The Principal Cyber Defense Analyst oversees the investigation and analysis of potential security threats,
evaluates risk, and provides guidance to remediate and implement appropriate security controls. This role is responsible for the initial response and triage of security incidents, advanced monitoring of security events from event management (SIEM) solutions, leading technical investigations, and assisting in the implementation of recommendations to improve Allscripts security posture.
The Principal Cyber Defense
Analyst is a subject matter expert in all SOC tolls and assists in the configuration and implementation of the security roadmap.
:
- Oversees the monitoring and analysis of network, endpoint, and database telemetry from tools which
- include, but are not limited to: Endpoint Detection and Response (EDR), IDS/IPS, Firewalls, Active
- Directory, Windows Event Logs, Vulnerability Management tools
- Collaborates with the SOC manager to escalate security issues to other business units including solutions
- development, customer hosting and Corporate IT
- Independently works with security log tools and event management (SIEM) solutions to create correlation
- rules to aid in improved detection
- Maintains heightened awareness of current security vulnerabilities, attacks, and mitigation techniques, with
- regular and proactive communication to management on findings pertinent to Allscripts setting
- Independently identifies security vulnerabilities with high fidelity
- Provides consultation to development and operational teams in the appropriate application of security best
- practices and the use of advanced security technologies
- Provides consultation to operational teams in the tuning of security solutions and ensure their integrity
- Independently performs detailed security reviews to ensure design components are being securely
- implemented
- Participates in the definition and documentation of security standards and best practices
- Independently reviews and triages security tickets of junior engineers and events from multiple solutions
- 7+ years of experience required.
Required skills
- Microsoft Defender for Endpoint, Crowdstrike Falcon and exposure management
- Intune policy deployment / device compliance & encryption (BitLocker, FileVault)
- Phishing and malware analysis (sandbox tools)
- Vulnerability scanning tools (Tenable, Qualys, other)
- Microsoft Sentinel, Splunk or other SIEM experience
- Network controls, segmentation, VPN awareness
- Identity lifecycle (onboarding/offboarding, terminations, transfers)
- Microsoft Identity Manager (MIM), Azure AD / Entra ID
- SSO (SAML, OAuth, OIDC, WS-Fed) configuration
- Powershell scripting (Entra ID, Defender)
- Automox or Intune patching
Working Arrangements: US Hours & Hybrid [3 days WFO]
📌 Principal IT Cyber Defense Analyst (Pune)
🏢 Veradigm
📍 Pune