About this role
Zscaler runs one of the largest security data lakes in the industry, and this role sits in its threat hunting department building the detections that run against it. The work combines threat research with real engineering: writing detections and hunting logic in Python against AWS infrastructure, building GitLab pipelines and repeatable deployment steps, developing YAML based detections and SIGMA style rules, and migrating existing hunting detections onto next generation systems. You would also use Hadoop, Athena and data lakes to monitor and test new intelligence sources. It is a good fit for a detection engineer who wants scale, or for a data engineer with security interest, since a lot of the day is pipeline and platform work. No years figure is published anywhere in the listing.
Who this is for
The posting publishes no years of experience figure anywhere in its qualifications, so our experience field is empty and this role will not appear under any experience filter here. The minimum qualifications open with a foundational understanding of AI and machine learning technologies and experience leveraging, securing or positioning AI driven solutions within your domain, which Zscaler now includes across postings, followed by significant experience as a senior detection engineer leading complex detection strategies and mentoring junior team members, and expertise validating detection logic and performing root cause analysis of failures.
Day to day: combine threat research and engineering expertise to develop advanced detections and hunting logic using Python and AWS infrastructure; design, scale and maintain engineering projects including GitLab pipelines and repeatable deployment steps to improve hunting efficiency; develop YAML based detections and SIGMA like rule technologies while migrating existing hunting detections to next generation systems; use data platforms including Hadoop, Athena and data lakes to monitor and test new intelligence sources for enhanced threat visibility; and independently write detections and playbooks while supporting operational demands.
Location and office reality: the posting states this is a hybrid role in Pune, reporting to a Senior Manager in the threat hunting department. The number of office days is not specified. Pune is worth noting given how Bangalore heavy this board usually is.
One judgment call we are disclosing: the qualifications mention mentoring junior team members. There is no reporting line, hiring or performance review language anywhere in the posting, so we read that as senior technical mentorship and published this as an individual contributor role. If that distinction matters to you, confirm it early.
No interview process is published.
Day to day: combine threat research and engineering expertise to develop advanced detections and hunting logic using Python and AWS infrastructure; design, scale and maintain engineering projects including GitLab pipelines and repeatable deployment steps to improve hunting efficiency; develop YAML based detections and SIGMA like rule technologies while migrating existing hunting detections to next generation systems; use data platforms including Hadoop, Athena and data lakes to monitor and test new intelligence sources for enhanced threat visibility; and independently write detections and playbooks while supporting operational demands.
Location and office reality: the posting states this is a hybrid role in Pune, reporting to a Senior Manager in the threat hunting department. The number of office days is not specified. Pune is worth noting given how Bangalore heavy this board usually is.
One judgment call we are disclosing: the qualifications mention mentoring junior team members. There is no reporting line, hiring or performance review language anywhere in the posting, so we read that as senior technical mentorship and published this as an individual contributor role. If that distinction matters to you, confirm it early.
No interview process is published.
Apply on company site
Opens job-boards.greenhouse.io, the employer's own application page. Applying is always free.