Vultr is on a mission to make high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators around the world. With 33 global cloud data center locations, Vultr is trusted by hundreds of thousands of active customers across 185 countries for its flexible, scalable, global Cloud Compute, Cloud GPU, Bare Metal, and Cloud Storage solutions. In December 2024 Vultr announced an equity financing at a $3.5 billion valuation. Founded by David Aninowsky and self-funded for over a decade, Vultr has grown to become the world’s largest privately-held cloud infrastructure company.
🏢 About Vultr
Vultr is expanding its India presence and is building its first Global Integrated Operations Command Center (GIOC) in Chennai — the 24x7 nerve center for monitoring, triage, and incident resolution across Vultr’s global security operations.
🎯 The Role
We are seeking Senior Security Engineers to own escalated investigations and lead incident response across Vultr’s security surface — SIEM, threat detection, identity and access, and endpoint/cloud telemetry. This is a deep-dive role for experienced security operators who lead investigations, threat hunting, and forensics, drive detection engineering, and mentor Security Engineers — and who want to grow toward incident response, threat-detection, or security engineering leadership. You must be comfortable with a rotational shift and on-call model — including nights, weekends, and holidays — to sustain follow-the-sun coverage.
✅ Key Responsibilities
Own alerts escalated from Security Engineers across SIEM, identity/access, endpoint, and cloud, and drive investigations to closure
Lead deep analysis using log correlation, endpoint and network forensics, and threat-intelligence enrichment
Meet response SLA targets and provide regular, accurate updates throughout the incident lifecycle
Determine scope, root cause, and attacker activity; distinguish true positives from benign anomalies
Drive containment, eradication, and recovery actions, and implement hardening to close the attack path
Act as technical lead on major-incident (Sev-0 / Sev-1) and suspected-breach bridges, coordinating across towers
Build and tune detections and correlation rules to improve fidelity and reduce false positives
Conduct proactive threat hunting using hypotheses, threat intel, and the MITRE ATT&CK framework
Automate triage and response with SOAR playbooks and scripting to reduce manual effort and MTTR/MTTC
Author and maintain runbooks, detection logic, and knowledge-base articles that raise L1 first-time resolution
Mentor and coach Security analysts; review triage and investigation quality and provide feedback
Lead post-incident reviews (PIR) and root-cause write-ups with clear corrective actions
📌 Required Qualifications
Graduate/Engineer in a relevant field (B.E./B.Tech, or equivalent)
5-8 years of experience in security operations, incident response, or a SOC, including Senior Security Engineers escalation and incident-response ownership
Deep hands-on expertise with SIEM, EDR, log analysis, and endpoint/network forensics
Strong understanding of attacker techniques, the MITRE ATT&CK framework, threat intelligence, and the incident-response lifecycle
Proven experience leading complex investigations, containment/eradication, and root-cause analysis
Detection-engineering and automation skills (Python, SOAR playbooks, detection-as-code) and familiarity with ITSM tooling
Strong written and verbal communication for technical leadership, documentation, and mentoring; willingness and ability to work a rotational 24x7 shift and on-call model, including nights, weekends, and holidays
🎁 Benefits
Medical Insurance stipend paid annually
9 Company-Paid Holidays
Generous Leave Policy + 1 month paid sabbatical every 5 years + Anniversary Bonus each year