368,746open jobs
9,444companies
47,506added this week
Browse all
Salary
$23k – $59k per year (Estimated)
Location
In office (Bengaluru)
Seniority
Middle · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Tekion is an end-to-end, AI-native automotive retail platform that unifies dealership operations - DMS, CRM, digital retail, service, payments and analytics - on a single cloud-based operating system. Tekion powers 3,000+ dealerships and has processed $43B+ in transactions.

About Tekion:

Positively disrupting an industry that has not seen any innovation in over 50 years, Tekion has challenged the paradigm with the first and fastest cloud-native automotive platform that includes the revolutionary Automotive Retail Cloud (ARC) for retailers, Automotive Enterprise Cloud (AEC) for manufacturers and other large automotive enterprises and Automotive Partner Cloud (APC) for technology and industry partners. Tekion connects the entire spectrum of the automotive retail ecosystem through one seamless platform. The transformative platform uses cutting-edge technology, big data, machine learning, and AI to seamlessly bring together OEMs, retailers/dealers and consumers. With its highly configurable integration and greater customer engagement capabilities, Tekion is enabling the best automotive retail experiences ever. Tekion employs close to 3,000 people across North America, Asia and Europe.

Job Introduction:

The Security Threat Detection Engineer II (SOC) is a hands-on member of the company's 24x7 Security Operations Center, responsible for monitoring, triaging, and responding to security alerts across the company's technology environment. This role operates on a rotating shift schedule, including night shifts, weekends, and holidays, to ensure continuous security coverage. A major focus of this role is responding to and investigating security alerts, reducing false positives through detection tuning, building and improving detection rules, conducting proactive threat hunting, performing malware analysis to support investigations, tracking and reporting SOC metrics, and automating response workflows using AI agents and SOAR platforms. The Engineer II works on moderately complex projects with minimal supervision and partners with IT, Engineering, and Security Operations to identify risks, remediate vulnerabilities, and strengthen overall security posture.

Key Roles & Responsibilities

  • Work in a 24x7 SOC environment on a rotating shift schedule, including night shifts, weekends, and holidays, providing continuous alert monitoring and response coverage.

  • Triage, investigate, and respond to security alerts from SIEM, EDR, cloud, network, and identity sources; escalate confirmed incidents per established procedures.

  • Continuously tune detections and alert logic to reduce false positives and improve signal-to-noise ratio across the alert pipeline.

  • Build, test, and maintain detection rules and use cases aligned to frameworks such as MITRE ATT&CK, based on emerging threats and gaps identified during investigations.

  • Conduct proactive, hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry to uncover threats that evade existing detections, and convert hunt findings into new detection rules.

  • Perform malware analysis (static and dynamic/sandbox-based) on suspicious files, scripts, and artifacts to determine behavior, extract indicators of compromise (IOCs), and inform containment, detection, and response actions.

  • Design, build, and maintain automation using AI agents and SOAR workflows/playbooks to accelerate alert triage, enrichment, containment, and response.

  • Define, track, and report SOC metrics (e.g., MTTD, MTTR, alert volume, false positive rates, automation coverage) to measure and improve SOC effectiveness.

  • Participate in incident detection, response, containment, and root cause analysis, including post-incident reviews and lessons learned.

  • Implement, configure, and maintain security tools, monitoring systems, and access controls that support SOC operations.

  • Support vulnerability management, including scanning, analysis, and remediation coordination.

  • Collaborate with Engineering and IT teams to embed security best practices and improve telemetry, logging, and detection coverage.

  • Assist in maintaining compliance with security standards and regulatory requirements (e.g., SOC 2, ISO 27001, NIST).

  • Contribute to threat modeling and risk assessments for new projects and technologies.

  • Create and maintain security documentation, runbooks, playbooks, and knowledge bases to support consistent shift handoffs and response quality.

  • Provide guidance and mentorship to junior engineers and analysts, including during shift operations.

  • Stay current on emerging security threats, detection techniques, AI-driven security tooling, and technologies.

Basic Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related field; equivalent experience considered.

  • 4-6 years of experience in security operations, security engineering, incident response, or related roles.

  • Willingness and ability to work in a 24x7 SOC on a rotating shift schedule, including night shifts, weekends, and holidays.

  • Hands-on experience with alert triage, investigation, and incident response in a SOC environment.

  • Experience building and tuning detections in SIEM/EDR platforms and reducing false positives; familiarity with MITRE ATT&CK.

  • Experience conducting threat hunts using endpoint, network, cloud, and identity telemetry, and translating findings into detections.

  • Experience with malware analysis, including static and dynamic analysis, sandboxing tools, and IOC extraction; familiarity with tools such as sandbox environments, YARA, or disassemblers/debuggers is a plus.

  • Experience with SOAR platforms and building automated playbooks; exposure to AI agents or LLM-based automation for security operations strongly preferred.

  • Strong understanding of network, application, and cloud security principles.

  • Experience with security tools such as SIEM, EDR, IDS/IPS, vulnerability scanners, and endpoint protection.

