Skip to content

Open nowPosted 70 days ago

SIEM & SecOps Engineer II

Zeta25 open roles

Where
Hyderabad
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSIEM & SecOps Engineer IIZeta · Hyderabad
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Zeta's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 70 days ago

The posting

About us: Build the future of banking.

Zeta is a next-generation banking technology company providing cloud-native, fully stackable processing and core banking platforms for issuers. With a focus on scalability, compliance, and innovation, Zeta empowers financial institutions to modernize their technology infrastructure and deliver secure, seamless digital banking experiences.

Our impact runs at real-world scale. Today, over 25 million cards are live on Zeta-powered platforms across 7 countries, supported by a passionate team of 1,700+ Zetanauts across India, the US, EMEA, and Asia. Backed by SoftBank Vision Fund, Mastercard, and other reputed strategic investors, we reached a valuation of $2 billion in 2025.

Our focus is on establishing product lines that focus on key outcomes by addressing real customer pain points, modernizing legacy systems, and strengthening core fundamentals. As a result, our systems and platforms support a wide range of banking and payments capabilities, including:

1. Tachyon, our cloud-native banking stack built for population-scale systems

2. Cipher, our unified authentication platform for secure, high-volume banking environments

3. Digital Credit as a Service, enabling banks to launch credit lines on UPI

4. Elena, our intelligent and conversational AI platform for banking

5. Pixel, India’s first digital-native credit card, launched in partnership with HDFC Bank, for whom we also revamped their PayZapp mobile app: Winner of the Celent Model Bank Award for Payments Innovation 2024

6. Sparrow, the leading card experience for non-prime cardholders in the US

…and more across cards, payments, lending, and core banking.

We are an engineering-first organization that values ownership, bias for action, and long-term thinking. Together, we solve some of the hardest problems in banking tech. Our culture is built around trust, collaboration, and creating the conditions for you to drive impact proportionate to your potential. Reinforcing our commitment to creating an inclusive and supportive workplace, we have been consistently recognized as a Great Place to Work.

If you want to build cutting-edge banking tech that enables banks to serve millions reliably, securely, and at a population scale, Zeta is your playground.

If you would like to learn more about how we have grown and evolved over the years, watch our journey here. You can also explore our website and follow us on LinkedIn, Instagram, YouTube, and X.

About the Role:

As a Security Operations Implementation Engineer, you will be playing a pivotal role in enabling Zeta in implementing and integrating SIEMs, detecting and responding to attacks at an early stage and make sure infrastructure and applications are secure. You will work with an amazing peer group that fuels this ambition.

We are looking for a highly motivated SIEM / SOC Engineer with 4-6 years of experience in developing, enhancing, and maintaining enterprise-scale Security Operations and SIEM platforms based on the ELK Stack (Elasticsearch, Logstash, Kibana). The candidate will play a key role in advancing our next-generation security monitoring capabilities by enhancing existing SIEM modules, developing new detection use cases, integrating security technologies such as UEBA, SOAR, Threat Intelligence, and supporting the SOC team with effective detection and response capabilities.

The ideal candidate should possess strong hands-on experience in log parser development, security content engineering, ELK administration, AWS environments, microservices architectures, and open-source security technologies.

Responsibilities:

  • Design, develop, and maintain high-fidelity detection rules, correlation rules, alerts, and security use cases for newly onboarded and existing log sources. Continuously tune detections to reduce false positives, improve detection fidelity, and expand detection coverage across the environment.
  • Develop security monitoring and detection content for AWS services, Kubernetes, microservices, Linux, macOS, databases, web applications, firewalls, and other enterprise technologies by leveraging the MITRE ATT&CK framework, threat intelligence, and adversary TTPs.
  • Onboard new security and application log sources by developing Logstash pipelines, custom parsers, Grok patterns, ingest processors, and enrichment workflows. Analyze raw log formats, normalize events to a common schema, and enrich security telemetry to enable reliable detection and investigation.
  • Design and maintain operational dashboards, executive dashboards, SOC dashboards, and threat hunting visualizations using optimized OpenSearch Query DSL, aggregations, and visualizations to provide actionable security insights and platform observability.
  • Integrate Threat Intelligence Platforms (TIP), IOC feeds, and enrichment services with OpenSearch. Develop IOC correlation rules, automated enrichment workflows, and contextual detections to identify malicious activity across ingested telemetry.
  • Expand the SIEM by implementing advanced capabilities such as UEBA, anomaly detection, OpenSearch Notebooks for investigation playbooks, SOAR workflows for automated response, and AI-driven automation to streamline Level 1 SOC operations.
  • Collaborate with SOC analysts during alert investigations, threat hunting, and incident response by providing L2/L3 detection engineering support, validating detections, identifying detection gaps, and continuously improving existing security content.
  • Follow Detection-as-Code practices by developing, testing, version-controlling, and deploying detection content through Git-based workflows and CI/CD pipelines, ensuring consistent, reliable, and scalable delivery of SIEM content.

