Verified today
MTS-2 Security Operations Engineer
About the role
eBay's Computer Security Incident Response Team (CSIRT) Operations team seeks an MTS-2 Security Operations Engineer to protect eBay's information assets by monitoring, investigating, and responding to cybersecurity events. Day-to-day work includes 24x7 security event monitoring, alert and phishing triage, initial incident investigation, containment actions, threat detection tuning, OSINT collection, and escalation to Detection & Response Engineers. The role is based in Bengaluru, India and follows a hybrid work model with a rotating 24x7 shift schedule including weekends and holidays.
What you’ll do
- Monitor global security events and alerts across enterprise security platforms in a 24x7 operational environment, identifying, classifying, and prioritizing security events for investigation.
- Perform initial investigation, triage, and analysis of security events, documenting findings, participating in investigation calls, and escalating incidents per established procedures.
- Execute approved containment actions to limit incident impact and assist with forensic preservation and investigation while maintaining chain of custody.
- Analyze security alerts, identify indicators of compromise (IOCs), and recommend improvements to detection content and alert tuning to reduce false positives.
- Collect, analyze, and disseminate relevant open-source intelligence (OSINT) to support investigations and improve situational awareness.
- Participate in testing, evaluation, implementation, and continuous improvement of security technologies, detection capabilities, and operational processes.
- Perform timely verbal and documented escalations to Detection & Response Engineers and on-call personnel when incidents require advanced investigation or exceed response thresholds.
- Participate in a rotating 24x7 shift schedule, including weekends and holidays, to support continuous global security operations.
What you’ll bring
- Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.
- Minimum of three (3) years of professional experience in Security Operations, Security Incident Response, Threat Detection, Digital Forensics, or a related cybersecurity discipline.
- Experience investigating security events and responding to cybersecurity incidents in an enterprise environment.
- Experience working with SIEM, EDR, or other enterprise security monitoring technologies.
- At least one of the following certifications: SANS GIAC (GCIA, GCIH, GCED, GCFA, GCFE, GMON, GNFA, GREM, or equivalent), ISC2 (CISSP, CCSP), CompTIA Security+, Cisco (CCNA, CCNP), EC-Council (CEH, ECI
- Minimum of three (3) years of specialised experience in one or more of: SOC or CSIRT, Security Incident Response and Investigation, Threat Detection and Monitoring, Digital Forensics and Evidence Pres
Skills
Education
Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.