  • Knowledge of cloud platforms (AWS, GCP, Azure) and their security services and logging.

  • Familiarity with compliance and security frameworks (NIST, ISO 27001, SOC 2, CIS).

  • Scripting or automation experience (Python, Bash, or equivalent) preferred.

  • Experience defining and reporting operational security metrics (MTTD, MTTR, false positive rates) preferred.

  • Strong analytical and problem-solving skills.

  • Good written and verbal communication abilities, including clear documentation and shift handoffs.

  • Industry certifications such as CISSP, GCIH, GCIA, GCFA, GREM, GCTI, or CEH preferred.

Perks & Benefits

  • Opportunity to work with some of the smartest minds to solve complex challenges at scale.

  • Impactful role in shaping and securing a global, cloud-native & AI driven platform.

  • Innovative, collaborative, and fast-paced culture.

Effective 4 Aug 2026, Current Tekion Employees should apply via the Internal Job Board in Ashby

Tekion is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, victim of violence or having a family member who is a victim of violence, the intersectionality of two or more protected categories, or other applicable legally protected characteristics.

For more information on our privacy practices, please refer to our Applicant Privacy Notice here.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,746 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Bengaluru
Senior ML Engineer 2 hours ago
$149k – $224k per year • In office • Full-Time • 5+ years exp • Master's Degree • San Francisco • Washington • Palo Alto
Python
Python
pySpark
Databases
Apache Kafka
AI/ML
AI Agents
Agentforce
Airflow
Anomaly Detection
Feature Store
Flink
Ray
Red Teaming
Spark
DevOps
CI/CD
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Marketing
Salesforce
Apply
$256k – $320k per year • Remote/Hybrid • Full-Time • Seattle
Go
Python
AI/ML
AI Agents
CrewAI
LangChain
LangGraph
DevOps
AWS
GCP
Kubernetes
Apply
$44k – $115k per year (Estimated) • Remote • Full-Time • 8+ years exp • Bachelor's Degree • Mexico
Apex
JavaScript
Apex
Lightning Web Components
Salesforce CLI
AI/ML
AI Agents
ChatGPT
Claude
Cursor
Prompt Engineering
Agentforce
LLM Guardrails
Model Context Protocol
Frontend
Web Components
DevOps
CI/CD
Git
Rest API
GitHub
Cybersecurity
HIPAA
Marketing
Salesforce
Apply
$170k – $220k per year • Equity 1–2.8% • In office • Full-Time • 3+ years exp • San Francisco
Python
SQL
Python
Django
AI/ML
AI Agents
Context Engineering
LLM
LLM Evaluation
RAG
Apply
In office • Internship • Master's Degree • Austin
C++
Python
C++
PyTorch C++
AI/ML
AI Agents
CUDA
CUDA Toolkit
LLM
NCCL
PyTorch
TensorRT
TensorRT-LLM
Triton
vLLM
Apply
$32k – $78k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Bengaluru
Python
DevOps
AWS
Azure
Incident Management
Kubernetes
Platform Engineering
SLI/SLO/SLA
Terraform
IAM
Cybersecurity
CIS Benchmarks
ISO 27001
NIST CSF
SOC 2
Apply
$166k – $249k per year • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • Pleasanton
Apply
$34k – $83k per year (Estimated) • In office • Full-Time • 12+ years exp • Master's Degree • Bengaluru
Apply
$197k – $246k per year • Equity • In office • Full-Time • Pleasanton
SQL
Databases
Databricks
AI/ML
AI Agents
Management
n8n
Zapier
Marketing
HubSpot
Marketo
Salesforce
Apply
$125k – $207k per year • Equity • Remote • Full-Time
Apply
$31k – $82k per year (Estimated) • In office • Full-Time • 3+ years exp • Hyderabad • Bengaluru
Apply
$31k – $73k per year (Estimated) • In office • Full-Time • 5+ years exp • Bengaluru
Apply
$16k – $34k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Mumbai • Bengaluru
JavaScript
PowerShell
SQL
C#
C#
.NET
Databases
Azure SQL Database
MS SQL
DevOps
Azure
Rest API
Cybersecurity
Microsoft Entra ID
QA
Postman
Swagger
Apply
$37k – $73k per year (Estimated) • In office • Internship • 4+ years exp • Bachelor's Degree • Bengaluru
Python
Scala
SQL
Databases
Apache Kafka
Databricks
AI/ML
ChatGPT
Copilot
Cursor
Spark
DevOps
AWS
Azure
CI/CD
GCP
Git
GitHub
Terraform
Apply
$41k – $89k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bengaluru
C#
TypeScript
JavaScript
C#
.NET
Databases
Apache Kafka
AI/ML
Copilot
LLM
OpenAI
Frontend
Angular
GraphQL
DevOps
Azure
Azure AKS
Azure DevOps
CI/CD
Docker
GitHub
GitHub Actions
Grafana
Kubernetes
Prometheus
Rest API
Apply
See all jobs
This is one of many
368,746 more open roles from verified company boards, updated every day.