The IR Manager will work closely with the SOC team and report directly to the Head of Cybersecurity Operations. This role is responsible for managing the lifecycle of security incidents, ensuring investigation, response, and recovery, while driving continuous improvements in incident response processes and playbooks.
Role & responsibilities
Incident Response and Threat Intelligence:
- Lead end-to-end incident response activities: detection, triage, containment, eradication, and recovery.
- Work closely with SOC analysts in a 24x7 workplace to validate alerts and escalate high-risk threats.
- Perform hands-on investigations using SIEM, EDR, and forensic tools across endpoints, networks, and cloud environments.
- Conduct malware analysis, log correlation, and threat hunting to identify advanced or persistent threats.
- Integrate threat intelligence (IOCs, TTPs, MITRE ATT&CK; mapping) into proactive detection and response improvements.
Training and Awareness:
- Mentor SOC analysts and junior incident responders on investigation techniques and response best practices.
- Conduct incident response simulations, tabletop exercises, and post-incident knowledge-sharing sessions.
- Drive continuous skill development across security operations teams.
- Promote a strong incident response culture with accountability and learning focus.
Collaboration with Other Security Teams:
- Partner with SOC, Vulnerability Assessment, Network, Cloud, Application, and Infrastructure teams during incidents.
- Coordinate endpoint-level remediation with IT and infrastructure teams to ensure timely closure.
- Act as a central bridge between security operations and business units during crisis situations.
- Foster cross-team collaboration while enforcing response and remediation accountability.
NonNegotiable & Role-Critical Requirements:
- 8-12 years of cybersecurity experience, with 5+ years in hands-on incident response and SOC operations.
- Proven leadership during high-severity, business-impacting security incidents.
- Strong, practical expertise in SIEM, EDR, malware analysis, and threat hunting.
- Deep understanding of network security, TCP/IP, cloud security, and modern attack techniques.
- Certifications such as GCIH, GCFA, or equivalent are mandatory.
ONLY Prospects with solid experience in malware analysis, log analysis, threat hunting, and incident investigations, please share your resume at
[email protected]
📌 Incident Response Analyst (Ahmedabad)
🏢 Adani Group
📍 Ahmedabad