Sobre esta vaga de Senior Security Engineer na Vultr
Who We Are
Vultr is on a mission to make high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators around the world. With 33 global cloud data center locations, Vultr is trusted by hundreds of thousands of active customers across 185 countries for its flexible, scalable, global Cloud Compute, Cloud GPU, Bare Metal, and Cloud Storage solutions. In December 2024 Vultr announced an equity financing at a $3.5 billion valuation. Founded by David Aninowsky and self-funded for over a decade, Vultr has grown to become the world’s largest privately-held cloud infrastructure company.
Vultr Cares
Medical Insurance stipend paid annually
9 Company-Paid Holidays
Generous Leave Policy + 1 month paid sabbatical every 5 years + Anniversary Bonus each year
Professional Development Reimbursement
Internet reimbursement
Fitness membership reimbursement
Company paid Wellable subscription
Join Vultr
Vultr is expanding its India presence and is building its first Global Integrated Operations Command Center (GIOC) in Chennai — the 24x7 nerve center for monitoring, triage, and incident resolution across Vultr’s global security operations.
We are seeking Senior Security Engineers to own escalated investigations and lead incident response across Vultr’s security surface — SIEM, threat detection, identity and access, and endpoint/cloud telemetry. This is a deep-dive role for experienced security operators who lead investigations, threat hunting, and forensics, drive detection engineering, and mentor Security Engineers — and who want to grow toward incident response, threat-detection, or security engineering leadership. You must be comfortable with a rotational shift and on-call model — including nights, weekends, and holidays — to sustain follow-the-sun coverage.
Role Overview
The Senior Security Engineer owns alerts escalated from Security Engineer and leads investigation on the most complex security events. You perform deep analysis, drive incidents to resolution within defined SLAs, determine root cause and scope, contain and eradicate threats, and deliver detections and fixes that prevent recurrence. The role ensures deep technical investigation and platform security that protects customer data and platform integrity.
You act as a senior escalation point and security subject-matter expert, leading incident-response bridges, partnering with Secops/Engineering SMEs on remediation, and raising the team’s capability through detections, runbooks, and mentoring. Success is measured by MTTR/MTTC, investigation quality, recurrence reduction, and detection coverage. The role runs on a rotational shift and on-call schedule to sustain 24x7 coverage.
Key Responsibilities
Escalated Investigation & Incident Response
Own alerts escalated from Security Engineers across SIEM, identity/access, endpoint, and cloud, and drive investigations to closure
Lead deep analysis using log correlation, endpoint and network forensics, and threat-intelligence enrichment
Meet response SLA targets and provide regular, accurate updates throughout the incident lifecycle
Containment, Eradication & Root Cause
Determine scope, root cause, and attacker activity; distinguish true positives from benign anomalies
Drive containment, eradication, and recovery actions, and implement hardening to close the attack path
Partner with L3 / Engineering SMEs on remediation and with stakeholders on disclosure and compliance obligations
Preserve forensic evidence and maintain chain-of-custody throughout the investigation
Major Incident Response & Technical Leadership
Act as technical lead on major-incident (Sev-0 / Sev-1) and suspected-breach bridges, coordinating across towers
Make and document containment and recovery decisions under pressure, balancing risk and availability
Serve as senior escalation point and security subject-matter expert for the GIOC
Detection Engineering, Threat Hunting & Automation
Build and tune detections and correlation rules to improve fidelity and reduce false positives
Conduct proactive threat hunting using hypotheses, threat intel, and the MITRE ATT&CK framework
Automate triage and response with SOAR playbooks and scripting to reduce manual effort and MTTR/MTTC
Drive permanent reduction of repeat incidents through detection, hardening, and process change
Knowledge, Runbooks & Mentoring
Author and maintain runbooks, detection logic, and knowledge-base articles that raise L1 first-time resolution
Mentor and coach Security analysts; review triage and investigation quality and provide feedback
Lead knowledge transfer and shadowing during onboarding and go-live
Post-Incident Review & Continuous Improvement
Lead post-incident reviews (PIR) and root-cause write-ups with clear corrective actions
Track corrective and preventive actions to closure and measure recurrence
Surface systemic risks and drive trend-based detection and hardening improvements
Qualifications & Experience
Graduate/Engineer in a relevant field (B.E./B.Tech, or equivalent)
5-8 years of experience in security operations, incident response, or a SOC, including Senior Security Engineers escalation and incident-response ownership
Deep hands-on expertise with SIEM, EDR, log analysis, and endpoint/network forensics
Strong understanding of attacker techniques, the MITRE ATT&CK framework, threat intelligence, and the incident-response lifecycle
Proven experience leading complex investigations, containment/eradication, and root-cause analysis
Detection-engineering and automation skills (Python, SOAR playbooks, detection-as-code) and familiarity with ITSM tooling
Strong written and verbal communication for technical leadership, documentation, and mentoring; willingness and ability to work a rotational 24x7 shift and on-call model, including nights, weekends, and holidays
Proficient in English verbal and written communication
Preferred Qualifications
ITIL V4 certification; experience with security operations and IR frameworks (NIST, SANS)
Security certification (GCIH, GCIA, GCFA, CySA+, or CISSP)
Experience with detection-as-code, SOAR automation, and scripting (Python) for response workflows
Exposure to cloud security, container/workload security, and GPU / high-density infrastructure
Prior experience as a senior escalation / incident-response resource in a 24x7 SOC or command-center environment
Inclusion & Privacy
We are an equal opportunity employer and are committed to creating an inclusive environment for all employees. We welcome applications from individuals of all backgrounds and experiences, and we prohibit discrimination based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected status under applicable laws. Vultr will consider qualified applicants with arrest or conviction records in accordance with applicable laws and will not conduct a background check until after an offer of employment has been extended and accepted.
We also take your privacy seriously. We handle personal information responsibly and follow applicable laws, including U.S. privacy rules and India’s Digital Personal Data Protection Act, 2023. Your data is used only for legitimate business purposes and is protected with proper security measures.
Where allowed by law, applicants may request details about the data we collect, access or delete their information, withdraw consent for its use, and opt out of nonessential communications. For more details, please see our Privacy Policy.