We are looking for Incident Analyst to anchor the technical depth of our 24×7 Security Operations Center. This role detects, triages, investigates and responds to security incidents across our private-cloud platform and the enterprise services it supports. The successful candidate is a hands-on practitioner who can own an incident end to end — from the first alert in Splunk through containment, eradication and recovery — while also raising the quality of our detections and acting as a senior escalation point and mentor for less-experienced analysts. The environment is a private cloud built on OpenStack and Red Hat OpenShift, instrumented with Splunk (SIEM), Cribl (data pipeline), Elastic Security (EDR) and Corelight (NDR); comfort working across virtualized and containerized infrastructure log sources is expected.
Your Key Responsibilities
Security Monitoring, Triage & Detection
Monitor security alerts and events in Splunk to identify threats, anomalies and malicious activity across the private-cloud platform and enterprise services
Perform triage and investigation of security events, acting as the senior technical decision point on whether an alert represents a genuine incident
Investigate EDR and NDR alerts involving malware, suspicious scripts, credential theft, lateral movement, persistence, ransomware and endpoint or network compromise
Incident Response (full lifecycle)
Own security incidents end to end across the full response lifecycle: identification, containment, eradication, recovery and post-incident review
Execute containment and remediation actions in coordination with platform, infrastructure, network and application teams
Lead the response on assigned incidents and coordinate cross-team activity to ensure timely investigation, escalation and resolution
Develop and maintain incident response playbooks and standard operating procedures (SOPs), and drive their improvement after each major incident
SIEM, Detection Engineering & Log Pipeline
Create, tune and optimize Splunk correlation searches, alerts, dashboards and reports to improve detection quality and coverage
Write and maintain efficient SPL queries supporting investigation, hunting, reporting and detection engineering
Reduce alert fatigue by tuning noisy detections, lowering false positives and strengthening correlation logic, weighing false-positive cost against miss cost when making tuning decisions
Support onboarding of new log sources and validate log quality, parsing, field extraction and normalization
Manage and maintain Cribl Stream/Edge pipelines for log routing, filtering, enrichment and normalization, optimizing data flow and Splunk license consumption
Threat Hunting & Intelligence
Conduct hypothesis-driven threat hunts to uncover advanced persistent threats (APTs) and techniques that evade existing detections
Map detection coverage to MITRE ATT&CK, identify and report gaps, and convert successful hunts into durable detections
Apply threat intelligence and frameworks (MITRE ATT&CK, Cyber Kill Chain, Diamond Model) to enrich investigations and improve detection and response
Identify patterns, trends and indicators of compromise (IOCs) to proactively detect and prevent recurrence
Documentation, Reporting & Governance
Conduct root cause analysis (RCA) and produce clear incident reports for management and stakeholders
Maintain accurate, detailed records of incidents, actions taken, evidence collected and lessons learned in the case-management platform
Contribute to the continuous improvement of security monitoring use cases and detection rules
Support audit and compliance requirements by providing evidence of incident-management activities
Working arrangement
Full-time role reporting to the SOC Manager, operating within a 24×7 Security Operations Center
Participation in rotational shifts — day, evening and night — including weekends and public holidays on a rotational basis
Defined acknowledgement, triage and escalation SLAs apply to each shift, with structured shift handovers to maintain continuity of in-flight incidents
What We’re Looking For
Required skills / qualifications
Education
Bachelor’s degree in Computer Science, Information Security, Cybersecurity or a related field; equivalent professional experience and certifications will be considered in lieu of a degree
Experience
4–8 years in security operations, incident response or SOC monitoring
Proven hands-on experience with Splunk — advanced SPL, dashboard development, alert creation, correlation and administration
Demonstrated experience with Cribl Stream/Edge — data routing, filtering, pipelines and log enrichment
Strong background in incident analysis, investigation, evidence handling, escalation management and full-lifecycle response aligned with industry standards
Networking: strong understanding of TCP/IP, DNS, HTTP/S, firewalls, proxies and IDS/IPS
Operating Systems: proficiency in Windows and Linux environments
Scripting: proficiency in Python, Bash or PowerShell for automation and analysis
Platform Technologies: familiarity with private-cloud and platform log sources — Red Hat OpenShift, OpenStack, Commvault, Scality and related infrastructure
Ticketing / Case Mgmt: ServiceNow, Jira or equivalent for incident tracking, evidence attachment, escalation notes and closure documentation
Preferred skills / qualifications
Industry Certifications, Such As
Splunk Core Certified Power User or Splunk Certified Admin
Cribl Certified Admin
GIAC certifications relevant to detection and response — GCIA, GCIH, GCDA or GCFA
Blue Team Level 2 (BTL2) or equivalent hands-on defensive certification
Experience monitoring OpenStack and Kubernetes/OpenShift environments
Familiarity with detection-as-code practices (version control and peer review of detection content)
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Upload your Profile Picture
Accepted Formats: jpg, png
Upto 2MB in size
Your application for Analyst - Security Operations
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!