
Security Operations Engineer II (Employer of Record)
Credit Acceptance3 months ago
Remote, IndiaMid Level
Responsibilities
- Operate, tune, administer, and troubleshoot enterprise EDR, SIEM/SOAR, WAF/proxy, email security, and related security tools.
- Detect, analyze, contain, eradicate, and recover from security incidents and respond to SOC alerts and outages.
- Author and tune detection rules, analyze log data and block events, improve signal quality, and reduce false positives.
- Build automation, playbooks, API integrations, and an automation backlog for high-frequency Security Operations tasks.
- Implement CI/CD pipelines and Infrastructure-as-Code workflows for consistent and auditable security configuration changes.
- Manage proxy filtering, SSL inspection, URL/category policies, identity-aware policies, geo/risk-based controls, exceptions, and performance troubleshooting.
- Maintain security dashboards, uptime and coverage metrics, asset inventories, documentation, diagrams, configuration baselines, upgrade schedules, license compliance, and key/secret rotations.
- Support vulnerability management, research vulnerabilities and attacker techniques, and report residual risk and security-control analysis.
- Provide on-call support for tooling availability and ingestion/normalization issues, including nights, weekends, and holidays.
- Conduct knowledge transfers through runbooks, how-to guides, tabletop exercises, and training sessions.
Requirements
- Bachelor’s degree in computer science, Information Systems, Data Science, or a closely related field, or equivalent experience.
- At least 2 years of experience in cybersecurity, anomaly detection, SOC detection, threat analytics, SIEM, IT, operations incident response, network security, or security engineering.
- Basic experience administering, deploying, and managing security tools, including WAF/proxy and SIEM/SOAR platforms.
- Experience scripting in Python and/or PowerShell, building API integrations, and working with JSON and YAML.
- Experience with CI/CD and Git workflows and Infrastructure-as-Code for security configurations.
- Basic understanding of TLS/SSL, HTTP, identity-aware policies, and egress/ingress routing.
- Experience with EDR, IDS, or IPS monitoring tools.
- Understanding of the MITRE ATT&CK Framework, Cyber Kill Chain, incident response processes, risk management, CVEs, cyber threats, and vulnerability mitigation.
- Ability to produce formal and informal reports, briefings, and security-control analysis, with strong documentation and change-management discipline.
- Preferred certifications include GSEC, GCIA/GCED, GCDA, AZ-500, SC-200/SC-100, Network+, or CCNA.
- Preferred experience includes WAF rulesets, Infrastructure-as-Code automation, detection engineering using KQL/SPL, log pipelines, data normalization, Zero Trust architecture, and ZTNA posture policies.
Benefits
- Remote work arrangement with regular overlap with U.S. business hours.
- Employer-of-Record employment in India with locally compliant payroll, benefits, and statutory coverage.
- Full-time integration with Credit Acceptance’s global team while legally employed through the EoR partner.
- Participation in on-call rotations, including nights, weekends, and holidays.