Senior Security Operations Engineer
Pure Storage
- Location
- Bangalore, India
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 67 approvals (FY2023)
- Posted
- 2h ago
Skills
About this role
Everpure (NYSE: P) has evolved from storage pioneer to data platform, closing fiscal 2026 with $3.7 billion in revenue, its first billion-dollar quarter, and accelerating growth into FY27. Our strategic agenda spans the companies defining the next era of technology - hyperscalers, AI labs, the AI hardware supply chain, data platform providers, and the broader AI ecosystem.
This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.
THE ROLE
As a Senior Security Operations Engineer – Attack Surface Management, you will help engineer, operate, and continuously improve our enterprise Attack Surface and Vulnerability Management capabilities.
You will focus on discovering and understanding our attack surface, identifying vulnerabilities and exposures, prioritizing them based on real-world risk, and driving remediation across our global environment.
The role spans Attack Surface Management, Vulnerability Management, Zero Trust, Secrets and Credential Security, SSPM, Deception, Detection Engineering and Security Automation. We are looking for engineers with strong ASM/Vulnerability Management fundamentals and deeper expertise in one or more adjacent security domains.
WHAT YOU'LL DO
• Engineer and improve enterprise Attack Surface and Vulnerability Management across cloud, infrastructure, endpoints, applications, and internet-facing environments.
• Discover and correlate assets across security platforms and identify unknown, unmanaged, stale, and externally exposed assets.
• Drive risk-based vulnerability prioritization using asset criticality, exposure, exploitability, known exploitation, threat intelligence, and compensating controls.
• Establish remediation workflows and SLAs and partner with asset owners to drive measurable risk reduction.
• Operate and troubleshoot Zscaler ZIA/ZPA, including SSL inspection, access policies, connectivity, and Zero Trust controls.
• Discover and investigate exposed secrets and credentials across source code, CI/CD, cloud, repositories, and enterprise platforms, and coordinate remediation and credential rotation.
• Develop and improve SIEM detections to identify exploitation, anomalous activity, credential abuse, and attack-surface-related threats.
• Support threat hunting and incident investigations using vulnerability, asset, endpoint, and threat intelligence context.
• Develop automation using Python, PowerShell, REST APIs, and SOAR for asset enrichment, vulnerability triage, remediation tracking, integrations, and reporting.
• Partner with Cloud, Infrastructure, Network, Product Security, and Engineering teams to investigate exposures and drive remediation.
• Translate technical findings into clear, actionable risk guidance and reporting for technical teams and leadership.
• Support security governance and compliance requirements including SOC 2, ISO 27001, and NIST.
WHAT YOU BRING
• 7+ years of cybersecurity experience, with hands-on experience in Security Operations, Attack Surface Management, Vulnerability Management, or Exposure Management.
• Strong understanding of asset discovery, vulnerability lifecycle, risk-based prioritization, remediation, and validation.
• Hands-on experience with platforms such as Tenable, Qualys, Wiz, Prisma Cloud, or similar technologies.
• Strong security fundamentals across TCP/IP, DNS, HTTP/HTTPS, TLS, proxies, firewalls, operating systems, identity, and cloud infrastructure.
• Experience automating security workflows using Python, PowerShell, REST APIs, or similar technologies.
• Strong troubleshooting and analytical skills with the ability to