Build the future of banking.
About the Role:
As a Security Operations Implementation Engineer, you will be playing a pivotal role in enabling Zeta in implementing and integrating SIEMs, detecting and responding to attacks at an early stage and make sure infrastructure and applications are secure. You will work with an amazing peer group that fuels this ambition.
We are looking for a highly motivated SIEM / SOC Engineer with 4-6 years of experience in developing, enhancing, and maintaining enterprise-scale Security Operations and SIEM platforms based on the ELK Stack (Elasticsearch, Logstash, Kibana). The candidate will play a key role in advancing our next-generation security monitoring capabilities by enhancing existing SIEM modules, developing new detection use cases, integrating security technologies such as UEBA, SOAR, Threat Intelligence, and supporting the SOC team with effective detection and response capabilities.
The ideal candidate should possess strong hands-on experience in log parser development, security content engineering, ELK administration, AWS environments, microservices architectures, and open-source security technologies.
Responsibilities:
Design, develop, and maintain high-fidelity detection rules, correlation rules, alerts, and security use cases for newly onboarded and existing log sources. Continuously tune detections to reduce false positives, improve detection fidelity, and expand detection coverage across the environment.
Develop security monitoring and detection content for AWS services, Kubernetes, microservices, Linux, macOS, databases, web applications, firewalls, and other enterprise technologies by leveraging the MITRE ATT&CK framework, threat intelligence, and adversary TTPs.
Onboard new security and application log sources by developing Logstash pipelines, custom parsers, Grok patterns, ingest processors, and enrichment workflows. Analyze raw log formats, normalize events to a common schema, and enrich security telemetry to enable reliable detection and investigation.
Design and maintain operational dashboards, executive dashboards, SOC dashboards, and threat hunting visualizations using optimized OpenSearch Query DSL, aggregations, and visualizations to provide actionable security insights and platform observability.
Integrate Threat Intelligence Platforms (TIP), IOC feeds, and enrichment services with OpenSearch. Develop IOC correlation rules, automated enrichment workflows, and contextual detections to identify malicious activity across ingested telemetry.
Expand the SIEM by implementing advanced capabilities such as UEBA, anomaly detection, OpenSearch Notebooks for investigation playbooks, SOAR workflows for automated response, and AI-driven automation to streamline Level 1 SOC operations.
Collaborate with SOC analysts during alert investigations, threat hunting, and incident response by providing L2/L3 detection engineering support, validating detections, identifying detection gaps, and continuously improving existing security content.
Follow Detection-as-Code practices by developing, testing, version-controlling, and deploying detection content through Git-based workflows and CI/CD pipelines, ensuring consistent, reliable, and scalable delivery of SIEM content.
Skills:
Hands-on experience with any enterprise SIEM platforms such as Elastic/ELK, OpenSearch, Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, Google Chronicle, Wazuh, ELK/EFK or similar solutions.
Experience developing, maintaining, and tuning detection rules, correlation rules, alerts, dashboards, visualizations, and security use cases using SIEM query languages and detection frameworks such as OpenSearch/Elasticsearch Query DSL, Sigma, KQL, SPL, EQL, or equivalent.
Strong experience onboarding log sources by developing custom parsers, Logstash pipelines, Fluentd/Fluent Bit configurations, Grok patterns, ETL pipelines, field mappings, log normalization, and data enrichment workflows.
4–6 years of experience in Detection Engineering, SIEM Engineering, Security Operations, or SOC environments.
Good understanding of SIEM architecture, event correlation, log management, detection engineering, the MITRE ATT&CK framework, Cyber Kill Chain, threat hunting methodologies, attacker TTPs, Threat Intelligence integration, and IOC-based detections.
Experience developing detections and investigating security events across Linux, macOS, databases, web applications, firewalls, WAFs, enterprise infrastructure, and cloud environments.
Familiarity with open-source security technologies such as Wazuh, Suricata, Zeek (Bro), Velociraptor, HELK, EFK, Falco, osquery, or similar security monitoring solutions.
Strong foundation in computer networking, operating systems, authentication and authorization concepts, web technologies, and common attack techniques.
Familiarity with YARA rules, malware detection concepts, and security automation is an added advantage.
Strong analytical, troubleshooting, and investigative skills with the ability to identify detection gaps, validate detections, and continuously improve security monitoring content.
