Overview
Serve as an Associate, Information Security Analyst within the Security and IT Operations team, monitoring and analyzing security incidents, vulnerabilities and events; enhancing security tools and automation; and helping protect clients, systems and data from internal and external threats.
What you'll do
- Monitor, analyze and report on security detections from logging and monitoring systems, using threat intelligence to discover, triage, prioritize and document potential incidents.
- Monitor and triage client and internal requests, document incident response activities, and support analysis, containment and resolution planning.
- Maintain and improve existing security tools and contribute to new tools and automation for incident detection and response.
- Serve as a primary administrator for Black Kite, Proofpoint, NINJIO and Rapid7 InsightVM, and respond to alerts from those platforms as well as Microsoft Defender, CrowdStrike and Zscaler.
- Collaborate with internal stakeholders and third parties to assess, respond to and resolve vendor and supply-chain security incidents.
- Partner with the broader IT organization to prioritize and remediate security vulnerabilities.
- Support internal and external audits by gathering evidence, responding to requests and helping address identified gaps.
- Compile and update monthly security metrics, reports and dashboards using data from multiple security platforms.
- Help execute strategies that increase security awareness and knowledge throughout the organization.
- Work with management and business leaders to advance Information Risk Management's strategy and priorities.
- Engage stakeholders throughout the company to understand business needs and provide practical security guidance and subject-matter expertise.
- Represent Information Security in planning, requirements-gathering, project-management and rollout meetings across the business and IT.
- Support a 24x7 operational environment through scheduled rotation and on-call coverage for US nights and weekends, US and India holidays, incidents, critical production events and business-continuity needs.
- Perform other projects and responsibilities as assigned.
What you'll need
- Proficiency in the secure and responsible use of generative AI tools such as ChatGPT, Claude, Microsoft Copilot and Gemini.
- Knowledge of AI security risks and controls, with experience assessing, monitoring and supporting the secure adoption and use of AI technologies in accordance with organizational policies and industry best practices.
- Strong working knowledge of Windows Server, Microsoft Azure, endpoint detection and response (EDR), managed detection and response (MDR), and data loss prevention (DLP).
- Experience assessing, implementing, optimizing and documenting a broad set of security technologies and processes, including data protection, identity and access management (IAM), network security, and IaaS, PaaS and other computing environments.
- Experience with cloud security and governance tools, server virtualization technologies and vendor security reviews.
- Current knowledge of incident response, secure system configuration, vulnerability management and hardening guidance, including the Center for Internet Security (CIS) Controls and Benchmarks.
- Working knowledge of applicable frameworks and regulatory requirements, including PCI DSS, HIPAA, GLBA, GDPR, NIST and ISO standards.
- Excellent written and verbal business-English communication skills, with the ability to collaborate effectively with technical and non-technical stakeholders across cultures and time zones.
- A self-directed, hands-on approach, with the ability to work independently and productively with remote team members and limited direct supervision.
- Strong analytical and problem-solving skills, including the ability to define problems, collect and evaluate data, establish facts and draw sound conclusions while considering multiple variables.
- High attention to detail, with the ability to manage competing priorities, meet multiple deadlines and remain effective during operational pressure.
- Ability to write clear reports, business correspondence and procedural manuals, and to create meaningful security metrics and dashboards.
- Bachelor's degree in information technology, cybersecurity, computer science or a related field.
- At least three years of hands-on cybersecurity practitioner experience.
- At least two years of experience with Amazon Web Services (AWS), Microsoft Azure, Google Cloud or IBM Cloud, and VMware.
- Hands-on experience using and maintaining enterprise-grade security tools, including Microsoft Defender; CrowdStrike Falcon Complete/MDR, Identity Threat Protection, Shield, Recon+, Cloud Security and Next-Gen SIEM; Wiz; Zscaler ZIA, ZPA, ZDX and ZTA; Proofpoint TAP and DLP; NINJIO; Black Kite; and Rapid7 InsightVM.
- Demonstrated ability to extract, validate and communicate reports and operational metrics from these platforms.
- Required certifications: CompTIA Security+; Proofpoint Certified Threat Protection Analyst; Proofpoint Certified Information Protection Analyst; CompTIA Cybersecurity Analyst (CySA+); and CompTIA SecAI+ (Security AI+).
Nice to have
- Five or more years of hands-on cybersecurity practitioner experience.
- Certified Cloud Security Professional (CCSP).
- ITIL Foundation.
Details
- Based in Bengaluru, India and hired through Revantage India.
- Full-time, exempt role.
- One position will align primarily to US Central Time; the other will maintain meaningful daily overlap with US Central Time.
- Both positions participate in rotating on-call coverage for US nights and weekends and provide coverage on US and India holidays to support uninterrupted operations.
- Support a 24x7 operational environment through scheduled rotation and on-call coverage for incidents, critical production events and business-continuity needs.
Read the full description and apply on the company’s own careers page.