Expert IT Cyber Defense Analyst
Veradigm® · Pune
Job description
About the role
The Expert IT Cyber Defense Analyst is a senior technical role responsible for advanced threat detection, security monitoring, incident investigation, and response across enterprise environments. This position acts as a technical authority within the Security Operations Center (SOC), driving high‑impact investigations, optimizing detections, mentoring analysts, and strengthening the organization’s overall cyber defense posture.
Key responsibilities
- Perform continuous monitoring of network, endpoint, identity, cloud, and application telemetry using SIEM, EDR, IDS/IPS, firewalls, Azure AD, and vulnerability management platforms.
- Identify sophisticated threats by correlating multi‑source telemetry, detecting anomalies, and recognizing attacker TTPs.
- Enhance SIEM and EDR detection logic by creating and tuning correlation rules, behavioral analytics, watchlists, and automated alert workflows.
- Lead high‑severity incidents and complex investigations involving malware, privilege misuse, lateral movement, ransomware indicators, persistence mechanisms, and potential data exfiltration.
- Conduct in‑depth forensic analysis of endpoints, logs, cloud audit trails, and network flows to determine root cause, scope, and business impact.
- Collaborate with the Incident Response team to drive containment, eradication, and recovery efforts with minimal operational disruption.
- Perform proactive threat hunting aligned with the latest threat intelligence, emerging TTPs, vulnerabilities, and adversary campaigns.
- Mentor Tier 1 and Tier 2 analysts, review alerts handled by junior staff, and contribute to SOC capability uplift through training and knowledge sharing.
Required profile
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent practical experience.
- 5–8+ years of experience in SOC operations, cyber defense, threat hunting, or incident response.
- Proven experience investigating high‑severity incidents, malware behavior, lateral movement, privilege misuse, and network‑based threats.
- Strong analytical, investigative, and communication skills.
- Preferred certifications: GCIH, Security+, CEH, CySA+, AZ‑500.
Required skills
- SIEM platforms: Splunk, Microsoft Sentinel.
- EDR tools: CrowdStrike, Microsoft Defender.
- IDS/IPS and firewall technologies.
- Cloud security monitoring: Azure, AWS.
- Operating systems: Windows, Linux.
- Threat frameworks: MITRE ATT&CK, cyber kill chain.
- SOAR playbook development and automated alert workflows.
- Threat hunting, forensic analysis, and detection rule writing.
What we offer
- Quarterly Company‑Wide Recharge Days.
- Flexible work environment (Hybrid).
- Peer‑based incentive “Cheer” awards.
- Tuition Reimbursement Program.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in India.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 week ago
Expires 1 month from now
22 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Veradigm®
Pune