Skills:

  • Hands-on experience with any enterprise SIEM platforms such as Elastic/ELK, OpenSearch, Splunk, Microsoft Sentinel, IBM QRadar, ArcSight, Google Chronicle, Wazuh, ELK/EFK or similar solutions.
  • Experience developing, maintaining, and tuning detection rules, correlation rules, alerts, dashboards, visualizations, and security use cases using SIEM query languages and detection frameworks such as OpenSearch/Elasticsearch Query DSL, Sigma, KQL, SPL, EQL, or equivalent.
  • Strong experience onboarding log sources by developing custom parsers, Logstash pipelines, Fluentd/Fluent Bit configurations, Grok patterns, ETL pipelines, field mappings, log normalization, and data enrichment workflows.
  • 4–6 years of experience in Detection Engineering, SIEM Engineering, Security Operations, or SOC environments.
  • Good understanding of SIEM architecture, event correlation, log management, detection engineering, the MITRE ATT&CK framework, Cyber Kill Chain, threat hunting methodologies, attacker TTPs, Threat Intelligence integration, and IOC-based detections.
  • Experience developing detections and investigating security events across Linux, macOS, databases, web applications, firewalls, WAFs, enterprise infrastructure, and cloud environments.
  • Familiarity with open-source security technologies such as Wazuh, Suricata, Zeek (Bro), Velociraptor, HELK, EFK, Falco, osquery, or similar security monitoring solutions.
  • Strong foundation in computer networking, operating systems, authentication and authorization concepts, web technologies, and common attack techniques.
  • Familiarity with YARA rules, malware detection concepts, and security automation is an added advantage.
  • Strong analytical, troubleshooting, and investigative skills with the ability to identify detection gaps, validate detections, and continuously improve security monitoring content.
  • Hands-on experience with AWS environments and a good understanding of core AWS services such as IAM, CloudTrail, VPC, EC2, EKS, S3, CloudWatch, and cloud security monitoring concepts.
  • Familiarity with Kubernetes, Helm, containerized workloads, microservices architectures, and cloud-native security monitoring, Git, CI/CD Pipeline knowledge etc.

Experience and Qualifications:

  • 4 to 6 years of overall experience as Security Operations engineer in medium to large-size product companies.
  • Bachelor of Technology (BE/B.Tech), M.Tech/ME in Computer Science or equivalent.
  • Must have worked on the ELK/EFK implementation projects, and Logstash data parsing rules.
  • Threat intelligence like OSINT, MISP, AlienVault, IDRBT etc.
  • Expertise in Log monitoring tools like Splunk, ELK/EFK, SumLogic, Loggly etc.
  • Assists in ensuring compliance with industry standards (for example, PCI DSS/3DS, GDPR, ISO 27001, SOC2 etc) by conducting assessments and implementing necessary controls, presenting to auditors.
  • Hands on experience in detection engineering, security investigations, incident response and forensics.
  • Experience in threat hunting using threat intelligence to investigate potential risks and finding suspicious behaviour.
  • Create, modify, and tune the SIEM rules to adjust the specifications of alerts and incidents.
  • Designs, implements, and configures Kibana visualizations as required by the business.
  • Configures Logstash, FileBeats, VictoriaMetrics, Prometheus, Velociraptor, Grafana and possibly other ELK/EFK Stack components to collect and store the data necessary to meet business requirements efficiently.
  • Strong data analysis skills; ability to independently write scripts/code to parse and analyse complex logs and data and optimize the SIEM system capabilities as well as the audit and logging features of the event log sources.
  • Understanding and familiarity with existing TTP frameworks like MITRE ATT&CK, Cyber Kill Chain etc.

Zeta is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We encourage applicants from all backgrounds, cultures, and communities to apply and believe that a diverse workforce is key to our success.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Zeta's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Zeta's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Zeta's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.