27 Aug
|
RP STRATIVA GLOBALS
|
India
27 Aug
RP STRATIVA GLOBALS
India
Cyber Security Analyst / SOC Analyst / Information Security Analyst
LOCATION: REMOTE,
EXPERIENCE: 0 TO 5 YEARS
We are looking for motivated and technically strong Cyber Security / SOC / Information Security professionals to join our security team. The role provides opportunities to work across Security Operations, SIEM, EDR/XDR, Threat Detection, Incident Response, Cloud Security, IAM, Vulnerability Management, Application Security, and GRC .
Depending on the candidate’s experience, technical expertise, and project requirements, the position may involve responsibilities ranging from SOC L1/L2/L3 operations to security engineering, threat hunting, detection engineering, security architecture, and governance .
Key Responsibilities1. Security Operations & Incident Response
- Monitor and analyze security alerts using SIEM, EDR, and XDR platforms .
- Perform alert triage, event correlation, investigation, and escalation.
- Investigate suspicious activities and security incidents.
- Support incident containment, remediation, and recovery activities.
- Perform root-cause analysis and prepare incident reports.
- Support digital forensics and incident response activities as required.
1. SIEM, EDR & XDR
- Monitor enterprise security events and endpoint telemetry.
- Investigate suspicious processes, network connections, authentication events, and other security indicators.
- Develop, tune, and optimize security detection rules and use cases.
- Identify and reduce false positives while improving detection coverage.
- Work with enterprise security platforms and security monitoring technologies.
1. Threat Hunting & Detection Engineering
- Conduct proactive threat hunting across security logs and telemetry.
- Develop detection logic using the MITRE ATT&CK; framework .
- Create queries and correlation rules for SIEM, EDR, and XDR platforms.
- Research emerging threats, attack techniques, and indicators of compromise.
- Improve organizational detection and response capabilities.
1. Network & Infrastructure Security
- Monitor and analyze network security events and suspicious traffic.
- Support security technologies including Firewalls, WAF, IDS/IPS, VPN, and network monitoring solutions .
- Assist with network segmentation, access control, and Zero Trust security initiatives.
- Investigate network-based security incidents.
1. Identity & Access Security
- Support IAM, IDAM, PAM, SSO, MFA, and RBAC environments.
- Monitor privileged account activity and potential identity misuse.
- Assist with access reviews and identity governance processes.
- Investigate authentication and authorization-related security events.
1. Cloud Security
- Support security monitoring across AWS, Microsoft Azure, and/or Google Cloud environments.
- Review cloud IAM roles, security groups, storage permissions,
and security configurations.
- Monitor cloud-native security services and alerts.
- Support container and Kubernetes security where applicable.
- Assist with CSPM, CWPP, and CIEM initiatives.
1. Vulnerability & Risk Management
- Perform vulnerability assessments and security scans.
- Analyze vulnerability findings and prioritize remediation.
- Track remediation and patch-management activities.
- Support security risk assessments and infrastructure security reviews.
- Work with technical teams to address identified security weaknesses.
1. Application & DevSecOps Security
- Support SAST, DAST, API security, and application vulnerability assessments .
- Review application security findings and recommend remediation.
- Assist in integrating security controls into CI/CD pipelines.
- Promote secure development and DevSecOps practices.
- Support API and web application security testing.
1. Data & Database Security
- Support DLP, DAM, encryption, data classification, and data protection initiatives.
- Monitor database activity and privileged access events.
- Investigate potential data-access violations and security incidents.
- Assist with implementation of data security controls.
1. Governance, Risk & Compliance
- Support information-security governance and compliance initiatives.
- Assist with frameworks and standards such as ISO 27001, SOC 2, GDPR, and PCI-DSS .
- Maintain security documentation, policies, procedures, and risk registers.
- Support internal and external security audits.
- Assist in control assessments and compliance reviews.
Core Security Domains Candidates may be assigned to one or more of the following areas based on their skills and project requirements:
- SOC Operations – L1 / L2 / L3
- SIEM Operations & Engineering
- EDR / XDR Operations
- Security Monitoring & Incident Response
- Threat Intelligence
- Threat Hunting
- Detection Engineering
- Digital Forensics & Incident Response (DFIR)
- Network Security
- Cloud Security
- IAM / IDAM / PAM
- Data Security & DLP
- Application & API Security
- DevSecOps
- Vulnerability Management
- Zero Trust Security
- Security Automation & SOAR
- GRC & Compliance
- Security Architecture
Required Skills For Freshers / Entry-Level Candidates
- Robust understanding of basic cybersecurity concepts.
- Understanding of TCP/IP, DNS, HTTP/HTTPS, and networking fundamentals .
- Basic knowledge of Windows and Linux operating systems.
- Understanding of authentication and authorization concepts.
- Familiarity with security logs and event analysis.
- Basic understanding of SIEM and security monitoring concepts.
- Awareness of common cyber threats, attack techniques, and vulnerabilities.
- Basic knowledge of the MITRE ATT&CK; framework .
- Strong analytical and problem-solving skills.
- Willingness to work in a 24/7 SOC environment , where applicable.
For Experienced Candidates Candidates with relevant experience may additionally be expected to have knowledge of:
- SIEM engineering and correlation-rule development.
- Detection engineering and threat hunting.
- Incident response and investigation.
- EDR/XDR administration and investigation.
- Security automation and SOAR.
- Cloud security monitoring and configuration reviews.
- Vulnerability management and remediation.
- IAM/PAM technologies.
- Security architecture and enterprise security controls.
- GRC, risk management, and compliance frameworks.
Preferred Skills
- Hands-on experience with SIEM, EDR, or XDR platforms.
- Previous experience in a SOC, MSSP, enterprise security, or cybersecurity environment .
- Exposure to cloud security technologies.
- Experience with threat hunting or detection engineering.
- Familiarity with SOAR and security automation.
- Knowledge of security frameworks such as MITRE ATT&CK;, NIST, and ISO 27001 .
- Experience working with enterprise-scale security environments.
Certifications – Preferred, Not Mandatory
- CompTIA Security+
- CEH
- CySA+
- CISSP
- CISM
- ISO 27001 Lead Auditor / Lead Implementer
- AWS / Azure / Google Cloud Security Certifications
- Other relevant cybersecurity certifications
Professional Competencies
- Strong analytical and investigative mindset.
- Excellent problem-solving and logical reasoning skills.
- Ability to analyze security events and identify potential threats.
- Strong written and verbal communication skills.
- Ability to document incidents, investigations, and technical findings clearly.
- Ability to work independently as well as collaboratively with security and IT teams.
- Strong attention to detail.
- Ability to adapt to rapidly changing cybersecurity threats and technologies.
- Willingness to continuously learn and develop technical skills.
Experience Level 0–5+ years of relevant experience The position is open to freshers, entry-level cybersecurity professionals, SOC analysts, and experienced information-security professionals , with responsibilities aligned to the candidate’s technical capabilities and experience level.
Work Environment The role may involve working in a 24/7 Security Operations Center (SOC) environment, including rotational shifts, depending on project and customer requirements.
📌 Cyber Security Analyst (India)
🏢 RP STRATIVA GLOBALS
📍 India