Role Description
Job Description Incident Response Analyst Experience 5–9 years in Security Operations, Incident Response, Threat Hunting, or Cyber Defense Shift 24×7 Rotational (including weekends and public holidays) Role Overview We are seeking an experienced Incident Response Analyst with solid hands-on knowledge of SIEM investigations, EDR triage, advanced email security analysis, incident response, threat hunting, and security log analysis. The candidate will be responsible for investigating security incidents, coordinating with internal security teams, supporting remediation activities, and communicating findings to clients and stakeholders. Key Responsibilities
Monitor, triage, and investigate security s and incidents.
Perform detailed incident analysis across endpoints, identity, email, cloud, and network environments.
Correlate security events across multiple tools and data sources.
Determine incident scope, severity, impact, and root cause.
Support containment, remediation, recovery, and incident closure activities.
Conduct proactive threat hunting and identify suspicious activity.
Coordinate with SecOps, IAM, Cloud, Network, Infrastructure, and other technical teams.
Maintain accurate investigation notes, incident timelines, and reports.
Recommend improvements to security detections, response playbooks, and operational processes.
Communicate investigation findings and recommendations to clients and stakeholders.
Ensure proper handover of open incidents across shifts. Mandatory Skills SIEM Platform
Splunk
Microsoft Sentinel
Cortex XSIAM is most prioritized The candidate should have experience in:
Writing and modifying SPL / KQL / XQL queries
Investigating s and incidents
Correlating events across multiple log sources
Analyzing endpoint, identity, cloud, network, and authentication logs
Identifying true positives, false positives, and suspicious activity EDR Platform Strong hands-on experience with:
Microsoft Defender for Endpoint
CrowdStrike Falcon
Cor
📌 SOC Analyst (Bengaluru)
🏢 UST
📍 Bengaluru