SECTION I · THE BRIEF
Brief #32925Updated 21 SEP 2026REMOTEGreenhouseSOFTWARE COMPANIES
Employbl Company Profile

Senior Security Engineer

Arcana combines proprietary datasets, rigorous analysis tooling and best-in-class data integrity to enable the world’s top institutions to make high-impact decisions about digital asset strategy and allocation. Arcana…

Location
Remote
Company size
10–50
Posted
Today
Via
Greenhouse
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Senior Security Engineer

Arcana· Bangalore, HybridView company profile


Job title
Senior Security Engineer
Job location
Bangalore, Hybrid
Job description

Senior Security Engineer 

We are looking for a hands-on Senior Security Engineer to own and improve security operations across our corporate IT, cloud, and Kubernetes environments. The role covers security monitoring and detection, incident response, security tooling and integrations, automation, and day-to-day IT security.

What You'll Do

  • Own security monitoring, triage, investigation, and incident response across endpoint, identity, email, network, SaaS, GCP, and GKE environments.
  • Operate and improve security capabilities across SIEM, EDR, DLP, cloud security, network security, and identity security.
  • Integrate security tools and telemetry into the SOC to improve visibility, correlation, investigation, and response.
  • Build and tune detections, correlation rules, alerts, dashboards, and monitoring use cases based on attack scenarios and observed activity.
  • Build automated workflows for alert enrichment, triage, investigation, containment, escalation, and response using APIs and scripting.
  • Investigate incidents end-to-end, including scoping, evidence collection, root-cause analysis, containment, remediation, and post-incident actions.
  • Monitor and investigate GCP and GKE activity, including IAM changes, service-account activity, cloud audit events, Kubernetes activity, workload behaviour, and network events.
  • Identify gaps and misconfigurations across cloud IAM, Kubernetes RBAC, workloads, containers, secrets, network controls, logging, and security configurations.
  • Manage and tune DLP controls and investigate potential data-exfiltration or policy-violation events.
  • Investigate phishing and account-compromise activity, including email headers, URLs, domains, attachments, authentication events, and indicators of compromise.
  • Support IT security across endpoints, device posture, identity and access, SaaS applications, privileged access, and security configurations.
  • Work with infrastructure and engineering teams to remediate security findings and improve logging, detection coverage, and preventive controls.
  • Maintain practical incident-response playbooks, detection documentation, and investigation procedures.

What You'll Need

  • 5–7 years of hands-on cybersecurity experience, with strong experience in security operations, security engineering, or incident response.
  • Strong hands-on experience with SIEM and EDR, including log analysis, detection development, alert tuning, investigation, and response.
  • Experience integrating security technologies and telemetry using APIs, webhooks, scripts, or automation/orchestration platforms.
  • Experience building and automating SOC and incident-response workflows rather than relying entirely on manual triage.
  • Hands-on experience securing and monitoring Google Cloud Platform (GCP).
  • Strong understanding of GCP IAM, service accounts, audit logging, VPC networking, storage, KMS, and cloud security controls.
  • Hands-on security experience with Kubernetes/GKE, including RBAC, service accounts, namespaces, secrets, network policies, workload security, container security, and audit logging.
  • Ability to investigate activity across cloud control-plane, Kubernetes, container/workload, identity, and network telemetry.
  • Good understanding of DLP and experience tuning policies and investigating data-security events.
  • Strong networking fundamentals, including DNS, HTTP/S, TCP/IP, VPNs, proxies, firewalls, and network traffic analysis.
  • Experience investigating phishing, credential compromise, endpoint threats, suspicious network activity, cloud events, and container/Kubernetes security events.
  • Understanding of common attacker behaviours and techniques, including privilege escalation, credential abuse, persistence, lateral movement, and data exfiltration.
  • Working knowledge of MITRE ATT&CK and its practical application to detection and investigation.
  • Hands-on scripting or automation experience with Python, shell scripting, or similar technologies.
  • Ability to independently take a security event from initial detection through investigation, containment, remediation, and closure.

Good to Have

  • Experience building or maturing a SOC/security operations capability in a cloud-first environment.
  • Experience with security orchestration and automated response.
  • Experience with cloud security posture management, vulnerability management, and container/workload security.
  • Experience developing custom detections using telemetry from multiple security and infrastructure sources.
  • Familiarity with Infrastructure-as-Code and CI/CD security from an operational security perspective.

 

View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.