Jobs Companies Zeta SIEM & SecOps Engineer II

À propos de ce poste SIEM & SecOps Engineer II chez Zeta

Zeta · Sur site · Hyderabad
About us:
Build the future of banking.

Zeta is a next-generation banking technology company providing cloud-native, fully stackable processing and core banking platforms for issuers. With a focus on scalability, compliance, and innovation, Zeta empowers financial institutions to modernize their technology infrastructure and deliver secure, seamless digital banking experiences. 
 
Our impact runs at real-world scale. Today, over 25 million cards are live on Zeta-powered platforms across 7 countries, supported by a passionate team of 1,700+ Zetanauts across India, the US, EMEA, and Asia. Backed by SoftBank Vision Fund, Mastercard, and other reputed strategic investors, we reached a valuation of $2 billion in 2025.
 
Our focus is on establishing product lines that focus on key outcomes by addressing real customer pain points, modernizing legacy systems, and strengthening core fundamentals. As a result, our systems and platforms support a wide range of banking and payments capabilities, including:
1. Tachyon, our cloud-native banking stack built for population-scale systems
2. Cipher, our unified authentication platform for secure, high-volume banking environments
3. Digital Credit as a Service, enabling banks to launch credit lines on UPI
4. Elena, our intelligent and conversational AI platform for banking
5. Pixel, India’s first digital-native credit card, launched in partnership with HDFC Bank, for whom we also revamped their PayZapp mobile app: Winner of the Celent Model Bank Award for Payments Innovation 2024
6. Sparrow, the leading card experience for non-prime cardholders in the US
…and more across cards, payments, lending, and core banking.
 
We are an engineering-first organization that values ownership, bias for action, and long-term thinking. Together, we solve some of the hardest problems in banking tech. Our culture is built around trust, collaboration, and creating the conditions for you to drive impact proportionate to your potential. Reinforcing our commitment to creating an inclusive and supportive workplace, we have been consistently recognized as a Great Place to Work.
 
If you want to build cutting-edge banking tech that enables banks to serve millions reliably, securely, and at a population scale, Zeta is your playground.
If you would like to learn more about how we have grown and evolved over the years, watch our journey here. You can also explore our website and follow us on LinkedIn, Instagram, YouTube, and X.
 

About the Role:
We are looking for a passionate and technically strong Detection Engineer / SOC Analyst to join our Security Operations Centre (SOC). The ideal candidate should have a strong foundation in cybersecurity, be eager to learn, and be capable of contributing to detection engineering, incident response, and the continuous improvement of our cloud-native SIEM platform under the guidance of the SOC Lead.

Responsibilities:

  • Design, develop, tune, and maintain SIEM detection use cases and correlation rules.
  • Investigate and triage security alerts escalated from L1 analysts across multiple security platforms, including:
  • Network Firewalls
  • Web Application Firewalls (WAF)
  • Cloud Platforms
  • Endpoint Security (Linux/macOS)
  • Other security monitoring solutions
  • Perform threat investigations with a strong focus on Linux security mainly on MacOS devices, including threat hunting, log analysis, and detection engineering.
  • Create, tune, and optimize dashboards, alerts, detection logic, parsers, and log collection pipelines.
  • Build and maintain log ingestion workflows using tools such as Logstash, Fluentd, Fluent Bit, or similar ETL/data pipeline technologies.
  • Support cloud-native SIEM operations based on AWS OpenSearch, including index management, parsing, dashboards, detection tuning, and platform optimization.
  • Assist with incident response activities, investigations, containment, and root cause analysis under the guidance of the SOC Lead.
  • Develop and maintain SOAR playbooks and automation workflows to improve SOC efficiency.
  • Contribute to Detection-as-Code workflows using Git-based version control and CI/CD pipelines.
  • Work closely with engineering teams to onboard new log sources, improve telemetry quality, and fine-tune data collection.
  • Support and enhance AI-driven capabilities within the SIEM, including assisting in the development and integration of AI agents for SOC operations.
  • Continuously research emerging threats, attack techniques, and detection methodologies to improve the SOC's detection coverage.
  • Skills:

  • Good understanding of SIEM query languages such as OpenSearch Query DSL, Sigma, or similar detection rule/query languages. If not already experienced, the candidate should demonstrate the ability to learn and become productive quickly.
  • Comfortable working with open-source security tools and modern security engineering practices.
  • Experience supporting SOAR automation and playbook development.
  • Ability to investigate alerts across cloud, endpoint, network, and application security technologies.
  • Strong analytical, troubleshooting, and communication skills with the ability to work independently while collaborating effectively within the SOC team.
  • Enthusiastic, proactive, self-driven, and quick to learn new technologies. The candidate should be able to rapidly understand and adapt to the existing SOC environment, detection engineering workflows, tooling, and operational processes with minimal supervision.
  • Familiarity with MITRE ATT&CK mapping.
  • Experience in working with OpenSource SIEM platforms such as ELK/Wazuh/Bro 
  • review/suggest latest trends of SIEM to integrate to our in-house SIEM
  • Experience and Qualifications:

  • 3–6 years of experience in SOC, Detection Engineering, Threat Detection, or Incident Response.
  • Strong fundamentals in Computer Networking and Operating Systems (Linux/Windows).
  • Strong hands-on experience investigating Linux security incidents and developing Linux-focused detection use cases.
  • Experience working with cloud-native SIEM platforms, preferably AWS OpenSearch.
  • Hands-on experience creating SIEM detection rules, dashboards, parsers, log normalization, and use case tuning.
  • Experience with log collection and processing tools such as Logstash, Fluentd, Fluent Bit, or similar ETL solutions.
  • Good understanding of Kubernetes, containers, and microservices-based environments from a security monitoring perspective.
  • Experience working with Detection-as-Code methodologies using Git and CI/CD workflows.
  • Proficiency in Python and strong scripting skills (Bash/PowerShell or similar).

  • Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success.
    Prêt à postuler chez Zeta ?
    Postuler chez Zeta

    Emplois similaires

    Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

    Plus d’emplois chez Zeta

    Voir tous les emplois chez Zeta →

    Postuler maintenant
    🤖

    Doucement — un instant

    JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

    Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

    Catch your next role the second it’s posted.

    Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

    Create free account

    Free forever · takes 30 seconds · already have one?

    Prenez une longueur d’avance dans votre recherche d’emploi.

    Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

    Rejoindre le canal — c’est gratuit