Senior Security Monitoring & Response Analyst (Incident Responder)
mastercard · Pune
Job description
About the role
The Security Operation Centre Incident Response (SOCIR) Team is looking for a Senior Security Monitoring and Response Analyst (Incident Responder) to strengthen our capability in detecting, triaging, and responding to cybersecurity threats across the organization. The ideal candidate is analytical, detail‑oriented, calm under pressure, and passionate about threat detection and response.
Key responsibilities
- Provide support to SOC analysts and serve as an escalation point for alerts generated by SIEM, EDR, and other security technologies, enabling rapid identification of potential threats.
- Perform advanced triage of security incidents, including log analysis, threat validation, DFIR, malware analysis and impact assessment.
- Execute incident response activities such as containment, eradication, recovery, and documentation.
- Collaborate with cross‑function teams to investigate root causes and strengthen defensive controls.
- Maintain and create SOPs related to Incident Response, regulatory reporting, and forensic or malware analysis techniques.
- Support threat hunting efforts by proactively identifying anomalous behavior and emerging threat patterns.
- Provide continuous feedback and lead improvements in alert fidelity, automation opportunities, SOC training and detection logic.
Required profile
- Advanced level experience in Security Operations, Incident Response, Threat Detection, DFIR, and malware reverse engineering.
- Strong expertise in log analysis, EDR platforms, and SIEM technologies (e.g., Splunk, Microsoft Sentinel).
- Demonstrated ability to lead complex incident investigations, including lateral movement analysis, malware triage, and cloud incident handling.
- Deep understanding of network security, operating‑system internals (Windows, Linux), and common attack techniques (MITRE ATT&CK, kill chain).
- Familiarity with forensics (endpoint, memory, network) and evidence‑preservation methodologies.
- Hands‑on experience performing containment, eradication, and recovery across on‑prem, cloud, and hybrid environments.
- Strong knowledge of threat intelligence, TTP mapping, and adversary‑behaviour interpretation.
- Ability to develop and maintain IR playbooks, SOPs, and detection‑logic improvements.
- Excellent communication skills for collaborating with engineering, legal, IT, and leadership during high‑severity incidents.
- Ability to mentor junior analysts and lead incident bridges under pressure.
- Background in cloud security (Azure, AWS, GCP) including log sources, identity models, and incident patterns.
- Preferred certifications include GCFE, GCFA, OSCP, GREM or equivalent expertise.
Required skills
- Splunk
- Microsoft Sentinel
- EDR platforms
- DFIR
- Malware reverse engineering
- Log analysis
- Windows operating system
- Linux operating system
- MITRE ATT&CK framework
- Endpoint forensics
- Memory forensics
- Network forensics
- Azure
- AWS
- GCP
- Threat intelligence analysis
- Incident response playbooks
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in India.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
A question about this job?
Ask it here: you will get the full job summary by e-mail, right away.
Published 1 week ago
Expires 1 month from now
35 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
mastercard
Pune