ASAI job platform logo
  1. Home
  2. /Jobs
  3. /Security Engineer Jobs in Bengaluru
  4. / Senior Security Operations Engineer
CI
Couchbase, Inc.

Senior Security Operations Engineer

Bengaluru · Senior

Expect moderate competitionVerified listingPosted 19d ago

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

What we know about this role

Hiring pulse

MEDIUM

Couchbase, Inc. is reviewing applications at a steady pace. Expect a standard response time as they evaluate the current pool.

Apply window

First 72 hours

Window passed - posted 19d ago

Early applicants get seen before the pile builds.

Not a repost

The first time we've seen this listing - it hasn't been closed and reopened.

Skills required

31 listed
Evidence CollectionPenetration TestingInfrastructure SecurityPolicy EnforcementSocial EngineeringException HandlingBusiness ContinuityContainer Security+23 more
Evidence CollectionPenetration TestingInfrastructure SecurityPolicy EnforcementSocial Engineering

You almost certainly match several of these already. Unlock your skill map to see the matches, the gaps, and what to fix first.

Job description

Couchbase, the operational data platform for AI, empowers businesses to succeed by bringing data to life in new ways. Major market-leading companies rely on Couchbase for mission critical operational, analytical, mobile and AI workloads. Built to replace legacy infrastructure and fragmented data services, Couchbase empowers enterprises with a unified platform architected for performance, flexibility and global scale.

With Couchbase, organizations bring their data to life, launching game‑changing customer experiences, exploring the limitless potential of AI, and seamlessly extending applications from the cloud to the edge and beyond. Couchbase’s AI‑ready technology and enterprise partnership model eliminate complexity and reduce total cost of ownership, enabling teams to stay agile, innovative and secure.

Couchbase believes data should never slow you down, but act as the foundation for your next breakthrough. Discover why Couchbase is trusted to help the world’s biggest players scale, move fast and stay resilient, no matter what’s next on their roadmap. Visit couchbase.com and follow us on LinkedIn and X.

Want to be part of our story? Apply today!

About Couchbase

Couchbase is the Operational Data Platform for AI. Our customers don't run AI in a lab — they run it in production, where agents remember, reason, and act on live operational data. With the Couchbase AI Data Plane, we give those agents one governed layer for memory, context, tool access, and MCP, deployed anywhere from public cloud to Kubernetes to the edge to air-gapped environments. Amadeus, Cisco, Comcast, FICO, PepsiCo, United, Verizon, and Wells Fargo trust us with their data.

That means AI security isn't a side topic here. It's adjacent to the product, and it's the environment we operate in every day.

The Role

We're hiring a Sr. Security Operations Engineer to join Couchbase's global Information Security team as our second dedicated SecOps engineer.

We think the interesting work in security operations right now sits at the intersection of two things. The first is that AI has changed what a capable adversary can do at scale, which changes what detection and response have to look like. The second is that AI is also the most useful thing to happen to defenders in years — and we'd rather be early than careful about that.

We use AI internally in security operations, not as a pilot: triage agents that risk-rank and route findings, automated threat modeling with human review at closure, reachability scoring that separates real exposure from scanner noise, and AI-assisted detection and response workflows. We want someone who will build on that, push it further, and stay clear-eyed about where it earns trust and where it doesn't.

Roughly half your time is operational — triage, investigation, containment, tuning. The other half is engineering and program work: building detection content, automating response, and running security capabilities across cloud, identity, endpoint, and AI governance. You'll work across Engineering, SRE, IT, Cloud, Legal, and Compliance, and you'll own outcomes rather than tickets.

Key Responsibilities

Detection & Response Operations

  • Own alert triage, investigation, and containment alongside our existing SecOps engineer, supporting a follow-the-sun coverage model.
  • Manage the SIEM day to day: log source onboarding, normalization, retention, correlation rule development, and validation of alert use cases.
  • Maintain the operating model with our managed detection partners — escalation thresholds, containment ownership, and handoff procedures.
  • Measure and report MTTD, MTTR, and MTTC against defined targets; run a regular alert-tuning cadence.
  • Develop incident-specific response playbooks and support cross-functional tabletop exercises.
  • Run hypothesis-driven threat hunting against available telemetry, with documented hypotheses, resulting detections, and tracked follow-up.

