hirly

Vectranetworks

Senior Detection Engineer - Cloud

Bengaluru, Karnataka, India

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Vectranetworks first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Senior
Country
IN
Work mode
Remote-friendly
First seen by hirly
13 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Vectra® is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises.

The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond to the most advanced cyber-attacks. With 35 patents in AI-driven threat detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai.

Position Overview

We are seeking an experienced Threat Detection Engineer to extend Vectra's detection capabilities across cloud and identity environments , with additional exposure to network-based threat detection.

Vectra's Attack Signal Production Group is responsible for building Vectra's core threat detection and prioritization technology, leveraging AI and other methods to alert customers to critical threats across their cloud, identity, and network environments.

Threat Detection Engineers work closely with Data Scientists who are developing AI models, and Security Researchers who are researching the threat landscape and assisting modeling efforts . This role will focus primarily on developing detections for cloud and identity attack behaviours , including threats across AWS, Azure, GCP, and identity platforms such as Microsoft Entra ID.

The ideal candidate has hands-on experience investigating cloud and identity threats using telemetry such as authentication and audit logs, CloudTrail, cloud platform logs, and network flow data. Familiarity with network threat models, protocols, and network-based telemetry is important, particularly as cloud detection increasingly incorporates data sources such as VPC and flow logs.

The role is primarily focused on cloud and identity threat detection , while providing the versatility to contribute to network detection initiatives where relevant.

Responsibilities and Accountabilities

Research cloud and identity attack behaviours and identify opportunities for new detections.

Develop, test, and maintain detection logic using Python and other appropriate detection technologies.

Analyze telemetry from cloud and identity environments, including authentication activity, control-plane activity, audit logs, application logs, and network flow logs.

Develop detections across common cloud platforms such as AWS, Azure as well as identity environments such as Microsoft Entra ID.

Investigate malicious activity and reproduce attacker techniques to validate detection hypotheses.

Collaborate with Data Scientists and Security Researchers to improve detection coverage and accuracy.

Continuously assess detection effectiveness and improve detections based on real-world data.

Stay current with emerging cloud, identity, and network attacker techniques and TTPs.

Work with large and diverse security datasets using technologies and techniques such as Python, notebooks, SQL, Pandas, and cloud analytics platforms.

Contribute to network threat detection where appropriate, including analysis of network protocols, flow data, PCAPs, and network attack behaviours.

Attitudes and Behaviours

Focus on impact and results; work on the right problems and drive them through to completion.

Demonstrate curiosity and a strong investigative mindset when working with unfamiliar attacker behaviours, telemetry, or technologies.

Show drive and resourcefulness in overcoming technical ambiguity and incomplete information.

Have a track record of successfully solving complex and ambiguous problems.

Balance detection coverage with detection quality, scalability, and maintainability.

Demonstrate high integrity and an ability to collaborate effectively across Security Research, Data Science, Engineering, and Product teams.

Qualifications and Experience

6+ years of cybersecurity experience, preferably focused on threat detection, security research, threat hunting, incident response, or detection engineering.

Strong experience investigating threats in cloud and identity environments.

Hands-on knowledge of AWS/Azure cloud platform.

Strong understanding of identity concepts, cloud and identity attack techniques; experience with Microsoft Entra ID is preferred.

Experience working with security telemetry such as CloudTrail, cloud audit logs , authentication logs, flow logs, PCAPS and network telemetry.

Working proficiency in Python , including experience using Python for data analysis, automation, investigation, or detection development.

Working knowledge of network security fundamentals, protocols, and network threat models .

Familiarity with large-scale analytics or data platforms such as Databricks, cloud-native log analytics platforms, or equivalent technologies .

Excellent technical, analytical, communication, and collaboration skills.

Preferred Experience

Experience building and operating production-quality cloud or identity detections, rather than solely investigating alerts generated by existing products.

Experience developing detections using multiple telemetry sources or correlating activity across identity, cloud control-plane, workload, and network data.

Experience with adversary simulation or offensive security techniques in AWS, Azure or identity environments.

Experience analyzing network traffic using tools such as Wireshark, Zeek, Suricata, or similar technologies.

Optional certifications such as OSCP, GCIA, GCDA, GSEC, cloud security certifications, or equivalent practical experience .

Vectra provides a comprehensive total rewards package that supports the financial, physical, mental and overall health of our employees and their families. Compensation includes competitive base pay, incentive pla n eligibility, and participation in the employee equity plan (stock options). Specific benefits offered var ies by location, but commonly in clude health care insurance , income protection / life insurance , access to retirement savings plans, behavioral & emotional wellness services , generous time away from work, and a comprehensive employee recognition program.

Vectra is committed to creating a diverse environment and is proud to be an equal opportunity employer.

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.

Original posting on Vectranetworks's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job