India - Default Template
Bengaluru, Karnataka, India
About Tekion:
Positively disrupting an industry that has not seen any innovation in over 50 years, Tekion has challenged the paradigm with the first and fastest cloud-native automotive platform that includes the revolutionary Automotive Retail Cloud (ARC) for retailers, Automotive Enterprise Cloud (AEC) for manufacturers and other large automotive enterprises and Automotive Partner Cloud (APC) for technology and industry partners. Tekion connects the entire spectrum of the automotive retail ecosystem through one seamless platform. The transformative platform uses cutting-edge technology, big data, machine learning, and AI to seamlessly bring together OEMs, retailers/dealers and consumers. With its highly configurable integration and greater customer engagement capabilities, Tekion is enabling the best automotive retail experiences ever. Tekion employs close to 3,000 people across North America, Asia and Europe.
Job Introduction:
The Security Threat Detection Engineer II (SOC) is a hands-on member of the company's 24x7 Security Operations Center, responsible for monitoring, triaging, and responding to security alerts across the company's technology environment. This role operates on a rotating shift schedule, including night shifts, weekends, and holidays, to ensure continuous security coverage. A major focus of this role is responding to and investigating security alerts, reducing false positives through detection tuning, building and improving detection rules, conducting proactive threat hunting, performing malware analysis to support investigations, tracking and reporting SOC metrics, and automating response workflows using AI agents and SOAR platforms. The Engineer II works on moderately complex projects with minimal supervision and partners with IT, Engineering, and Security Operations to identify risks, remediate vulnerabilities, and strengthen overall security posture.
Key Roles & Responsibilities
Work in a 24x7 SOC environment on a rotating shift schedule, including night shifts, weekends, and holidays, providing continuous alert monitoring and response coverage.
Triage, investigate, and respond to security alerts from SIEM, EDR, cloud, network, and identity sources; escalate confirmed incidents per established procedures.
Continuously tune detections and alert logic to reduce false positives and improve signal-to-noise ratio across the alert pipeline.
Build, test, and maintain detection rules and use cases aligned to frameworks such as MITRE ATT&CK, based on emerging threats and gaps identified during investigations.
Conduct proactive, hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry to uncover threats that evade existing detections, and convert hunt findings into new detection rules.
Perform malware analysis (static and dynamic/sandbox-based) on suspicious files, scripts, and artifacts to determine behavior, extract indicators of compromise (IOCs), and inform containment, detection, and response actions.
Design, build, and maintain automation using AI agents and SOAR workflows/playbooks to accelerate alert triage, enrichment, containment, and response.
Define, track, and report SOC metrics (e.g., MTTD, MTTR, alert volume, false positive rates, automation coverage) to measure and improve SOC effectiveness.
Participate in incident detection, response, containment, and root cause analysis, including post-incident reviews and lessons learned.
Implement, configure, and maintain security tools, monitoring systems, and access controls that support SOC operations.
Support vulnerability management, including scanning, analysis, and remediation coordination.
Collaborate with Engineering and IT teams to embed security best practices and improve telemetry, logging, and detection coverage.
Assist in maintaining compliance with security standards and regulatory requirements (e.g., SOC 2, ISO 27001, NIST).
Contribute to threat modeling and risk assessments for new projects and technologies.
Create and maintain security documentation, runbooks, playbooks, and knowledge bases to support consistent shift handoffs and response quality.
Provide guidance and mentorship to junior engineers and analysts, including during shift operations.
Stay current on emerging security threats, detection techniques, AI-driven security tooling, and technologies.
Basic Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field; equivalent experience considered.
4–6 years of experience in security operations, security engineering, incident response, or related roles.
Willingness and ability to work in a 24x7 SOC on a rotating shift schedule, including night shifts, weekends, and holidays.
Hands-on experience with alert triage, investigation, and incident response in a SOC environment.
Experience building and tuning detections in SIEM/EDR platforms and reducing false positives; familiarity with MITRE ATT&CK.
Experience conducting threat hunts using endpoint, network, cloud, and identity telemetry, and translating findings into detections.
Experience with malware analysis, including static and dynamic analysis, sandboxing tools, and IOC extraction; familiarity with tools such as sandbox environments, YARA, or disassemblers/debuggers is a plus.
Experience with SOAR platforms and building automated playbooks; exposure to AI agents or LLM-based automation for security operations strongly preferred.
Strong understanding of network, application, and cloud security principles.
Experience with security tools such as SIEM, EDR, IDS/IPS, vulnerability scanners, and endpoint protection.
Knowledge of cloud platforms (AWS, GCP, Azure) and their security services and logging.
Familiarity with compliance and security frameworks (NIST, ISO 27001, SOC 2, CIS).
Scripting or automation experience (Python, Bash, or equivalent) preferred.
Experience defining and reporting operational security metrics (MTTD, MTTR, false positive rates) preferred.
Strong analytical and problem-solving skills.
Good written and verbal communication abilities, including clear documentation and shift handoffs.
Industry certifications such as CISSP, GCIH, GCIA, GCFA, GREM, GCTI, or CEH preferred.
Perks & Benefits
Opportunity to work with some of the smartest minds to solve complex challenges at scale.
Impactful role in shaping and securing a global, cloud-native & AI driven platform.
Innovative, collaborative, and fast-paced culture.
Effective 4 Aug 2026, Current Tekion Employees should apply via the Internal Job Board in Ashby
Tekion is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, victim of violence or having a family member who is a victim of violence, the intersectionality of two or more protected categories, or other applicable legally protected characteristics.
For more information on our privacy practices, please refer to our Applicant Privacy Notice here.