
Senior Development Engineer II, Security Operations
kAIgentic
Posted 2026-05-18
Tech & Engg
Job Description
Ovii's Interpretation of the Role
Senior Security Operations Engineer responsible for end‑to‑end detection, incident response, threat hunting and automation across cloud, identity, endpoint and AI surfaces for a regulated‑enterprise AI platform.
Role Snapshot
- Own detection engineering across multi‑cloud and AI pipelines
- Run full‑cycle incident response and post‑mortem reviews
- Lead proactive threat hunting and vulnerability management
- Build Python‑based SecOps automations and SOAR playbooks
- Operate SIEM, EDR, CSPM and SOAR stacks
Must-Have Requirements
- Security operations / detection engineering
- Incident response
- Threat hunting
- Python scripting
- Cloud security (AWS/Azure/GCP)
- SIEM operation
- EDR operation
- SOAR orchestration
- Vulnerability management
- Identity security (Okta/Entra)
- security operations
- detection engineering
- incident response
- threat hunting
Nice-to-Have Signals
- Experience in regulated financial services, fintech, regtech or healthcare
- Familiarity with AI‑specific attack surfaces (prompt injection, model abuse, RAG poisoning)
- Offensive security background (OSCP, GPEN, GCIH, etc.)
- SecOps certifications (GCFA, GCIH, GCDA, GCFR, OSDA)
- Experience building a SecOps function in a startup
- regulated industry experience
- AI‑specific attack surface familiarity
- offensive security background
Work Setup
- Location: Bengaluru, India
- Work mode: HYBRID
- Remote scope: UNSPECIFIED
- Employment type: Full-Time
Not Specified in JD
- Visa sponsorship
- Salary range
- Remote eligibility
- Education requirement
- Certifications
- Relocation
- Notice period
- Travel
- Security clearance
- Coding test
- Portfolio
- GitHub
- Writing sample
- Cover letter
What You'll Likely Work On
- Design, implement and tune detections for cloud, identity, endpoint, SaaS and AI pipelines
- Lead end‑to‑end incident response, including triage, containment, recovery and customer communication
- Conduct proactive threat‑hunting campaigns across infrastructure, code repositories and AI models
- Operate and automate the SIEM, EDR, CSPM and SOAR stack, reducing noise with automated decisions
- Develop Python‑based enrichment, response and ticketing playbooks for the SecOps automation layer
- Manage vulnerability lifecycle: prioritization, patch SLAs, exception handling and validation
- Run identity‑focused threat detection (session anomalies, OAuth abuse, MFA fatigue, token misuse)
- Own on‑call rotation, incident drills, tabletop exercises and game days
- Partner with platform, infrastructure and AI engineering teams to harden model and tool surfaces
- Translate operational learnings into controls, policies and audit‑ready evidence
Good Fit If You Have
- Calm under pressure with high‑judgment decision making
- Strong fundamentals: TCP/IP, TLS, OS internals, OAuth/OIDC, Kubernetes basics
- Customer‑focused mindset and empathy
- Entrepreneurial, zero‑to‑one problem solver
- Collaborative ownership without relying on titles
Skills
- Security operations & detection engineering
- Incident response & threat hunting
- Python scripting for automation
- Cloud security (AWS, Azure, GCP)
- SIEM (Splunk, Sumo, Elastic, Panther)
- EDR (CrowdStrike, SentinelOne, Defender)
- SOAR orchestration
- Identity security (Okta, Entra)
- Vulnerability management processes
- AI‑specific attack surface knowledge