Automation & AI-Assisted Security Engineering

  • Build and agent-based workflows for enrichment, triage, and automated containment.
  • Operate and tune AI triage agents that ingest findings from cloud and vulnerability tooling, rank by severity and reachability, and route to named owners.
  • Integrate security tooling via API so detection, findings, and evidence flow automatically.
  • Automate repetitive operational work — evidence collection, inventory reconciliation, and reporting.

Vulnerability & Exposure Management

  • Run the vulnerability management lifecycle across endpoints, servers, network devices, and cloud workloads: scan coverage, risk-based prioritization, owner assignment, SLA tracking, and verification.
  • Prioritize on exploitability, reachability, and business context rather than raw CVSS.
  • Maintain an authoritative asset register reconciled across cloud, endpoint, and vulnerability tooling, with automated discovery and per-asset ownership.
  • Coordinate internal and external penetration testing across corporate, data center, and product environments; track findings to closure and retest.

Cloud & Infrastructure Security

  • Operate CSPM and CNAPP tooling across AWS, Azure, GCP, and Kubernetes, including policy enforcement and exception workflow.
  • Support infrastructure-as-code baselines, deployment-time enforcement, and drift detection.
  • Support key and secrets management: centralized storage, automated rotation, least-privilege access review, and audit coverage.
  • Operate and tune EDR across workstations, servers, and cloud workloads, and wire alerts into response workflows.

Identity Security

  • Support privileged access management, phishing-resistant MFA, and risk-based conditional access; monitor identity risk signals and build detections for credential abuse, MFA fatigue, and session anomalies.
  • Build detections for AI-enabled social engineering against help desk and finance workflows — impersonation, deepfake-assisted verification bypass, and account recovery abuse.
  • Support access review automation and joiner/mover/leaver reconciliation evidence.

AI Security & Data Protection

  • Configure and tune DLP for AI channels — labeling coverage, prompt and upload controls, and incident review.
  • Operate shadow-AI detection and enforcement, including blocking, connector approvals, and exception handling.
  • Support AI use-case intake, risk tiering, and scoped AI red team exercises against high-risk agents and applications.

Governance & Reporting

  • Produce security metrics and program reporting for leadership and governance committees.
  • Support audit evidence collection for SOC 2, ISO 27001, and related frameworks.
  • Maintain runbooks, business continuity documentation, and restore and failover test evidence.

Qualifications

Required

  • 5–8 years hands-on in security operations, with real incident triage, investigation, and containment experience.
  • Deep, practical SIEM experience — writing and tuning detections, onboarding log sources, and building correlation logic (Coralogix, Splunk, Sentinel, Elastic, or similar).
  • Strong public cloud security skills on at least one of AWS, Azure, or GCP, plus working knowledge of Kubernetes and container security.
  • Hands-on EDR operation and tuning (SentinelOne, CrowdStrike, or equivalent).
  • Vulnerability management experience at scale: scanning, risk-based prioritization, remediation tracking, and exception governance (Rapid7, Qualys, Tenable, or similar).
  • Scripting and automation ability — Python plus comfort working with REST APIs and infrastructure-as-code (Terraform).
  • Working knowledge of identity platforms and identity-centric attacks — SSO, MFA, conditional access, token theft, session hijacking (Okta or equivalent).
  • Familiarity with NIST CSF and how control maturity assessments translate into engineering work.
  • Genuine curiosity about applying AI to security work, and the judgment to know when automated output needs a human before it's trusted.
  • Strong written communication — you'll be documenting playbooks, escalation paths, and metrics that other teams depend on.

Nice to Have

  • SOAR development experience (BlinkOps, Tines, Torq, XSOAR) or building automation against security tool APIs.
  • CNAPP/CSPM experience (Wiz, Aikido, Prisma Cloud, Sysdig).
  • DLP and CASB/SSE operation (Netskope, Zscaler, Proofpoint).
  • Threat hunting experience with documented hypothesis-driven methodology.
  • Privileged access management deployment or operation.
  • Email security tuning (Abnormal, Proofpoint, Mimecast) and phishing simulation programs.
  • MDM and endpoint baseline management (Kandji, Jamf, Workspace ONE, Intune).
  • Network security fundamentals — segmentation, firewall policy review, WAF (Palo Alto, Cloudflare).
  • Backup and recovery security, including immutability and restore testing.
  • Detection engineering practices — detection-as-code, MITRE ATT&CK coverage mapping, purple team exercises.
  • Exposure to AI/LLM security: prompt injection, agentic tool abuse, MCP and connector risk, model supply chain, or AI red teaming.
  • Certifications such as GCIA, GCIH, GCFA, OSCP, AWS Security Specialty, Security+, or CISSP.
  • Bachelor's degree in Computer Science, Information Security, or a related field.

