Everpure
About this role
This is a detection engineering seat in Everpure's Global Information Security Office, and the posting is unusually clear that it is not a monitoring job. You build the detections, correlation rules and response logic that let the team catch real attacks rather than generate alert volume. The platform is Splunk, and the detections span identity, endpoint, network, cloud infrastructure, SaaS applications, data loss prevention, vulnerability and asset posture. You also write Python and use APIs to build enrichment and automation that makes responders faster. Everpure states the measure of success directly: signal quality, attack reduction and faster containment, not how many alerts fire. Apply if you have done incident response and want to move upstream into building the content that catches things, and if you are comfortable with MITRE ATT and CK, attacker tradecraft and tuning noisy alerts down.
Who this is for
Requirements as published:
- 6+ years of experience in cybersecurity or a related technical field.
- 3+ years of hands on experience in incident response and detection.
- Ability to design, implement and maintain high fidelity detections, correlation rules, alerts, dashboards and use cases in Splunk and related security platforms.
- Working knowledge of frameworks including MITRE ATT and CK and CVE/CVSS, plus attacker tradecraft and risk context.
- Python and API skills for building enrichment and automation workflows.
The actual day to day:
- Building detections across identity, endpoint, network, cloud infrastructure, SaaS, DLP, vulnerability and asset posture data.
- Correlating signals from different tools to spot attacker behaviour, misuse and anomalous activity.
- Sitting in incident triage, investigation and containment, then feeding the lessons back into detection content.
- Tuning noisy alerts down, cutting false positives and raising true positive rates.
- Working on logging strategy: event onboarding, normalisation, parsing, correlation, retention and reporting.
- Writing playbooks, runbooks and detection documentation for the responders who use them.
- Partnering with business units, IT and engineering to map how the business actually works to the telemetry needed to defend it.
What the posting says you will help build:
- High signal detections for credential misuse, privilege abuse, lateral movement, endpoint compromise, and cloud and SaaS attacks.
Location and office reality:
- Bangalore, onsite. The posting carries #LI-ONSITE and Everpure states it is primarily an in office environment.
Honest fit guidance:
- This is a detection engineering role, so a pure SOC analyst background of watching a queue will not be enough on its own. They want the person who writes the rules.
- Splunk is the named platform. Experience in another SIEM transfers, but say so directly rather than letting them assume.
- The posting explicitly rejects alert volume as a success measure, which is a good sign if you have been stuck in a noisy SOC.
- 6+ years of experience in cybersecurity or a related technical field.
- 3+ years of hands on experience in incident response and detection.
- Ability to design, implement and maintain high fidelity detections, correlation rules, alerts, dashboards and use cases in Splunk and related security platforms.
- Working knowledge of frameworks including MITRE ATT and CK and CVE/CVSS, plus attacker tradecraft and risk context.
- Python and API skills for building enrichment and automation workflows.
The actual day to day:
- Building detections across identity, endpoint, network, cloud infrastructure, SaaS, DLP, vulnerability and asset posture data.
- Correlating signals from different tools to spot attacker behaviour, misuse and anomalous activity.
- Sitting in incident triage, investigation and containment, then feeding the lessons back into detection content.
- Tuning noisy alerts down, cutting false positives and raising true positive rates.
- Working on logging strategy: event onboarding, normalisation, parsing, correlation, retention and reporting.
- Writing playbooks, runbooks and detection documentation for the responders who use them.
- Partnering with business units, IT and engineering to map how the business actually works to the telemetry needed to defend it.
What the posting says you will help build:
- High signal detections for credential misuse, privilege abuse, lateral movement, endpoint compromise, and cloud and SaaS attacks.
Location and office reality:
- Bangalore, onsite. The posting carries #LI-ONSITE and Everpure states it is primarily an in office environment.
Honest fit guidance:
- This is a detection engineering role, so a pure SOC analyst background of watching a queue will not be enough on its own. They want the person who writes the rules.
- Splunk is the named platform. Experience in another SIEM transfers, but say so directly rather than letting them assume.
- The posting explicitly rejects alert volume as a success measure, which is a good sign if you have been stuck in a noisy SOC.
Apply on company site
Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.