Senior Security Operations Engineer @Couchbase, Inc.
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago

[Hiring] Senior Security Operations Engineer @Couchbase, Inc.

3wks ago - Couchbase, Inc. is hiring a remote Senior Security Operations Engineer. πŸ’Έ Salary: unspecified πŸ“Location: India

Role Description

We're hiring a Sr. Security Operations Engineer to join Couchbase's global Information Security team as our second dedicated SecOps engineer. We think the interesting work in security operations right now sits at the intersection of two things:

  • AI has changed what a capable adversary can do at scale, which changes what detection and response have to look like.
  • AI is also the most useful thing to happen to defenders in years.

We use AI internally in security operations, not as a pilot:

  • Triage agents that risk-rank and route findings.
  • Automated threat modeling with human review at closure.
  • Reachability scoring that separates real exposure from scanner noise.
  • AI-assisted detection and response workflows.

Roughly half your time is operational β€” triage, investigation, containment, tuning. The other half is engineering and program work: building detection content, automating response, and running security capabilities across cloud, identity, endpoint, and AI governance. You'll work across Engineering, SRE, IT, Cloud, Legal, and Compliance, and you'll own outcomes rather than tickets.

Key Responsibilities

  • Detection & Response Operations
    • Own alert triage, investigation, and containment alongside our existing SecOps engineer, supporting a follow-the-sun coverage model.
    • Manage the SIEM day to day: log source onboarding, normalization, retention, correlation rule development, and validation of alert use cases.
    • Maintain the operating model with our managed detection partners β€” escalation thresholds, containment ownership, and handoff procedures.
    • Measure and report MTTD, MTTR, and MTTC against defined targets; run a regular alert-tuning cadence.
    • Develop incident-specific response playbooks and support cross-functional tabletop exercises.
    • Run hypothesis-driven threat hunting against available telemetry, with documented hypotheses, resulting detections, and tracked follow-up.
  • Automation & AI-Assisted Security Engineering
    • Build agent-based workflows for enrichment, triage, and automated containment.
    • Operate and tune AI triage agents that ingest findings from cloud and vulnerability tooling, rank by severity and reachability, and route to named owners.
    • Integrate security tooling via API so detection, findings, and evidence flow automatically.
    • Automate repetitive operational work β€” evidence collection, inventory reconciliation, and reporting.
  • Vulnerability & Exposure Management
    • Run the vulnerability management lifecycle across endpoints, servers, network devices, and cloud workloads: scan coverage, risk-based prioritization, owner assignment, SLA tracking, and verification.
    • Prioritize on exploitability, reachability, and business context rather than raw CVSS.
    • Maintain an authoritative asset register reconciled across cloud, endpoint, and vulnerability tooling, with automated discovery and per-asset ownership.
    • Coordinate internal and external penetration testing across corporate, data center, and product environments; track findings to closure and retest.
  • Cloud & Infrastructure Security
    • Operate CSPM and CNAPP tooling across AWS, Azure, GCP, and Kubernetes, including policy enforcement and exception workflow.
    • Support infrastructure-as-code baselines, deployment-time enforcement, and drift detection.
    • Support key and secrets management: centralized storage, automated rotation, least-privilege access review, and audit coverage.
    • Operate and tune EDR across workstations, servers, and cloud workloads, and wire alerts into response workflows.
  • Identity Security
    • Support privileged access management, phishing-resistant MFA, and risk-based conditional access; monitor identity risk signals and build detections for credential abuse, MFA fatigue, and session anomalies.
    • Build detections for AI-enabled social engineering against help desk and finance workflows β€” impersonation, deepfake-assisted verification bypass, and account recovery abuse.
    • Support access review automation and joiner/mover/leaver reconciliation evidence.
  • AI Security & Data Protection
    • Configure and tune DLP for AI channels β€” labeling coverage, prompt and upload controls, and incident review.
    • Operate shadow-AI detection and enforcement, including blocking, connector approvals, and exception handling.
    • Support AI use-case intake, risk tiering, and scoped AI red team exercises against high-risk agents and applications.
  • Governance & Reporting
    • Produce security metrics and program reporting for leadership and governance committees.
    • Support audit evidence collection for SOC 2, ISO 27001, and related frameworks.
    • Maintain runbooks, business continuity documentation, and restore and failover test evidence.

Qualifications

  • 5–8 years hands-on in security operations, with real incident triage, investigation, and containment experience.
  • Deep, practical SIEM experience β€” writing and tuning detections, onboarding log sources, and building correlation logic (Coralogix, Splunk, Sentinel, Elastic, or similar).
  • Strong public cloud security skills on at least one of AWS, Azure, or GCP, plus working knowledge of Kubernetes and container security.
  • Hands-on EDR operation and tuning (SentinelOne, CrowdStrike, or equivalent).
  • Vulnerability management experience at scale: scanning, risk-based prioritization, remediation tracking, and exception governance (Rapid7, Qualys, Tenable, or similar).
  • Scripting and automation ability β€” Python plus comfort working with REST APIs and infrastructure-as-code (Terraform).
  • Working knowledge of identity platforms and identity-centric attacks β€” SSO, MFA, conditional access, token theft, session hijacking (Okta or equivalent).
  • Familiarity with NIST CSF and how control maturity assessments translate into engineering work.
  • Genuine curiosity about applying AI to security work, and the judgment to know when automated output needs a human before it's trusted.
  • Strong written communication β€” you'll be documenting playbooks, escalation paths, and metrics that other teams depend on.

Nice to Have

  • SOAR development experience (BlinkOps, Tines, Torq, XSOAR) or building automation against security tool APIs.
  • CNAPP/CSPM experience (Wiz, Aikido, Prisma Cloud, Sysdig).
  • DLP and CASB/SSE operation (Netskope, Zscaler, Proofpoint).
  • Threat hunting experience with documented hypothesis-driven methodology.
  • Privileged access management deployment or operation.
  • Email security tuning (Abnormal, Proofpoint, Mimecast) and phishing simulation programs.
  • MDM and endpoint baseline management (Kandji, Jamf, Workspace ONE, Intune).
  • Network security fundamentals β€” segmentation, firewall policy review, WAF (Palo Alto, Cloudflare).
  • Backup and recovery security, including immutability and restore testing.
  • Detection engineering practices β€” detection-as-code, MITRE ATT&CK coverage mapping, purple team exercises.
  • Exposure to AI/LLM security: prompt injection, agentic tool abuse, MCP and connector risk, model supply chain, or AI red teaming.
  • Certifications such as GCIA, GCIH, GCFA, OSCP, AWS Security Specialty, Security+, or CISSP.
  • Bachelor's degree in Computer Science, Information Security, or a related field.

Benefits

  • Generous Time Off Program - Flexibility to care for you and your family.
  • Wellness Benefits - A variety of world class medical plans to choose from, along with dental, vision, life insurance, and employee assistance programs.
  • Financial Planning - Retirement program and Business Travel Insurance.
  • Career Growth - Be valued, Create value approach.
  • Fun Perks - An ergonomic and comfortable in-office / WFH setup. Food & Snacks for in-office employees.
  • And much more!
Before You Apply
️
remote Be aware of the location restriction for this remote position: India
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Operations Engineer @Couchbase, Inc.
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 3wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: India
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,680+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later