
Tier 2 Cybersecurity Operations Analyst
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in India.
• Investigate escalated security incidents, including malware infections, advanced persistent threats, phishing campaigns, and unauthorized access attempts.
• Conduct root cause analysis to identify the source, scope, and impact of incidents.
• Implement measures for containment, eradication, and recovery, such as system isolation and security patching.
• Engage in proactive threat hunting utilizing SIEM and EDR/XDR platforms.
• Analyze Indicators of Compromise along with Tactics, Techniques, and Procedures.
• Correlate logs and alerts to identify patterns of malicious activity.
• Configure and fine-tune SIEM and SOAR platforms.
• Develop and maintain SIEM rules, dashboards, and alerts.
• Document incident timelines, findings, and remediation steps in ticketing systems.
• Prepare incident reports and conduct post-incident reviews for management and compliance purposes.
• Contribute to the development of standard operating procedures and incident-response playbooks.
• Mentor and guide Tier 1 analysts in alert triage and basic incident handling.
• Collaborate with Senior Analysts, threat intelligence teams, and IT departments on investigations and remediation efforts.
• Liaise with CERT-In and external vendors during significant incidents.
• Integrate threat intelligence feeds into security monitoring processes.
• Monitor emerging cyber threats, vulnerabilities, and attack trends relevant to the organization.
• Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; relevant certifications or equivalent experience may be accepted as a substitute.
• 4–7 years of experience in cybersecurity, ideally in a SOC environment or as a Tier 1 analyst.
• Direct experience in incident response.
• Advanced understanding of networking protocols including TCP/IP, DNS, and VPN.
• Knowledge of Windows, Linux, and macOS operating systems.
• Proficiency in SIEM platforms, EDR/XDR tools, and network security appliances.
• Experience in log analysis and packet capture tools like Wireshark.
• Familiarity with scripting languages such as Python, PowerShell, and Bash for automation purposes.
• Knowledge of cloud security tools, including AWS, Azure, or Google Cloud, is advantageous.
• Understanding of MITRE ATT&CK and common vulnerabilities, including the CVE database.
• Strong problem-solving and critical-thinking abilities.
• Capability to work effectively under pressure and manage multiple incidents simultaneously.
• Excellent communication skills to convey technical findings to non-technical stakeholders.
• Team mentoring and leadership skills.
• Applicants must provide accurate information; any falsification will lead to disqualification.
• Identity and credential verification, interviews, and screening for fraud or misrepresentation are integral parts of the hiring process.
• Opportunities for career growth and meaningful development.
• An inclusive benefits program focused on employees and their families.
• Tailored programs that address the needs of individuals and families.
• An innovative and inclusive workplace culture.
• Equal opportunity employment.
IQVIA
ALB Conciergerie
ALB Conciergerie
Get handpicked remote jobs straight to your inbox weekly.