27 days ago
Bengaluru, IndiaSenior
Responsibilities
- Research cloud and identity attack behaviors and identify opportunities for new detections.
- Develop, test, maintain, and improve detection logic using Python and other detection technologies.
- Analyze authentication, control-plane, audit, application, cloud, identity, and network telemetry.
- Develop detections across AWS, Azure, GCP, and Microsoft Entra ID environments.
- Investigate malicious activity and reproduce attacker techniques to validate detection hypotheses.
- Collaborate with Data Scientists and Security Researchers to improve detection coverage and accuracy.
- Assess detection effectiveness using real-world data and maintain scalable, high-quality detections.
- Contribute to network threat detection through analysis of protocols, flow data, PCAPs, and network attack behaviors.
Requirements
- 6+ years of cybersecurity experience, preferably in threat detection, security research, threat hunting, incident response, or detection engineering.
- Strong experience investigating threats in cloud and identity environments.
- Hands-on knowledge of AWS and Azure cloud platforms.
- Strong understanding of identity concepts and cloud and identity attack techniques; Microsoft Entra ID experience is preferred.
- Experience working with CloudTrail, cloud audit logs, authentication logs, flow logs, PCAPs, and network telemetry.
- Working proficiency in Python for data analysis, automation, investigation, or detection development.
- Working knowledge of network security fundamentals, protocols, and network threat models.
- Familiarity with large-scale analytics or data platforms such as Databricks, cloud-native log analytics platforms, or equivalent technologies.
- Excellent technical, analytical, communication, and collaboration skills.
- Preferred experience building production-quality cloud or identity detections and correlating multiple telemetry sources.
- Preferred experience with adversary simulation or offensive security techniques in AWS, Azure, or identity environments.
- Preferred experience analyzing network traffic using Wireshark, Zeek, Suricata, or similar tools.
- Optional certifications include OSCP, GCIA, GCDA, GSEC, cloud security certifications, or equivalent practical experience.
Benefits
- Comprehensive total rewards package supporting employees' and families' financial, physical, mental, and overall health.
- Competitive base pay, incentive plan eligibility, and participation in an employee equity plan with stock options.
- Health care insurance, income protection and life insurance, retirement savings plans, behavioral and emotional wellness services, generous time away from work, and an employee recognition program; offerings vary by location.
About Vectra
Vectra builds an AI-driven threat detection and response platform (NDR/XDR) for enterprises operating hybrid and multi-cloud environments. Its software correlates signals across network, cloud, identity, and SaaS systems to surface attacker behavior, prioritize incidents, and automate response, sold as a subscription platform. Founded in 2011 and headquartered in San Jose, California, Vectra is privately held and serves security teams in regulated and large-scale organizations.
