This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Analyst based in India.
This role is an opportunity to strengthen security operations within a globally distributed, 24/7 environment protecting large-scale digital platforms and their users.
You will monitor, investigate, and respond to security events across cloud infrastructure, applications, endpoints, identities, and other critical systems.
The position combines hands-on incident response, detection engineering, threat intelligence, vulnerability management, and security automation.
You will work closely with security, engineering, infrastructure, product, privacy, legal, and compliance teams during complex investigations.
As you develop in the role, you will take greater ownership of incidents, operational improvements, and specialized areas such as cloud security or threat hunting.
You will also contribute to improving SIEM/SOAR capabilities, playbooks, automation, documentation, and overall monitoring coverage.
This is a strong opportunity for a security professional ready to take on more complex responsibilities while developing deeper expertise in modern cloud and security operations.
Accountabilities
- Monitor, analyze, and interpret security, system, application, cloud, and infrastructure logs to identify suspicious activity, configuration issues, and potential security incidents.
- Use SIEM platforms, security dashboards, threat intelligence, and proactive investigation techniques to identify anomalous or malicious activity.
- Monitor cloud infrastructure and services for security events, misconfigurations, indicators of compromise, and emerging risks.
- Track relevant security advisories, vulnerabilities, attack techniques, and changes in the threat landscape, escalating findings as appropriate.
- Investigate security alerts, incidents, and service requests through structured triage, analysis, documentation, escalation, and follow-up.
- Develop, maintain, tune, and improve detection use cases and alerts across SIEM and other security monitoring platforms.
- Design, implement, and maintain security automation workflows using SOAR or comparable orchestration technologies.
- Investigate and coordinate security incidents across technical and non-technical teams, taking ownership from initial triage through containment, remediation, recovery, and closure when required.
- Act as an Incident Commander or Incident Coordinator for appropriate security incidents, establishing ownership, priorities, dependencies, and follow-up actions.
- Maintain accurate incident timelines and provide clear, timely status updates to stakeholders and security leadership.
- Participate in major incident calls, supporting evidence collection, investigation, timeline development, incident summaries, and post-incident reviews.
- Collaborate with Product Security, Infrastructure Security, Application Security, GRC, Engineering, Privacy, Legal, and other relevant teams during investigations.
- Provide technical findings and evidence during security or privacy-related incidents and investigations.
- Create, maintain, and continuously improve SOPs, security playbooks, runbooks, detection use cases, and knowledge-base documentation.
- Support audit activities by gathering security evidence, validating controls, and coordinating with relevant stakeholders.
- Contribute to vulnerability assessment, prioritization, and remediation activities using appropriate security platforms.
- Support proof-of-concept initiatives, security tool evaluations, process improvements, and operational enhancement projects.
- Use scripting and automation to improve security investigations, monitoring, and operational efficiency.
- Take ownership of assigned responsibilities during each shift, ensuring timely escalation, effective handovers, and appropriate follow-through.
- Proactively identify and escalate risks, incidents, blockers, and operational concerns.
- Continuously develop security expertise and contribute to improvements in detection quality, response speed, monitoring coverage, automation, and team knowledge.
- Build a specialization aligned with team and business needs, such as cloud security monitoring, detection engineering, threat intelligence, or another relevant security discipline.
Requirements
- 3–5 years of hands-on experience in a 24/7 Security Operations Center, Cyber Fusion Center, or equivalent security operations environment.
- Experience in one or more areas such as SaaS security, cloud security, API or container security, threat intelligence, threat hunting, vulnerability management, SIEM, or SOAR operations.
- Strong practical experience using SIEM platforms for security monitoring, investigation, correlation, and detection engineering; Splunk experience is preferred.
- Hands-on experience with SOAR platforms and security automation workflows.
- Experience with Endpoint Detection and Response (EDR) technologies and related capabilities such as threat intelligence, exposure management, device control, or data protection.