At Couchbase, we believe innovation thrives when diverse perspectives are at the table. We actively encourage applications from individuals of all backgrounds—including women, people of color, LGTBQIA+ professionals, veterans, and individuals with disabilities. If you see a role that excites you, but don’t meet every qualification, we still encourage you to apply.

Studies show underrepresented talent is less likely to apply unless they meet all the criteria. We encourage you to apply if you’re excited about the role and can bring strong contributions to our team.

If you require reasonable accommodations during the recruitment process, please let your recruiter know—we’re happy to support you.

We value diverse educational and career backgrounds. If your experience aligns with the role’s goals—even if it doesn’t follow a traditional path—we’d love to hear from you.

Why Couchbase?
Modern customer experiences need a flexible cloud database platform that can power applications spanning from cloud to edge and everything in between. Couchbase’s mission is to simplify how developers and architects develop, deploy and consume modern applications wherever they are. We have reimagined the database with our fast, flexible and affordable cloud database platform Capella, allowing organizations to quickly build applications that deliver premium experiences to their customers– all with best-in-class price performance. More than 30% of the Fortune 100 trust Couchbase to power their modern applications and build innovative new ones. See our recent awards to learn why Couchbase is a great place to work.We are honored to be a part of the Best Places to Work Award for the Bay Area and the UK. Couchbase offers a total rewards approach to benefits that recognizes the value you create here, so that you in turn may best serve yourself and your family. Some benefits include:
  • Generous Time Off Program - Flexibility to care for you and your family
  • Wellness Benefits - A variety of world class medical plans to choose from, along with dental, vision, life insurance, and employee assistance programs*
  • Financial Planning - Retirement program* and Business Travel Insurance
  • Career Growth - Be valued, Create value approach
  • Fun Perks - An ergonomic and comfortable in-office / WFH setup. Food & Snacks for in-office employees.
  • And much more!
*Note: some programs are not applicable to all countries. Please discuss with a Couchbase recruiter to learn more.
Learn more about Couchbase:
News and Press Releases
Couchbase Capella
Couchbase Blog
Investors
Disclaimer:
Couchbase is committed to being an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Join an impact initiative group and experience the amazing feeling of Couchbase can-do culture.
By using this website and submitting your information, you acknowledge our Candidate Privacy Notice and understand your personal information may be processed in accordance with our Candidate Privacy Notice following guidelines in your country of application.

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

More Security Engineer roles in Bengaluru

See all

Senior Software engineer - Advanced Threat Protection

Okta · Bengaluru

Lead Security Engineer IGA

Cyderes · Bengaluru

Sr Software Engineer - Cybersecurity Integrations (Armis)

ServiceNow · Bengaluru

Software Engineer (Cybersecurity Integrations) - Armis

ServiceNow · Bengaluru

Keep browsing

All open roles at Couchbase, Inc.All Security Engineer jobs in Bengaluru

Two ways in

Applicants who checked fit first are 3.1× more likely to hear back

Your match scoreCalculated · locked
86Overall
64Skills
97Experience

Your score for this role already exists

ASAI compared this JD against 41 signals - skills, seniority, domain, stack overlap etc. Add a resume and it unlocks in about 30 seconds.

No credit card · 1 tap with Google

Free · no signup

Get tomorrow's jobs before you have to search

Daily job drops, skill trends and free resources - posted straight to the group. Leave any time.

Join WhatsAppJoin Telegram

No spam. Just jobs and resources.

Why people use ASAI

Someone shared one job with you. ASAI keeps finding the rest.

  • Scored, not searched. Every role ranked against your actual profile.

  • Alerts as often as hourly. Reach new roles while the pile is still small.

  • Skill gaps, spelled out. See exactly which requirements you don't meet yet.

  • Verified jobs, only. Say no to ghost jobs. Your time deserves respect.

ASAI job platform logo

A job platform finally, balanced in your favour.

Jobs by CityJobs by CompanyGuidesHow We VerifyAboutPrivacy PolicyTerms of Service

Built in India 🇮🇳

© 2026 ASAI. All rights reserved.