Senior Security Operations Engineer

Couchbase

Bengaluru

On-site

INR 1,500,000 - 2,100,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Couchbase in Bengaluru is hiring a Sr. Security Operations Engineer to join our global security team. The role blends hands-on SecOps with engineering to advance detection, response and AI-assisted protections across cloud, identity, endpoints and data platforms.

You'll own incident triage, build automated workflows, and collaborate with Engineering, SRE, IT and Compliance to reduce risk and strengthen resilience across our CI/CD pipelines and cloud environments.

Qualifications

  • 5–8 years hands-on in security operations.
  • Experience writing and tuning detections in SIEMs.
  • Public cloud security skills (AWS, Azure or GCP) and Kubernetes knowledge.
  • Hands-on EDR operation and tuning.
  • Vulnerability management at scale with remediation tracking.

Responsibilities

  • Own security operations including triage, investigation and containment.
  • Manage SIEM log onboarding, normalization, retention and rule development.
  • Develop incident response playbooks and participate in tabletop exercises.
  • Build AI-assisted security workflows and integrations via API.
  • Operate CSPM/CNAPP tooling across cloud providers.
  • Maintain asset register and coordinate penetration testing.
  • Produce security metrics and governance reporting.

Skills

Security operations
Incident triage
Incident investigation
Cloud security
EDR tuning
Vulnerability management
SIEM
Kubernetes security

Tools

Coralogix
Splunk
Sentinel
Elastic

Job description

Job Description:

Couchbase, the operational data platform for AI, empowers businesses to succeed by bringing data to life in new ways. Major market-leading companies rely on Couchbase for mission critical operational, analytical, mobile and AI workloads. Built to replace legacy infrastructure and fragmented data services, Couchbase empowers enterprises with a unified platform architected for performance, flexibility and global scale.

With Couchbase, organizations bring their data to life, launching game‑changing customer experiences, exploring the limitless potential of AI, and seamlessly extending applications from the cloud to the edge and beyond. Couchbase’s AI‑ready technology and enterprise partnership model eliminate complexity and reduce total cost of ownership, enabling teams to stay agile, innovative and secure.

Couchbase believes data should never slow you down, but act as the foundation for your next breakthrough. Discover why Couchbase is trusted to help the world’s biggest players scale, move fast and stay resilient, no matter what’s next on their roadmap. Visit couchbase.com and follow us on LinkedIn and X.

About Couchbase

Couchbase is the Operational Data Platform for AI. Our customers dont run AI in a lab — they run it in production, where agents remember, reason, and act on live operational data. With the Couchbase AI Data Plane, we give those agents one governed layer for memory, context, tool access, and MCP, deployed anywhere from public cloud to Kubernetes to the edge to air‑gapped environments. Amadeus, Cisco, Comcast, FICO, PepsiCo, United, Verizon, and Wells Fargo trust us with their data.

That means AI security isnt a side topic here. Its adjacent to the product, and its the environment we operate in every day.

The Role

Were hiring a Sr. Security Operations Engineer to join Couchbases global Information Security team as our second dedicated SecOps engineer.

We think the interesting work in security operations right now sits at the intersection of two things. The first is that AI has changed what a capable adversary can do at scale, which changes what detection and response have to look like. The second is that AI is also the most useful thing to happen to defenders in years — and wed rather be early than careful about that.

We use AI internally in security operations, not as a pilot: triage agents that risk‑rank and route findings, automated threat modeling with human review at closure, reachability scoring that separates real exposure from scanner noise, and AI‑assisted detection and response workflows. We want someone who will build on that, push it further, and stay clear‑eyed about where it earns trust and where it doesnt.

Roughly half your time is operational — triage, investigation, containment, tuning. The other half is engineering and program work: building detection content, automating response, and running security capabilities across cloud, identity, endpoint, and AI governance. Youll work across Engineering, SRE, IT, Cloud, Legal, and Compliance, and youll own outcomes rather than tickets.