- Experience with CSPM/CNAPP platforms such as Wiz, CrowdStrike Falcon Cloud Security, Prisma Cloud, Microsoft Defender for Cloud, Sysdig, or equivalent.
- Experience assessing, prioritizing, and managing vulnerabilities using tools such as CrowdStrike Exposure Management/Spotlight, Qualys, Rapid7, Wiz, or equivalent.
- Practical experience with AWS or GCP is mandatory, including knowledge of cloud identity, logging, networking, compute, storage, and security controls.
- Basic scripting ability in Python, Bash, PowerShell, or an equivalent language for security operations, investigation, or automation.
- Strong understanding of the cybersecurity incident lifecycle, from identification and triage through containment, remediation, recovery, and post-incident activities.
- Demonstrated ability to investigate and coordinate incidents across technical and non-technical teams.
- Previous experience acting as an Incident Coordinator, Incident Commander, or security incident lead is highly desirable.
- Good understanding of cybersecurity risk concepts, security frameworks, threat landscapes, vulnerabilities, and potential technical and business impacts.
- Strong ability to correlate information across logs, cloud platforms, endpoints, identity systems, applications, threat intelligence, and other security data sources.
- Understanding of authentication and credential-management concepts, including public/private key authentication, API keys, access tokens, service accounts, and secure credential handling.
- Comfortable working with command-line interfaces, APIs, IDE-based tools, and modern security and cloud engineering workflows.
- Working knowledge of AI and LLM tools such as ChatGPT, Gemini, Claude, or equivalent, including their practical and secure use within Security Operations.
- Strong analytical and problem-solving abilities, with the independence to investigate moderately complex events and the judgment to escalate higher-risk or unfamiliar situations.
- Excellent attention to detail and ability to connect findings across multiple technical data sources.
- Strong written and verbal English communication skills, with the ability to communicate technical findings, risks, incident status, and required actions to both technical and non-technical audiences.
- Comfortable communicating during active security incidents and major incident calls.
- Experience collaborating within globally distributed teams across functions, cultures, regions, and time zones.
- Strong team-oriented approach and ability to work effectively with security, engineering, infrastructure, product, GRC, privacy, legal, and business stakeholders.
- Willingness and ability to work a 24/7 monthly rotating shift schedule, including weekends, with a five-day working week.
- Ability to independently own shift responsibilities, manage active incidents when required, and provide effective handovers.
- Entry-level or intermediate cybersecurity certifications such as CompTIA Security+, CySA+, GIAC GSEC, cloud security certifications, or equivalent credentials are preferred.
- Experience in SaaS, e-commerce, cloud-native, or technology environments is an advantage.
Benefits
- Remote work opportunity from India, with access to a local office environment where applicable.
- Flexible working hours and a virtual-first approach.
- High degree of autonomy, trust, and ownership in day-to-day work.
- Opportunities for continuous learning and professional development.
- Annual professional education budget of $1,500 for eligible employees, supporting courses, certifications, books, and other learning resources.
- Personal development workshops and structured development programs.
- Access to coaching and leadership development resources.
- Employee Assistance Program with counseling support for eligible employees.
- Subscription to a sleep and meditation platform for eligible employees.
- Quarterly additional company-wide days off focused on disconnecting and wellbeing.
- Sports, yoga, and meditation opportunities.
- Extended parental leave of up to 26 calendar weeks for primary caregivers, subject to eligibility.
- Performance-based bonus opportunities.
- Restricted Stock Units or stock options, depending on role, seniority, and location.
- Employee referral bonus of up to $3,000.
- Paid volunteering opportunities, including up to five paid days for eligible employees.
- Recognition programs celebrating contributions and work anniversaries.
- Global collaboration opportunities across teams, regions, and time zones.
- Opportunities to work with modern cloud, security, automation, and AI technologies while developing specialized cybersecurity expertise.
- Additional benefits may vary according to employment type, location, and applicable policies.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1