Couchbase, Inc. logo

Senior Security Operations Engineer

Couchbase, Inc. · Posted Sep 15

Cloud database, operational data platform, NoSQL, and database-as-a-service solutions

Bangalore, IndiaFull-timeHybridSenior Level5–9 years₹40.0L–₹65.0L yearly100+ applicants
SoftwareBig DataEnterprise SaaSDatabaseNoSQLCloud ComputingGrowth Stage
Full time

Get a personal compatibility score

Add a resume for personal matches

About the role

Couchbase is the operational data platform for AI, and its global Information Security team is hiring a Senior Security Operations Engineer as its second dedicated SecOps engineer. The role sits at the intersection of AI-driven threats and AI-assisted defense, with roughly half the time spent on operational triage, investigation, and containment and the other half on engineering and program work across detection, automation, cloud, identity, and AI security. You will work across Engineering, SRE, IT, Cloud, Legal, and Compliance.

What you will do

  • Own alert triage, investigation, and containment alongside our existing SecOps engineer, supporting a follow-the-sun coverage model.
  • Manage the SIEM day to day: log source onboarding, normalization, retention, correlation rule development, and validation of alert use cases.
  • Maintain the operating model with our managed detection partners — escalation thresholds, containment ownership, and handoff procedures.
  • Measure and report MTTD, MTTR, and MTTC against defined targets; run a regular alert-tuning cadence.
  • Develop incident-specific response playbooks and support cross-functional tabletop exercises.
  • Run hypothesis-driven threat hunting against available telemetry, with documented hypotheses, resulting detections, and tracked follow-up.
  • Build and agent-based workflows for enrichment, triage, and automated containment.
  • Operate and tune AI triage agents that ingest findings from cloud and vulnerability tooling, rank by severity and reachability, and route to named owners.
  • Integrate security tooling via API so detection, findings, and evidence flow automatically.
  • Automate repetitive operational work — evidence collection, inventory reconciliation, and reporting.
  • Run the vulnerability management lifecycle across endpoints, servers, network devices, and cloud workloads: scan coverage, risk-based prioritization, owner assignment, SLA tracking, and verification.
  • Prioritize on exploitability, reachability, and business context rather than raw CVSS.
  • Maintain an authoritative asset register reconciled across cloud, endpoint, and vulnerability tooling, with automated discovery and per-asset ownership.
  • Coordinate internal and external penetration testing across corporate, data center, and product environments; track findings to closure and retest.
  • Operate CSPM and CNAPP tooling across AWS, Azure, GCP, and Kubernetes, including policy enforcement and exception workflow.
  • Support infrastructure-as-code baselines, deployment-time enforcement, and drift detection.
  • Support key and secrets management: centralized storage, automated rotation, least-privilege access review, and audit coverage.
  • Operate and tune EDR across workstations, servers, and cloud workloads, and wire alerts into response workflows.
  • Support privileged access management, phishing-resistant MFA, and risk-based conditional access; monitor identity risk signals and build detections for credential abuse, MFA fatigue, and session anomalies.
  • Build detections for AI-enabled social engineering against help desk and finance workflows — impersonation, deepfake-assisted verification bypass, and account recovery abuse.
  • Support access review automation and joiner/mover/leaver reconciliation evidence.
  • Configure and tune DLP for AI channels — labeling coverage, prompt and upload controls, and incident review.
  • Operate shadow-AI detection and enforcement, including blocking, connector approvals, and exception handling.
  • Support AI use-case intake, risk tiering, and scoped AI red team exercises against high-risk agents and applications.
  • Produce security metrics an...

Skills used in this role

SIEMAICloud SecurityAWSAzureGCPKubernetesCSPMCNAPPEDRDLPMFAPAMInfrastructure as CodeAPIThreat HuntingVulnerability ManagementIncident ResponsePenetration TestingSecurity AutomationIdentity SecurityData ProtectionEndpoint SecurityAI SecurityMCP

Benefits and support

  • Compensation and benefits are detailed in the job posting

About Couchbase, Inc.

Couchbase, Inc. provides a modern, AI-ready cloud database and developer data platform that empowers enterprises to build, deploy, and run mission-critical applications. Its flagship solutions include Couchbase Server, Couchbase Capella (fully managed DBaaS), and Couchbase Mobile & Edge, designed to unify operational, analytical, and AI workloads across cloud and edge environments.

Industry
Software
Company size
800-1000 employees
Founded
2011
Location
San Jose, California, USA
Funding stage
Private Company

Funding

Private Company · $251M raised

AccelNorth Bridge Venture PartnersMayfield FundRedpoint VenturesIgnition PartnersAdams Street PartnersHaveli Investments
  • 2020-05-21Series G$105M

Leadership

BS
BJ Schaknowski

Chief Executive Officer

BM
Barry Morris

Chief Product and Strategy Officer

DT
Deirdre Toner

President and Chief Commercial Officer

GD
Gopi Duddi

Chief Technology Officer

JH
Josh Harbert

Chief Marketing Officer