ICC - Security Operations Analyst - Cyber Defense
SIEMEDRMicrosoft Security technologiesAzureAWSGoogle CloudMicrosoft SentinelSplunkPythonPowerShell
About the Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an ICC - Security Operations Analyst - Cyber Defense based in India. This is a hands-on cybersecurity role within a global 24/7 Security Operations Centre, focused on detecting, investigating, and responding to cyber threats. You will monitor security events across cloud, endpoint, network, and enterprise environments using modern SIEM, EDR, and security platforms. The role involves deep log analysis, alert triage, incident investigation, escalation, and coordination with specialized response teams. You will work with security professionals across multiple regions and technical disciplines in a globally distributed environment. Your expertise will contribute directly to improving detection quality, reducing false positives, and strengthening security monitoring capabilities. The position also provides exposure to diverse technologies, real-world threats, and incident response scenarios. This is a full-time, remote contract for six months , with potential for extension, and requires fluent English and availability aligned with the IST timezone. This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an ICC - Security Operations Analyst - Cyber Defense based in India. This is a hands-on cybersecurity role within a global 24/7 Security Operations Centre, focused on detecting, investigating, and responding to cyber threats. You will monitor security events across cloud, endpoint, network, and enterprise environments using modern SIEM, EDR, and security platforms. The role involves deep log analysis, alert triage, incident investigation, escalation, and coordination with specialized response teams. You will work with security professionals across multiple regions and technical disciplines in a globally distributed environment. Your expertise will contribute directly to improving detection quality, reducing false positives, and strengthening security monitoring capabilities. The position also provides exposure to diverse technologies, real-world threats, and incident response scenarios. This is a full-time, remote contract for six months , with potential for extension, and requires fluent English and availability aligned with the IST timezone. Accountabilities Monitor, triage, and investigate security alerts across SIEM, EDR, Microsoft security technologies, and cloud platforms. Analyze logs and security events from Windows and Linux systems, databases, applications, web servers, firewalls, and network intrusion detection systems. Investigate suspicious activity, determine potential root causes, and assess the severity and impact of security incidents. Support incident response, remediation, recovery, and containment activities in coordination with relevant cybersecurity teams. Determine appropriate escalation paths and collaborate with Incident Response specialists when threats require deeper investigation. Identify opportunities to improve detection quality, optimize security monitoring, reduce false positives, and tune whitelists. Prepare technical reports, investigation summaries, and security findings for relevant stakeholders. Maintain SOC procedures, technical documentation, playbooks, and knowledge-base content. Contribute to operational improvements, process optimization, and cybersecurity quality initiatives. Requirements 5+ years of relevant IT and/or cybersecurity experience, with hands-on experience in security operations. Proven experience with security alert triage, threat investigation, and incident response processes. Practical experience working with SIEM and EDR platforms in enterprise environments. Strong log analysis capabilities across Windows/Linux systems and broader enterprise infrastructure. Deep knowledge of Microsoft Security technologies. Experience with at least one major cloud environment, such as Azure, AWS, or GCP. Experience with SIEM platforms such as Microsoft Sentinel, Splunk, QRadar, ArcSight, or ELK. Experience with EDR solutions such as Microsoft Defender for Endpoint or CrowdStrike. Knowledge of email security, network monitoring, threat detection, and incident response. Strong knowledge of Linux, macOS, and Windows operating systems. Fluent English with strong written and verbal communication skills. Ability to work effectively within global, distributed cybersecurity teams and coordinate investigations across different functions. Nice to Have Tier 1 or Tier 2 incident response experience. Experience with AWS security monitoring across IaaS, PaaS, or SaaS environments. Scripting experience with Python, PowerShell, Bash, Ruby, or similar languages. Relevant certifications such as SC-200, GCIH, CEH, GCFA, GIAC, CCNA, or MCSE. Previous experience working in a global SOC or distributed cybersecurity operation. Benefits Full-time remote work from India. Six-month contract with potential for extension. Opportunity to work within a global 24/7 Security Operations Centre. Exposure to a broad cybersecurity technology stack spanning SIEM, EDR, cloud, network, endpoint, and enterprise security. Collaboration with cybersecurity specialists across multiple regions and technical disciplines. Hands-on experience with real-world threat detection, investigation, incident response, and remediation. Opportunity to contribute to security monitoring optimization and operational improvement initiatives. Globally distributed and remote-first working environment. Inclusive and transparent recruitment environment. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
You'll be redirected to Jobgether's application page
Job Details
Salary
Not disclosed
Location
India
Job type
Full-time
Category
Security Engineering
Experience
5+ years
Posted
Today
Job Highlights
- 5+ years level role
- 100% Remote — open to candidates in India
- Full-time position
About Jobgether
This job is hosted by Jobgether. Clicking Apply opens their site.
Remote Work Style
Mixed
Mix of flexible and scheduled meetings
Your Match
See how well your skills line up with this role, and what you're missing.
AI Cover Letter
Generate a cover letter tailored to this job from your profile.