{"id":1361648,"url":"https://alion.io/job/constant-security-engineer-gioc","title":"Security Engineer, GIOC","company":{"id":1786392,"name":"Constant","domain":"constant.com","url":"https://alion.io/company/constant-com","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"B","score":75,"open_postings":12,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-29T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Chennai, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":14000,"max_usd":34000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":414},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ITSM","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"Vultr","optional":false},{"name":"Confluence","optional":true},{"name":"ITIL","optional":true},{"name":"PagerDuty","optional":true},{"name":"PowerShell","optional":true},{"name":"Python","optional":true}],"status":"live","first_seen_at":"2026-09-25T12:38:15Z","employer_posted_date":"2026-09-25","last_verified_at":"2026-09-29T19:17:53Z","board_verified":true,"closed_at":null,"days_open":4,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":4},"description":"Who We Are\nVultr is on a mission to make high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators around the world. With 33 global cloud data center locations, Vultr is trusted by hundreds of thousands of active customers across 185 countries for its flexible, scalable, global Cloud Compute, Cloud GPU, Bare Metal, and Cloud Storage solutions. In December 2024 Vultr announced an equity financing at a $3.5 billion valuation. Founded by David Aninowsky and self-funded for over a decade, Vultr has grown to become the world’s largest privately-held cloud infrastructure company.\nVultr Cares\nMedical Insurance stipend paid annually\n\n9 Company-Paid Holidays\n\nGenerous Leave Policy + 1 month paid sabbatical every 5 years + Anniversary Bonus each year\n\nProfessional Development Reimbursement\n\nInternet reimbursement\n\nFitness membership reimbursement\n\nCompany paid Wellable subscription\n\nJoin Vultr\nVultr is expanding its India presence and is building its first Global Integrated Operations Command Center (GIOC) in Chennai - the 24x7 nerve center for monitoring, triage, and first response across Vultr’s global security operations.\nWe are seeking Security Engineers to serve as the first line of response across Vultr’s security signal surface - SIEM, threat, identity, and access alerts. This is a frontline security operations role for engineers who triage SIEM alerts, perform first-line containment, and preserve evidence in real time - and who want to grow into deeper SOC, threat-detection, or security engineering careers. You must be comfortable working a rotational shift model - including nights, weekends, and holidays - to sustain the coverage.\nRole Overview\nThe Security Engineer is the entry point of the GIOC incident lifecycle for the security tower. You monitor security signals, acknowledge and triage alerts within defined first-response SLAs, execute documented runbooks to investigate and contain common security events, and escalate cleanly to Senior Security when an alert falls outside L1 scope. The role ensures fast, accurate first response that protects customer data and platform security.\nYou operate from a consolidated single-pane-of-glass dashboard, classifying and routing incidents by severity and tower while owning accurate, complete documentation and chain-of-custody for every action. Success is measured by first-response SLA adherence, triage accuracy, and runbook resolution rate. The role runs on a rotational schedule to sustain 24x7 coverage.\nKey Responsibilities\nAlert Monitoring & First Response\nMonitor security signals - SIEM detections, authentication and access anomalies, threat-intel and endpoint alerts - from a consolidated single-pane-of-glass dashboard\n\nAcknowledge alerts and incidents within first-response SLA targets\n\nPerform initial review - validate the detection, rule out false positives, check recent changes, and review the CMDB before acting\n\nTriage & Severity Classification\nClassify each alert by severity and potential impact, confirming the owning tower (Security / cross-tower)\n\nRoute and assign tickets accurately to the correct tower or escalation path\n\nSustain triage accuracy at or above the GIOC go-live standard\n\nReassess severity as the investigation evolves, and declare higher when in doubt - treat suspected breaches as high-severity until ruled out\n\nRunbook-Driven Investigation & Containment\nMatch alert signatures to documented runbooks and execute permitted L1 actions\n\nPerform first-line containment within L1 scope (e.g., isolate, disable, or block per runbook) and preserve