
Cybersecurity Incident Response Analyst
- India
- Permanent
- Full-time
- Lead and manage the entire incident response lifecycle, from detection and analysis to containment, eradication, recovery, and post-incident review.
- Coordinate incident response efforts with internal teams (IT, legal, communications, etc.) and external stakeholders (vendors, law enforcement, etc.).
- Develop, implement, and maintain incident response plans, procedures, and playbooks.
- Conduct thorough forensic analysis of security incidents to identify root causes and recommend preventative measures.
- Utilize security tools and technologies such as EDR, network forensics, and other investigative platforms to respond to incidents.
- Document all incident activities, findings, and resolutions accurately and comprehensively.
- Provide regular updates and reports on incident status to senior management.
- Stay up-to-date with the latest threat landscape, vulnerabilities, and security technologies.
- Contribute to the continuous improvement of our security posture through proactive analysis and recommendations.
- Provide guidance and expertise to other security professionals during incident response activities.
- Collaborate in the design and evaluation of policies, processes, and standards forming the governance framework relating to information security.
- Evaluate and analyze security events and tools.
- Evaluate different information security products and tools.
- Produce various reports and communications to better recommend security orientations and plans.
- Write various types of documentation and reports related to incident response.
- Perform any other related task to support the security team's objectives.
- Bachelor's degree in Computer Science, Information Security, or a related field; or equivalent practical experience.
- 5+ years of experience in information security, with at least 3-5 years in a dedicated incident response or security operations role.
- Strong understanding of common security frameworks (e.g., NIST, ISO 27001).
- In-depth knowledge of various attack vectors, threat intelligence, and incident response methodologies.
- Proficiency with security tools such as EDR, IDS/IPS, vulnerability scanners, and forensic tools.
- Experience with cloud security (AWS, Azure, GCP) is a plus.
- Excellent analytical, problem-solving, and decision-making skills.
- Exceptional written and verbal communication skills, with the ability to clearly articulate complex technical information to both technical and non-technical audiences.
- Ability to work independently and as part of a team in a fast-paced and dynamic environment.
- Relevant certifications such as GCIH, GCFA, CISSP, or equivalent are highly desirable.