Credit Acceptance logo
Credit Acceptance

Driving Possibility

Security Operations Engineer II

Security OperationsSecurity OperationsFull TimeRemoteMid LevelTeam 1,001-5,000Since 1972H1B SponsorCompany SiteLinkedIn

Location

India

Posted

9 days ago

Salary

₹2,421.0K - ₹3,550.9K / year

Seniority

Mid Level

Bachelor Degree2 yrs expEnglishCyber SecurityPython

Job Description

Security Operations Engineer II

Credit Acceptance

• Operate and tune enterprise security tools (EDR, SIEM/SOAR, WAF/proxy, email security). • Manage proxy filtering policies, exceptions, SSL inspection, and performance troubleshooting. • Build automation and playbooks (Python/PowerShell, SOAR, APIs) to streamline SecOps tasks. • Implement CI/CD pipelines and Infrastructure-as-Code workflows for consistent, auditable security configuration changes. • Author and tune detection rules; improve signal quality and reduce false positives. • Maintain and author health dashboards, uptime/coverage metrics, and change governance documentation. • Conduct knowledge transfers through runbooks, how-to guides, tabletop exercises, and lunch & learn training sessions. • Maintain upgrade schedules, license compliance, configuration baselines, and key/secret rotations. • Administer URL/category policies, SSL inspection, identity-aware policies, geo/risk-based controls, and performance troubleshooting. • Analyze block events for false positives; measure impact; retire exceptions on schedule and report residual risk. • Build and maintain an automation backlog in partnership with SecOps, prioritizing high-frequency, high-toil tasks. • Provide on-call support for tooling availability and ingestion/normalization issues. • Report on metrics (uptime, coverage, MTTR, lead time, change success rate, exception aging). • Keep documentation, diagrams, and asset inventories current. • As needed, monitor and respond to alerts raised by various toolsets as part of an ongoing 24/7 Security Operations Center. • Report outages or incidents following guidelines and procedures. • Detect, analyze, and respond to incidents, coordinate with other stakeholders for containing, eradicating, and recovering from an incident. • Assist in developing testing criteria to implement new signatures/rules. • Participate in on-call rotations, including nights, weekends, and holidays.

Job Requirements

  • Bachelor’s degree in computer science, Information Systems, Data Science or closely related field of study or equivalent experience
  • Minimum 2 years of experience in cyber security, anomaly detection, Security Operations Center (SOC) detection, threat analytics, security incident and event management (SIEM), information technology (IT), operations incident response, network security or security engineering
  • Basic experience administering, deploying and managing security tools.
  • Basic experience operating WAF/proxy and SIEM/SOAR.
  • Scripting in Python and/or PowerShell and building API integrations; JSON/YAML proficiency.
  • CI/CD and Git workflows; Infrastructure-as-Code for security configurations.
  • Basic understanding of TLS/SSL, HTTP, identity-aware policies, and egress/ingress routing.
  • Documentation discipline and change management (ITIL basics).
  • Ability to produce formal and informal reports, briefings, and analysis of security controls.
  • Experience with Endpoint Detection and Response (EDR) or Intrusion Detection System or Intrusion Prevention System (IDS/IPS) monitoring tools.
  • Understanding of MITRE ATT&CK Framework and Cyber Kill Chain flow
  • Understanding of incident response processes and risk management.
  • Preferred: Actively hold one or more of the following certifications: GSEC, GCIA/GCED, GCDA, AZ-500, SC-200/SC-100, Network+ or CCNA.

Benefits

  • Performance bonus
  • Allowances
  • Employer-paid insurance benefits
  • Flexible work options including work from home, on site and hybrid positions
  • Company provided technology packages for all Team Members
  • Collaborative atmosphere filled with forward-thinking Team Members
  • Extensive growth opportunities
  • Ongoing business training and career development opportunities
  • Competitive market-based salary with bonus compensation
  • Quarterly profit sharing and annual merit bonuses
  • Generous PTO and holidays that include 28.5 total days during first full year of employment
  • Excellent benefits package that includes 401(K) match, adoption assistance, parental leave, tuition reimbursement, comprehensive medical/dental/vision and many nonstandard benefits

Related Categories

Related Job Pages

More Security Operations Jobs

Climb Channel Solutions NA logo

Security Operations Engineer

Climb Channel Solutions NA

A different breed of specialty technology distributor. #ClimbWithUs

Full TimeRemoteTeam 51-200Since 1982H1B No Sponsor

• Engineer and maintain security operations platforms (SIEM, EDR, NDR, email, cloud) • Apply a detections-as-code approach • Architect and implement security engineering capabilities • Collaborate with cross-functional teams to embed security controls • Research, evaluate, and operationalize security products and services