Hands-on experience with AWS environments and a good understanding of core AWS services such as IAM, CloudTrail, VPC, EC2, EKS, S3, CloudWatch, and cloud security monitoring concepts.
Familiarity with Kubernetes, Helm, containerized workloads, microservices architectures, and cloud-native security monitoring, Git, CI/CD Pipeline knowledge etc.
Experience and Qualifications:
- 4 to 6 years of overall experience as Security Operations engineer in medium to large-size product companies.
- Bachelor of Technology (BE/B.Tech), M.Tech/ME in Computer Science or equivalent.
- Must have worked on the ELK/EFK implementation projects, and Logstash data parsing rules.
- Threat intelligence like OSINT, MISP, AlienVault, IDRBT etc.
- Expertise in Log monitoring tools like Splunk, ELK/EFK, SumLogic, Loggly etc.
- Assists in ensuring compliance with industry standards (for example, PCI DSS/3DS, GDPR, ISO 27001, SOC2 etc) by conducting assessments and implementing necessary controls, presenting to auditors.
- Hands on experience in detection engineering, security investigations, incident response and forensics.
- Experience in threat hunting using threat intelligence to investigate potential risks and finding suspicious behaviour.
- Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents.
- Designs, implements, and configures Kibana visualizations as required by the business.
- Configures Logstash, FileBeats, VictoriaMetrics, Prometheus, Velociraptor, Grafana and possibly other ELK/EFK Stack components to collect and store the data necessary to meet business requirements efficiently.
- Strong data analysis skills; ability to independently write scripts/code to parse and analyse complex logs and data and optimize the SIEM system capabilities as well as the audit and logging features of the event log sources.
- Understanding and familiarity with existing TTP frameworks like MITRE ATT&CK, Cyber Kill Chain etc.
Skills Required
- 3-6 years experience in SOC, Detection Engineering, Threat Detection, or Incident Response
- Strong fundamentals in Computer Networking and Operating Systems (Linux/Windows)
- Hands-on experience investigating Linux security incidents and developing Linux-focused detection use cases
- Experience with cloud-native SIEM platforms, preferably AWS OpenSearch
- Experience creating SIEM detection rules, dashboards, parsers, log normalization, and tuning
- Experience with log collection/processing tools such as Logstash, Fluentd, Fluent Bit (or similar ETL)
- Familiarity with SIEM query languages (OpenSearch Query DSL, Sigma, or similar)
- Experience with SOAR automation and playbook development
- Experience with Detection-as-Code workflows using Git and CI/CD
- Proficiency in Python and strong scripting skills (Bash, PowerShell or similar)
- Good understanding of Kubernetes, containers, and microservices-based environments for security monitoring
- Comfortable working with open-source security tools and platforms (ELK, Wazuh, Bro/Zeek)
- Familiarity with MITRE ATT&CK mapping
- Ability to develop and maintain AI-driven capabilities and assist integration of AI agents for SOC operations
Zeta Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Zeta and has not been reviewed or approved by Zeta.
-
Fair & Transparent Compensation — Pay is considered competitive for some roles and markets, with market-aligned offers in certain senior or U.S.-based positions. Overall compensation tends to be seen as fine-to-good rather than top-tier.
-
Parental & Family Support — Parental leave, adoption/fertility support, and childcare coverage are part of the package. These offerings contribute to a well-rounded family support mix even if specifics vary by location.
-
Wellbeing & Lifestyle Benefits — Flexible hours, paid volunteer time, public-transport incentives, concierge services, and workplace perks are highlighted. These lifestyle-oriented perks add breadth beyond core pay and health coverage.
Zeta Insights
What We Do
Founded in 2015, Zeta is a provider of next-gen credit card processing platform. Zeta’s cloud-native and fully API-enabled stack offers a comprehensive range of capabilities, including processing, issuing, lending, core banking, fraud detection, and loyalty programs. With a strong focus on technology, Zeta has over 1700+ employees and contractors, with more than 70% dedicated to technology roles. Operating across the US, UK, Middle East, and Asia, Zeta has served a global customer base of 35+ clients who have issued over 15 million cards on Zeta's platform to date. Backed by prominent investors such as Softbank Vision Fund 2 and Mastercard, Zeta has raised $280 million, at a valuation of $1.5 billion.






