Security Operations Engineer

Reposted 16 Hours Ago
Be an Early Applicant
Bangalore, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Software
The Role
Develops and matures cybersecurity detections, correlation rules, dashboards, policies, and response workflows across identity, endpoint, network, cloud, SaaS, DLP, vulnerability, and asset data. The role supports incident triage and investigation, automates enrichment using Python and APIs, improves alert quality, applies threat intelligence and MITRE ATT&CK, and creates playbooks and operational guidance to strengthen security operations.
Summary Generated by Built In

We’re in an unbelievably exciting area of tech and are fundamentally reshaping the data storage industry. Here, you lead with innovative thinking, grow along with us, and join the smartest team in the industry.

This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.

THE ROLE

You will partner with the security operations lead and broader security team to develop and mature security use cases that apply across the company’s environment and operations. Your mission is to build and refine the detections, policies, and response logic that enable the team to identify real attacks, misuse, intrusions, and data loss events with speed and confidence.

This is not a passive monitoring role. You will be expected to understand how the business operates, how attackers move, where meaningful signals live, and how to translate that knowledge into durable security content and response workflows. Success in this role is measured not by alert volume, but by signal quality, attack reduction, faster containment, and continuous operational improvement.

 

WHAT YOU’LL DO
  • Design, implement, and maintain high-fidelity detections, correlation rules, alerts, dashboards, and use cases in Splunk and related security platforms.
  • Build detections across multiple data domains, including identity, endpoint, network, cloud infrastructure, SaaS applications, DLP, vulnerability, and asset posture.
  • Correlate signals from diverse tooling and data sources to identify attacker behavior, misuse, anomalous activity, and material security risk.
  • Partner with business units, IT, engineering, and internal security stakeholders to map business processes and workloads to security use cases and required telemetry.
  • Support and participate in incident triage, investigation, containment, and post-incident improvement activities.
  • Develop enrichment and automation workflows using Python, APIs, and security tooling to improve analyst efficiency and response consistency.
  • Improve detection quality by tuning noisy alerts, reducing false positives, and increasing true positive rates.
  • Collaborate on logging strategy, event onboarding, normalization, parsing, correlation, retention, reporting, and platform customization.
  • Apply threat intelligence, attacker tradecraft, and frameworks such as MITRE ATT&CK, CVE/CVSS, and risk context to drive meaningful detections.
  • Create playbooks, runbooks, detection documentation, and operational guidance for responders and analysts.
  • Use lessons learned from incidents, hunts, and threat research to continuously improve content, coverage, and response workflows.
  • Help mature a security operations model that brings together detection, alerting, investigation, and response rather than treating them as isolated functions. 
What You Will Help Build
  • High-signal detections for credential misuse, privilege abuse, lateral movement, endpoint compromise, cloud and SaaS misuse, suspicious administrative activity, insider risk indicators, and sensitive data movement.
  • Risk-informed detections that combine activity with identity context, asset criticality, exposure data, vulnerability posture, and threat intelligence.
  • Response workflows that reduce manual effort and improve speed, consistency, and quality during investigations.
  • A detection program that focuses on real outcomes: prevention, earlier detection, faster containment, and reduced operational noise.

 

WHAT YOU BRING
  • 6+ years of experience in cybersecurity, or a related technical field
  • 3+ years of hands-on experience in incident response, detection engineering, security operations, or SIEM engineering
  • Strong hands-on experience with a SIEM platform; direct experience with Splunk is strongly preferred
  • Solid understanding of the incident response lifecycle, including triage, scoping, containment, eradication, recovery, and post-incident learning
  • Strong understanding of foundational networking, systems, cloud, and security principles
  • Ability to write scripts and automate tasks using Python or a similar language
  • Ability to work with APIs, integrate data sources, and automate enrichment or response actions
  • Strong analytical thinking and the ability to translate ambiguous threats or operational gaps into concrete detection logic
  • Excellent written and verbal communication skills, with the ability to collaborate effectively across technical and non-technical teams
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field

 

Preferred 
  • Exposure to SIEMs (e.g., Splunk) or SOAR platforms (e.g., Tines, XSOAR)
  • Experience with SOC technologies such as IDS/IPS, UTM firewalls, EDR, anti-virus, network-based threat detection, and netflow.
  • Familiarity with software development practices and secure coding principles
  • Experience with cloud-native monitoring (e.g., AWS Config, CloudTrail, Audit Logs)
  • Security certifications: GCIH, AWS Security Specialty, or equivalent

We are primarily an in-office environment and therefore, you will be expected to work from the Bangalore office in compliance with Everpure's policies, unless you are on PTO, or work travel, or other approved leave.