evidence for analysis\n\nDocument every step taken, with supporting evidence and timestamps, in the incident ticket\n\nEscalation & Handoff\nEscalate unresolved or out-of-scope alerts to the Senior Security Engineers with a clean, complete handoff (symptom · evidence collected · steps tried · current state)\n\nFlag missing or ineffective runbooks and detection gaps for review and continuous improvement\n\nInitiate and support major-incident (Sev-0 / Sev-1) bridges per the escalation matrix; engage Security leads and incident response immediately on suspected breaches\n\nTrack escalations to closure and confirm the threat is contained or ruled out before resolving the ticket\n\nOperational Documentation & Communication\nMaintain accurate shift logs, ticket updates, and incident timelines with chain-of-custody for security evidence\n\nProvide clear, timely status communication to stakeholders per severity, following defined disclosure and confidentiality protocols\n\nProduce thorough shift-handover notes for seamless follow-the-sun continuity on active investigations\n\nContinuous Improvement\nIdentify recurring alerts and false positives as candidates for detection tuning and automation\n\nContribute to and improve runbooks, detection logic, and knowledge-base articles\n\nParticipate in post-incident reviews (PIR) and trend reviews\n\nQualifications & Experience\nGraduate/Engineer in a relevant field (B.E./B.tech or equivalent)\n\n3-5 years of experience in a SOC, security operations, or IT operations, including hands-on security monitoring and alert triage\n\nWorking knowledge of security fundamentals - authentication and access, common attack types, logging, and endpoint/network telemetry\n\nFamiliarity with SIEM and alert-triage concepts, log analysis, and basic threat investigation\n\nUnderstanding of incident-management fundamentals and severity-based triage\n\nExposure to monitoring/observability tools and ticketing systems (SIEM consoles, alerting, ITSM)\n\nStrong written communication for accurate documentation and clean escalation handoffs; willingness and ability to work a rotational 24x7 shift model, including nights, weekends, and holidays\n\nProficient in English verbal and written communication\n\nPreferred Qualifications\nITIL V4 Foundation certification or equivalent ITSM knowledge\n\nSecurity certification (CompTIA Security+, CySA+, or equivalent)\n\nScripting familiarity (Bash, Python, or PowerShell) for routine automation\n\nExposure to cloud security and GPU / high-density infrastructure\n\nPrior experience in a 24x7 SOC or command-center environment, and tools such as JIRA, Confluence, PagerDuty, SIEM, and observability platforms\n\nInclusion & Privacy\nWe are an equal opportunity employer and are committed to creating an inclusive environment for all employees. We welcome applications from individuals of all backgrounds and experiences, and we prohibit discrimination based on race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected status under applicable laws. Vultr will consider qualified applicants with arrest or conviction records in accordance with applicable laws and will not conduct a background check until after an offer of employment has been extended and accepted.\nWe also take your privacy seriously. We handle personal information responsibly and follow applicable laws, including U.S. privacy rules and India’s Digital Personal Data Protection Act, 2023. Your data is used only for legitimate business purposes and is protected with proper security measures.\nWhere allowed by law, applicants may request details about the data we collect, access or delete their information, withdraw consent for its use, and opt out of nonessential communications. For more details, please see our Privacy Policy.","description_format":"text","description_chars":7440,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"English","level":"Advanced (C1)","optional":false}]},"benefits":["Equity","Health insurance","Internet reimbursement","Professional development"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Internet Services","Cloud Platforms (IaaS & PaaS)","Cloud Storage & File Sharing"],"lifecycle":[{"event":"open","at":"2026-09-28T00:02:51Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":3,"expected_fill_days":33,"reasons":["conf:2","stale_co","velocity","win:early"],"computed_at":"2026-09-29T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/constant-security-engineer-gioc","json_url":"https://alion.io/job/constant-security-engineer-gioc.json","meta":{"generated_at":"2026-09-30T02:08:03Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1533,"day_limit":5000,"remaining_today":3467,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}