Key Responsibilities
Detection & Response Operations
  • Own alert triage, investigation, and containment alongside our existing SecOps engineer, supporting a follow-the-sun coverage model.
  • Manage the SIEM day to day: log source onboarding, normalization, retention, correlation rule development, and validation of alert use cases.
  • Maintain the operating model with our managed detection partners — escalation thresholds, containment ownership, and handoff procedures.
  • Measure and report MTTD, MTTR, and MTTC against defined targets; run a regular alert‑tuning cadence.
  • Develop incident‑specific response playbooks and support cross‑functional tabletop exercises.
  • Run hypothesis‑driven threat hunting against available telemetry, with documented hypotheses, resulting detections, and tracked follow‑up.
Automation & AI‑Assisted Security Engineering
  • Build and agent‑based workflows for enrichment, triage, and automated containment.
  • Operate and tune AI triage agents that ingest findings from cloud and vulnerability tooling, rank by severity and reachability, and route to named owners.
  • Integrate security tooling via API so detection, findings, and evidence flow automatically.
  • Automate repetitive operational work — evidence collection, inventory reconciliation, and reporting.
Vulnerability & Exposure Management
  • Run the vulnerability management lifecycle across endpoints, servers, network devices, and cloud workloads: scan coverage, risk‑based prioritization, owner assignment, SLA tracking, and verification.
  • Prioritize on exploitability, reachability, and business context rather than raw CVSS.
  • Maintain an authoritative asset register reconciled across cloud, endpoint, and vulnerability tooling, with automated discovery and per‑asset ownership.
  • Coordinate internal and external penetration testing across corporate, data center, and product environments; track findings to closure and retest.
Cloud & Infrastructure Security
  • Operate CSPM and CNAPP tooling across AWS, Azure, GCP, and Kubernetes, including policy enforcement and exception workflow.
  • Support infrastructure‑as‑code baselines, deployment‑time enforcement, and drift detection.
  • Support key and secrets management: centralized storage, automated rotation, least‑privilege access review, and audit coverage.
  • Operate and tune EDR across workstations, servers, and cloud workloads, and wire alerts into response workflows.
Identity Security
  • Support privileged access management, phishing‑resistant MFA, and risk‑based conditional access; monitor identity risk signals and build detections for credential abuse, MFA fatigue, and session anomalies.
  • Build detections for AI‑enabled social engineering against help desk and finance workflows — impersonation, deepfake‑assisted verification bypass, and account recovery abuse.
  • Support access review automation and joiner/mover/leaver reconciliation evidence.
AI Security & Data Protection
  • Configure and tune DLP for AI channels — labeling coverage, prompt and upload controls, and incident review.
  • Operate shadow‑AI detection and enforcement, including blocking, connector approvals, and exception handling.
  • Support AI use‑case intake, risk tiering, and scoped AI red team exercises against high‑risk agents and applications.
Governance & Reporting
  • Produce security metrics and program reporting for leadership and governance committees.
  • Support audit evidence collection for SOC 2, ISO 27001, and related frameworks.
  • Maintain runbooks, business continuity documentation, and restore and failover test evidence.
Qualifications
Required
  • 5–8 years hands‑on in security operations, with real incident triage, investigation and containment experience.
  • Deep, practical SIEM experience — writing and tuning detections, onboarding log sources, and building correlation logic (Coralogix, Splunk, Sentinel, Elastic, or similar).
  • Strong public cloud security skills on at least one of AWS, Azure, or GCP, plus working knowledge of Kubernetes and container security.
  • Hands‑on EDR operation and tuning (SentinelOne, CrowdStrike, or equivalent).
  • Vulnerability management experience at scale: scanning, risk‑based prioritization, remediation tracking, and
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer New Bangalore, India
Senior Security Operations Engineer New Bangalore, India

Couchbase • Bengaluru

On-site
INR 4,000,000 - 6,500,000
Generous Time Off Program
Wellness Benefits
Retirement program
SE- Security Engineer
SE- Security Engineer

Keka Technologies Private Limited • Dadri

On-site
INR 5,709,000 - 8,563,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

Simfluent • Dadri

On-site
INR 1,200,000 - 1,800,000
Security Apps & Operations Engineer
Security Apps & Operations Engineer

Rediminds • Gurugram District

On-site
INR 1,500,000 - 2,800,000
Competitive salary
Bonus program
Certifications support
+1
Security Automation Engineer
Security Automation Engineer

AlphaSense Oy • Pune District

On-site
INR 1,800,000 - 3,200,000
Security Automation Engineer
Security Automation Engineer

AlphaSense Oy • Delhi

On-site
INR 1,500,000 - 2,500,000
Senior Security Engineer, AI & Automation
Senior Security Engineer, AI & Automation

F5 • Hyderabad

On-site
INR 3,500,000 - 7,000,000
Security Automation Engineer
Security Automation Engineer

AlphaSense Oy • Bengaluru

On-site
INR 2,500,000 - 5,000,000
Security Operations (SecOps) Engineer
Security Operations (SecOps) Engineer

ECLAT Health Solutions • Hyderabad

On-site
INR 800,000 - 1,500,000
AI Security Architect
AI Security Architect

TE Connectivity • Bengaluru

Hybrid
INR 2,800,000 - 4,800,000