Incident Response Analyst – Cybersecurity

Incident Response Analyst – Cybersecurity

22

Mumbai, Maharashtra, India

Job Views:

Created Date: 2026-08-13

End Date:

Salary: 65000

Industry: Edtech

Openings: 1

Primary Responsibilities :
• Perform triage, validation, severity classification (P1–P3), investigation, containment, and escalation of cybersecurity incidents • Investigate alerts/incidents originating from SIEM/SOAR, CrowdStrike EDR/XDR, Akamai WAF, Bugcrowd, Threat Intelligence platforms, application monitoring tools, and user-reported events. • Analyse security events, logs, IOCs, endpoint telemetry, network activity, and other evidence to determine scope, impact, attack vector, and root cause. • Coordinate incident response activities with SOC, IT Infrastructure, Application, Network, Cloud, IAM, Development, and other security teams. • Lead/coordinate P1 incident war rooms, ensuring appropriate stakeholder engagement, timely updates, escalation, and action tracking. • Track containment, remediation, recovery, and corrective/preventive actions through closure. • Maintain accurate incident records and manage associated ITSM, LSM, SCM, Threat Intelligence, and vendor/support tickets within agreed SLAs. • Prepare incident reports, RCA reports, timelines, lessons learned, and management updates for significant security incidents. • Support development and continuous improvement of Incident Response SOPs, playbooks, escalation matrices, and knowledge base documentation. • Work with SOC/SIEM/SOAR teams to identify opportunities for use-case enhancement and incident response automation, including IOC enrichment and automated phishing triage. • Monitor incident ageing, SLA adherence, recurring incidents, and MTTR, and contribute to operational and management reporting.
Experience Requirements:
4–7 years of cybersecurity experience with strong exposure to SOC Operations and Incident Response. • Strong understanding of the incident response lifecycle – Identification, Analysis, Containment, Eradication, Recovery, and Lessons Learned. • Hands-on experience with SIEM, SOAR, EDR/XDR, WAF, Threat Intelligence and ITSM platforms. • Experience investigating malware/ransomware, phishing, compromised accounts, suspicious endpoint/network activity, web attacks, and security breaches. • Good understanding of MITRE ATT&CK, IOC analysis, threat hunting concepts, log analysis, and attack techniques. • Ability to manage high-severity/P1 incidents and coordinate effectively across multiple technical and business stakeholders. • Strong analytical, troubleshooting, documentation, and communication skills. • Experience working in a large enterprise or managed security services environment preferred. Preferred Certifications GCIH, GCFA, CEH, CHFI, CySA+, Security+, SC-200, CrowdStrike certifications, or equivalent Incident Response/SOC certifications. Key Competencies: Incident Investigation | CSIM | SOC | SIEM/SOAR | EDR/XDR | CrowdStrike | Threat Analysis | RCA | MITRE ATT&CK | Incident Coordination | ITSM | Security Automation
Location

: Alliance Recruitment Agency

Share Job :