United States

Role Description We are hiring someone to build the operational infrastructure of the engineering team from scratch. This is not a project management role. There is no existing playbook, no mature intake process, no capacity framework, no defined utilization targets, and no release process. You will build all of it. Engineering’s primary purpose at TNT Growth is client delivery. The metrics that matter are client targets hit and net revenue retention. Every system you build, every process you design, every framework you implement needs to ladder up to that. If it doesn’t accelerate client outcomes, it doesn’t belong on the roadmap. You will be the operational backbone of the engineering team. You’ll work directly with the Director of Operations, the Technical Director, and engineers to ensure the right work gets done, in the right order, at the right level of investment. You will bring structure, visibility, and accountability to a team that is currently operating reactively. We are not looking for someone who manages tasks. We are looking for someone who builds the system that makes task management unnecessary. What You'll Own - Design and implement a single intake system for all engineering requests. - Triage incoming tickets with enough technical understanding to assess client-critical needs. - Translate client needs into actionable engineering work. - Own the prioritization framework for competing requests. - Assess every incoming client request against the client’s contracted scope of work. - Flag and escalate out-of-scope requests before they consume engineering time. - Partner with GMs and client success to ensure the team builds what clients are paying for. - Track scope compliance over time. - Build and maintain a forward-looking capacity plan. - Own the 30/60/90-day engineering calendar. - Design and run an early warning system for growing backlogs. - Manage sprint execution: standups, sprint planning, retrospectives, velocity tracking. - Design the team’s operating model. - Create SOPs for escalation, handoffs, scope changes, and release coordination. - Coordinate with the Product Designer to ensure alignment before anything goes live. - Own the framework for internal tooling initiatives. - Right-size build decisions based on needs. - Define expected utilization targets for each engineer. - Establish throughput metrics the team aligns on. - Use time-tracking data to build a real picture of engineering hours. - Determine when backlogs should be solved with better planning vs. additional headcount. - Prepare business cases for headcount requests. - Own the communication structure between engineering, ops, client success, growth, and leadership. - Coordinate with GMs to ensure client priorities are translated accurately. Qualifications - MUST have 5+ years in engineering operations, technical program management, or a similar role. - Experience building operational systems from scratch in a team that didn’t have them. - Strong enough technical understanding to triage engineering tickets and assess scope. - Client-centric mindset with the ability to connect work to business justification. - Experience with client engagement models and scope management. - Comfortable with data and metrics to drive decisions. - Experience managing remote, distributed teams across time zones. - AI-literate with an understanding of how AI tools can accelerate workflows. - Direct communicator who surfaces problems early and proposes solutions. Compensation - Salary Range: $30k-$85k (Non-US Only) - Flexible PTO and Paid Holidays

Worldwide
$30K - $85K / year
Job Closed
Full TimeRemoteTeam 201-500Since 2023H1B No Sponsor

• Monitor, investigate and respond to security events, alerts and incidents across corporate, QA, staging and production environments • Execute vulnerability operations including intake, prioritization, tracking and remediation coordination in an AI-forward environment • Support IAM program through access changes, privileged access controls, access reviews and control validation • Maintain and improve security runbooks, workflows, documentation and operational procedures • Identify operational gaps and recommend practical improvements that strengthen coverage, response and alignment to best practices • Partner with IT, Engineering and business teams to address security issues across internal and customer-facing environments • Manage work in Jira, including ticket updates, prioritization, workflow discipline and backlog execution • Participate in on-call incident response as needed

United States
Thrive logo

SOC Analyst

Thrive

NextGen Technology Services

Full TimeRemoteTeam 201-500H1B Sponsor

• Utilizes SIEM/XDR/EDR tools (AlienVault USMA/LevelBlue, LogRhythm, Microsoft Sentinel, Splunk CrowdStrike, etc.) to monitor alerts and security events of client networks and systems. • Identifies, analyzes, and responds to security incidents as they occur. • Collaborates and leverages their cybersecurity knowledge working alongside a team of skilled analysts to address potential threats within a 24x7 SOC. • Crafts escalations to clients for potential threats that include value-added and root cause analysis with recommendations for remediation. • Continually improves cybersecurity and information security expertise. • Performs other related duties as assigned.

United States