Incident Response Analyst – Cybersecurity
Incident Response Analyst – Cybersecurity
22
Mumbai, Maharashtra, India
Job Views:
Created Date: 2026-08-13
End Date:
Salary: 65000
Industry: Edtech
Openings: 1
Primary Responsibilities :
• Perform triage, validation, severity classification (P1–P3), investigation, containment, and escalation of cybersecurity incidents
• Investigate alerts/incidents originating from SIEM/SOAR, CrowdStrike EDR/XDR, Akamai WAF, Bugcrowd, Threat Intelligence platforms, application monitoring tools, and user-reported events.
• Analyse security events, logs, IOCs, endpoint telemetry, network activity, and other evidence to determine scope, impact, attack vector, and root cause.
• Coordinate incident response activities with SOC, IT Infrastructure, Application, Network, Cloud, IAM, Development, and other security teams.
• Lead/coordinate P1 incident war rooms, ensuring appropriate stakeholder engagement, timely updates, escalation, and action tracking.
• Track containment, remediation, recovery, and corrective/preventive actions through closure.
• Maintain accurate incident records and manage associated ITSM, LSM, SCM, Threat Intelligence, and vendor/support tickets within agreed SLAs.
• Prepare incident reports, RCA reports, timelines, lessons learned, and management updates for significant security incidents.
• Support development and continuous improvement of Incident Response SOPs, playbooks, escalation matrices, and knowledge base documentation.
• Work with SOC/SIEM/SOAR teams to identify opportunities for use-case enhancement and incident response automation, including IOC enrichment and automated phishing triage.
• Monitor incident ageing, SLA adherence, recurring incidents, and MTTR, and contribute to operational and management reporting.
Experience Requirements:
4–7 years of cybersecurity experience with strong exposure to SOC Operations and Incident Response.
• Strong understanding of the incident response lifecycle – Identification, Analysis, Containment, Eradication, Recovery, and Lessons Learned.
• Hands-on experience with SIEM, SOAR, EDR/XDR, WAF, Threat Intelligence and ITSM platforms.
• Experience investigating malware/ransomware, phishing, compromised accounts, suspicious endpoint/network activity, web attacks, and security breaches.
• Good understanding of MITRE ATT&CK, IOC analysis, threat hunting concepts, log analysis, and attack techniques.
• Ability to manage high-severity/P1 incidents and coordinate effectively across multiple technical and business stakeholders.
• Strong analytical, troubleshooting, documentation, and communication skills.
• Experience working in a large enterprise or managed security services environment preferred.
Preferred Certifications GCIH, GCFA, CEH, CHFI, CySA+, Security+, SC-200, CrowdStrike certifications, or equivalent Incident Response/SOC certifications.
Key Competencies:
Incident Investigation | CSIM | SOC | SIEM/SOAR | EDR/XDR | CrowdStrike | Threat Analysis | RCA | MITRE ATT&CK | Incident Coordination | ITSM | Security Automation
