCommerce • Fintech • Payments • Retail • Software • Analytics
US
35 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account