Vultr is on a mission to make high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators around the world. With 33 global cloud data center locations, Vultr is trusted by hundreds of thousands of active customers across 185 countries for its flexible, scalable, global Cloud Compute, Cloud GPU, Bare Metal, and Cloud Storage solutions. In December 2024 Vultr announced an equity financing at a $3.5 billion valuation. Founded by David Aninowsky and self-funded for over a decade, Vultr has grown to become the world’s largest privately-held cloud infrastructure company.
🏢 About Vultr
Vultr is expanding its India presence and is building its first Global Integrated Operations Command Center (GIOC) in Chennai — the 24x7 nerve center for monitoring, triage, and first response across Vultr’s global security operations.
🎯 The Role
We are seeking Security Engineers to serve as the first line of response across Vultr’s security signal surface — SIEM, threat, identity, and access alerts. This is a frontline security operations role for engineers who triage SIEM alerts, perform first-line containment, and preserve evidence in real time — and who want to grow into deeper SOC, threat-detection, or security engineering careers. You must be comfortable working a rotational shift model — including nights, weekends, and holidays — to sustain the coverage.
✅ Key Responsibilities
Monitor security signals — SIEM detections, authentication and access anomalies, threat-intel and endpoint alerts — from a consolidated single-pane-of-glass dashboard
Acknowledge alerts and incidents within first-response SLA targets
Perform initial review — validate the detection, rule out false positives, check recent changes, and review the CMDB before acting
Classify each alert by severity and potential impact, confirming the owning tower (Security / cross-tower)
Route and assign tickets accurately to the correct tower or escalation path
Sustain triage accuracy at or above the GIOC go-live standard
Reassess severity as the investigation evolves, and declare higher when in doubt — treat suspected breaches as high-severity until ruled out
Match alert signatures to documented runbooks and execute permitted L1 actions
Perform first-line containment within L1 scope (e.g., isolate, disable, or block per runbook) and preserve evidence for analysis
Document every step taken, with supporting evidence and timestamps, in the incident ticket
Escalate unresolved or out-of-scope alerts to the Senior Security Engineers with a clean, complete handoff (symptom · evidence collected · steps tried · current state)
Flag missing or ineffective runbooks and detection gaps for review and continuous improvement
Initiate and support major-incident (Sev-0 / Sev-1) bridges per the escalation matrix; engage Security leads and incident response immediately on suspected breaches
Track escalations to closure and confirm the threat is contained or ruled out before resolving the ticket
Maintain accurate shift logs, ticket updates, and incident timelines with chain-of-custody for security evidence
Provide clear, timely status communication to stakeholders per severity, following defined disclosure and confidentiality protocols
Produce thorough shift-handover notes for seamless follow-the-sun continuity on active investigations
Identify recurring alerts and false positives as candidates for detection tuning and automation
Contribute to and improve runbooks, detection logic, and knowledge-base articles
Participate in post-incident reviews (PIR) and trend reviews
📌 Required Qualifications
Graduate/Engineer in a relevant field (B.E./B.tech or equivalent)
3–5 years of experience in a SOC, security operations, or IT operations, including hands-on security monitoring and alert triage
Working knowledge of security fundamentals — authentication and access, common attack types, logging, and endpoint/network telemetry
Familiarity with SIEM and alert-triage concepts, log analysis, and basic threat investigation
Understanding of incident-management fundamentals and severity-based triage
Exposure to monitoring/observability tools and ticketing systems (SIEM consoles, alerting, ITSM)
Strong written communication for accurate documentation and clean escalation handoffs; willingness and ability to work a rotational 24x7 shift model, including nights, weekends, and holidays
Proficient in English verbal and written communication
⭐ Desirable Experience
ITIL V4 Foundation certification
🎁 Benefits
Vultr Cares Medical Insurance stipend paid annually 9 Company-Paid Holidays Generous Leave Policy + 1 month paid sabbatical every 5 years + Anniversary Bonus each year Professional Development Reimbursement Internet reimbursement Fitness membership reimbursement Company paid Wellable subscription
🛂 Visa & Eligibility
No specific visa or eligibility information provided.