#LI-ONSITE

WHAT YOU CAN EXPECT FROM US:

  • Innovation: We celebrate those who think critically, like a challenge, and aspire to be trailblazers.
  • Growth: We give you the space and support to grow along with us and to contribute to something meaningful. We have been named Fortune's Best Workplaces in Technology™, Fortune's Best Workplaces in the Bay Area™, and certified as a Great Place to Work®!
  • Team: We build each other up and set aside ego for the greater good.

And because we understand the value of bringing your full and best self to work, we offer a variety of perks to manage a healthy balance, including flexible time off, wellness resources, and company-sponsored team events. Check out purebenefits.com for more information.

ACCOMMODATIONS AND ACCESSIBILITY:

Candidates with disabilities may request accommodations for all aspects of our hiring process. For more on this, contact us at [email protected] if you’re invited to an interview.

OUR COMMITMENT TO A STRONG AND INCLUSIVE TEAM:

We’re forging a future where everyone finds their rightful place and where every voice matters. Where uniqueness isn’t just accepted but embraced. That’s why we are committed to fostering the growth and development of every person, cultivating a sense of community through our Employee Resource Groups and advocating for inclusive leadership.

Everpure is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other characteristic legally protected by the laws of the jurisdiction in which you are being considered for hire.

Join us and bring your best.

Bring your bold.

Pure and simple.

Skills Required

  • 6+ years of experience in cybersecurity or a related technical field
  • 3+ years of hands-on experience in incident response, detection engineering, security operations, or SIEM engineering
  • Strong hands-on experience with a SIEM platform; Splunk experience strongly preferred
  • Understanding of the incident response lifecycle, including triage, scoping, containment, eradication, recovery, and post-incident learning
  • Understanding of networking, systems, cloud, and security principles
  • Ability to write scripts and automate tasks using Python or a similar language
  • Ability to work with APIs, integrate data sources, and automate enrichment or response actions
  • Strong analytical thinking and ability to translate threats or operational gaps into detection logic
  • Excellent written and verbal communication skills
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field
  • Exposure to SIEM or SOAR platforms such as Splunk, Tines, or XSOAR
  • Experience with IDS/IPS, UTM firewalls, EDR, antivirus, network-based threat detection, or NetFlow
  • Familiarity with software development practices and secure coding principles
  • Experience with cloud-native monitoring such as AWS Config, CloudTrail, or Audit Logs
  • Security certification such as GCIH or AWS Security Specialty

Everpure Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Everpure and has not been reviewed or approved by Everpure.

  • Equity Value & Accessibility Equity and stock purchase programs are described as meaningful parts of total compensation, with RSUs and an ESPP highlighted as strengths.
  • Strong & Reliable Incentives Sales compensation is structured to support long sales cycles, including policies that pay full commission until the first sale for new or white‑space accounts.
  • Healthcare Strength Health coverage is portrayed as comprehensive, with multiple medical options, fully covered vision, dental PPO choices, mental‑health resources, and company HSA contributions.

Everpure Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Santa Clara, CA
4,090 Employees
Year Founded: 2009

What We Do

Pure Storage (NYSE:PSTG) helps innovators build a better world with data. Pure's data solutions enable SaaS companies, cloud service providers, and enterprise and public sector customers to deliver real-time, secure data to power their mission-critical production, DevOps, and modern analytics environments in a multi-cloud environment. One of the fastest growing enterprise IT companies in history, Pure Storage enables customers to quickly adopt next-generation technologies, including artificial intelligence and machine learning, to help maximize the value of their data for competitive advantage. And with a Satmetrix-certified NPS customer satisfaction score in the top one percent of B2B companies, Pure's ever-expanding list of customers are among the happiest in the world.

Similar Jobs

Elfonze Technologies Pvt Ltd Logo Elfonze Technologies Pvt Ltd

Cybersecurity Security Operations Engineer(Illumio

Cloud • Information Technology • Software • Consulting
In-Office
Bengaluru North, Yelahanka, Bengaluru Urban, Karnataka, IND
286 Employees
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
3970 Employees
In-Office
Bengaluru, Bengaluru Urban, Karnataka, IND
26035 Employees
In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
3970 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account