RAJ
Verified from Jobgether's careers page · Lever

Security Analyst

JobgetherIndia (On-Site) 🇮🇳5 YearsPosted Sep 8, 2026
Apply now

Apply faster

Fill most application fields automatically from your RealAnalystJobs profile. You review, you submit.

Included with the from $2 for 30 days unlock

About this role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Security Analyst based in India. This role is an opportunity to strengthen security operations within a globally distributed, 24/7 environment protecting large-scale digital platforms and their users. You will monitor, investigate, and respond to security events across cloud infrastructure, applications, endpoints, identities, and other critical systems. The position combines hands-on incident response, detection engineering, threat intelligence, vulnerability management, and security automation. You will work closely with security, engineering, infrastructure, product, privacy, legal, and compliance teams during complex investigations. As you develop in the role, you will take greater ownership of incidents, operational improvements, and specialized areas such as cloud security or threat hunting. You will also contribute to improving SIEM/SOAR capabilities, playbooks, automation, documentation, and overall monitoring coverage. This is a strong opportunity for a security professional ready to take on more complex responsibilities while developing deeper expertise in modern cloud and security operations. Accountabilities • Monitor, analyze, and interpret security, system, application, cloud, and infrastructure logs to identify suspicious activity, configuration issues, and potential security incidents. • Use SIEM platforms, security dashboards, threat intelligence, and proactive investigation techniques to identify anomalous or malicious activity. • Monitor cloud infrastructure and services for security events, misconfigurations, indicators of compromise, and emerging risks. • Track relevant security advisories, vulnerabilities, attack techniques, and changes in the threat landscape, escalating findings as appropriate. • Investigate security alerts, incidents, and service requests through structured triage, analysis, documentation, escalation, and follow-up. • Develop, maintain, tune, and improve detection use cases and alerts across SIEM and other security monitoring platforms. • Design, implement, and maintain security automation workflows using SOAR or comparable orchestration technologies. • Investigate and coordinate security incidents across technical and non-technical teams, taking ownership from initial triage through containment, remediation, recovery, and closure when required. • Act as an Incident Commander or Incident Coordinator for appropriate security incidents, establishing ownership, priorities, dependencies, and follow-up actions. • Maintain accurate incident timelines and provide clear, timely status updates to stakeholders and security leadership. • Participate in major incident calls, supporting evidence collection, investigation, timeline development, incident summaries, and post-incident reviews. • Collaborate with Product Security, Infrastructure Security, Application Security, GRC, Engineering, Privacy, Legal, and other relevant teams during investigations. • Provide technical findings and evidence during security or privacy-related incidents and investigations. • Create, maintain, and continuously improve SOPs, security playbooks, runbooks, detection use cases, and knowledge-base documentation. • Support audit activities by gathering security evidence, validating controls, and coordinating with relevant stakeholders. • Contribute to vulnerability assessment, prioritization, and remediation activities using appropriate security platforms. • Support proof-of-concept initiatives, security tool evaluations, process improvements, and operational enhancement projects. • Use scripting and automation to improve security investigations, monitoring, and operational efficiency. • Take ownership of assigned responsibilities during each shift, ensuring timely escalation, effective handovers, and appropriate follow-through. • Proactively identify and escalate risks, incidents, blockers, and operational concerns. • Continuously develop security expertise and contribute to improvements in detection quality, response speed, monitoring coverage, automation, and team knowledge. • Build a specialization aligned with team and business needs, such as cloud security monitoring, detection engineering, threat intelligence, or another relevant security discipline. Requirements • 3–5 years of hands-on experience in a 24/7 Security Operations Center, Cyber Fusion Center, or equivalent security operations environment. • Experience in one or more areas such as SaaS security, cloud security, API or container security, threat intelligence, threat hunting, vulnerability management, SIEM, or SOAR operations. • Strong practical experience using SIEM platforms for security monitoring, investigation, correlation, and detection engineering; Splunk experience is preferred . • Hands-on experience with SOAR platforms and security automation workflows. • Experience with Endpoint Detection and Response (EDR) technologies and related capabilities such as threat intelligence, exposure management, device control, or data protection. • Experience with CSPM/CNAPP platforms such as Wiz, CrowdStrike Falcon Cloud Security, Prisma Cloud, Microsoft Defender for Cloud, Sysdig, or equivalent. • Experience assessing, prioritizing, and managing vulnerabilities using tools such as CrowdStrike Exposure Management/Spotlight, Qualys, Rapid7, Wiz, or equivalent. • Practical experience with AWS or GCP is mandatory , including knowledge of cloud identity, logging, networking, compute, storage, and security controls. • Basic scripting ability in Python, Bash, PowerShell, or an equivalent language for security operations, investigation, or automation. • Strong understanding of the cybersecurity incident lifecycle, from identification and triage through containment, remediation, recovery, and post-incident activities. • Demonstrated ability to investigate and coordin

Description from Jobgether's public careers feed, reproduced so you can read the role here. Apply on the company's own site; RealAnalystJobs never submits anything for you.

Raj