Назад
Company hidden
1 день назад

Tier 2 Cybersecurity Operations Analyst (Cybersecurity)

Формат работы
remote (только India)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
India
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Tier 2 Cybersecurity Operations Analyst (SIEM/EDR/XDR): Investigating and responding to advanced security incidents while improving monitoring and detection capabilities with an accent on threat hunting, root cause analysis, and incident containment. Focus on correlating logs and alerts, tuning SIEM/SOAR tools, integrating threat intelligence, and mentoring Tier 1 analysts during complex investigations.

Location: Any location in India; remote

Company

hirify.global provides virtual care and develops solutions that expand access to healthcare.

What you will do

  • Investigate escalated incidents involving malware, advanced persistent threats, phishing, and unauthorized access.
  • Perform root cause analysis and implement containment, eradication, recovery, and remediation measures.
  • Conduct threat hunting with SIEM and EDR/XDR platforms, analyzing indicators of compromise, attack techniques, logs, and alerts.
  • Configure and optimize SIEM and SOAR tools, including detection rules, dashboards, and alerts.
  • Document investigations, prepare incident reports and post-incident reviews, and contribute to response playbooks and SOPs.
  • Mentor Tier 1 analysts and collaborate with senior analysts, threat intelligence, IT teams, CERT-In, and external vendors.

Requirements

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field; relevant certifications or equivalent experience may substitute.
  • 4–7 years of cybersecurity experience, preferably in a SOC or Tier 1 analyst role, with hands-on incident response experience.
  • Advanced knowledge of TCP/IP, DNS, VPN, and Windows, Linux, and macOS operating systems.
  • Proficiency with SIEM, EDR/XDR, network security appliances, log analysis, and packet capture tools such as Wireshark.
  • Experience with Python, PowerShell, or Bash scripting for automation and understanding of MITRE ATT&CK and CVE databases.
  • Strong problem-solving, communication, multitasking, mentoring, and incident leadership skills.

Nice to have

  • Familiarity with AWS, Azure, or Google Cloud security tools.
  • CompTIA Security+, CISSP, CEH, or GCIH certification.

Culture & Benefits

  • Inclusive, innovative environment focused on expanding access to care.
  • Opportunities for career growth, leadership, and professional development.
  • Benefits programs designed to support employees and their families.
  • Workplace culture that values diverse perspectives and continuous improvement.

Hiring process

  • Identity and credential verification is required.
  • Interviews may be conducted live or by video.
  • Fraud and misrepresentation screening is part of the process; falsified information leads to disqualification.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →