Senior Detection Engineer - Cloud

Vectra
Vectra

Bengaluru, Karnataka, India

Posted on Aug 4, 2026

Vectra® is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises.

The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond to the most advanced cyber-attacks. With 35 patents in AI-driven threat detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai.

Position Overview

We are seeking an experienced Threat Detection Engineer to extend Vectra's detection capabilities across cloud and identity environments, with additional exposure to network-based threat detection.

Vectra's Attack Signal Production Group is responsible for building Vectra's core threat detection and prioritization technology, leveraging AI and other methods to alert customers to critical threats across their cloud, identity, and network environments.

Threat Detection Engineers work closely with Data Scientists who are developing AI models, and Security Researchers who are researching the threat landscape and assisting modeling efforts. This role will focus primarily on developing detections for cloud and identity attack behaviours, including threats across AWS, Azure, GCP, and identity platforms such as Microsoft Entra ID.

The ideal candidate has hands-on experience investigating cloud and identity threats using telemetry such as authentication and audit logs, CloudTrail, cloud platform logs, and network flow data. Familiarity with network threat models, protocols, and network-based telemetry is important, particularly as cloud detection increasingly incorporates data sources such as VPC and flow logs.

The role is primarily focused on cloud and identity threat detection, while providing the versatility to contribute to network detection initiatives where relevant.

Responsibilities and Accountabilities

  • Research cloud and identity attack behaviours and identify opportunities for new detections.
  • Develop, test, and maintain detection logic using Python and other appropriate detection technologies.
  • Analyze telemetry from cloud and identity environments, including authentication activity, control-plane activity, audit logs, application logs, and network flow logs.
  • Develop detections across common cloud platforms such as AWS, Azure as well as identity environments such as Microsoft Entra ID.
  • Investigate malicious activity and reproduce attacker techniques to validate detection hypotheses.
  • Collaborate with Data Scientists and Security Researchers to improve detection coverage and accuracy.
  • Continuously assess detection effectiveness and improve detections based on real-world data.
  • Stay current with emerging cloud, identity, and network attacker techniques and TTPs.
  • Work with large and diverse security datasets using technologies and techniques such as Python, notebooks, SQL, Pandas, and cloud analytics platforms.
  • Contribute to network threat detection where appropriate, including analysis of network protocols, flow data, PCAPs, and network attack behaviours.

Attitudes and Behaviours

  • Focus on impact and results; work on the right problems and drive them through to completion.
  • Demonstrate curiosity and a strong investigative mindset when working with unfamiliar attacker behaviours, telemetry, or technologies.
  • Show drive and resourcefulness in overcoming technical ambiguity and incomplete information.
  • Have a track record of successfully solving complex and ambiguous problems.
  • Balance detection coverage with detection quality, scalability, and maintainability.
  • Demonstrate high integrity and an ability to collaborate effectively across Security Research, Data Science, Engineering, and Product teams.

Qualifications and Experience

  • 6+ years of cybersecurity experience, preferably focused on threat detection, security research, threat hunting, incident response, or detection engineering.
  • Strong experience investigating threats in cloud and identity environments.
  • Hands-on knowledge of AWS/Azure cloud platform.
  • Strong understanding of identity concepts, cloud and identity attack techniques; experience with Microsoft Entra ID is preferred.
  • Experience working with security telemetry such as CloudTrail, cloud audit logs, authentication logs, flow logs, PCAPS and network telemetry.
  • Working proficiency in Python, including experience using Python for data analysis, automation, investigation, or detection development.
  • Working knowledge of network security fundamentals, protocols, and network threat models.
  • Familiarity with large-scale analytics or data platforms such as Databricks, cloud-native log analytics platforms, or equivalent technologies.
  • Excellent technical, analytical, communication, and collaboration skills.

Preferred Experience

  • Experience building and operating production-quality cloud or identity detections, rather than solely investigating alerts generated by existing products.
  • Experience developing detections using multiple telemetry sources or correlating activity across identity, cloud control-plane, workload, and network data.
  • Experience with adversary simulation or offensive security techniques in AWS, Azure or identity environments.
  • Experience analyzing network traffic using tools such as Wireshark, Zeek, Suricata, or similar technologies.
  • Optional certifications such as OSCP, GCIA, GCDA, GSEC, cloud security certifications, or equivalent practical experience.

Vectra provides a comprehensive total rewards package that supports the financial, physical, mental and overall health of our employees and their families. Compensation includes competitive base pay, incentive plan eligibility, and participation in the employee equity plan (stock options). Specific benefits offered varies by location, but commonly include health care insurance, income protection / life insurance, access to retirement savings plans, behavioral & emotional wellness services, generous time away from work, and a comprehensive employee recognition program.

Vectra is committed to creating a diverse environment and is proud to be an equal opportunity employer.

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.