LogoLanguage
DeviceDriven (India) Pvt. Ltd

Padmanabham, Technopark Campus, Trivandrum , 695581

Security Analyst

Closing Date:30,Sept 2026
Job Published: 28,Aug 2026

Brief Description

 

We are looking for an experienced Security Analyst to join our Cybersecurity team. The role focuses on threat detection and incident response, vulnerability management, cloud and identity security, and compliance support across our enterprise infrastructure.

You will monitor and investigate security alerts, coordinate vulnerability remediation, support PCI-DSS and SOC 2 compliance, and work closely with infrastructure, engineering, and compliance teams.

Key Responsibilities

  • Monitor and triage security alerts across GCP, Okta, endpoint security, and cloud security platforms.
  • Investigate authentication anomalies, suspicious activity, account compromise, and potential security incidents.
  • Analyse Windows security events and GCP security activity, including IAM and service account changes.
  • Document investigations, determine true/false positives, and escalate critical incidents as required.
  • Follow and improve established incident response playbooks.
  • Coordinate monthly PCI vulnerability management using tools such as Rapid7 Nexpose/InsightVM and Orca Security.
  • Create and manage JIRA tickets for vulnerability remediation and track findings through closure.
  • Work with Infrastructure and Platform teams on patching, remediation, and SLA tracking.
  • Support SAST/DAST and application security initiatives.
  • Support PCI-DSS and SOC 2 Type II compliance activities, audits, and evidence collection.
  • Assist with third-party risk management, including vendor security assessments and review of SOC 2 and penetration testing reports.

 

 

Preferred Skills

  • Strong experience as a Security Analyst, SOC Analyst (Tier 2+), or Security Operations professional.
  • Hands-on experience with cloud security monitoring — GCP preferred; AWS/Azure acceptable.
  • Experience with IAM and identity security, including Okta, Azure AD, MFA, and authentication protocols.
  • Proven experience in vulnerability management and remediation coordination.
  • Experience with SIEM/SOAR platforms and security log analysis.
  • Experience working in regulated environments, preferably PCI-DSS, SOC 2, or financial services.

Technical Skills

  • Cloud Security: GCP Security Command Center, Cloud Monitoring, IAM, Cloud Logging.
  • Identity Security: Okta, MFA, authentication and authorization protocols.
  • Endpoint Security: Windows Security Events and scheduled task analysis.
  • Vulnerability Management: Rapid7 Nexpose/InsightVM, Qualys, Nessus, CVSS, patch management.
  • Application Security: OWASP Top 10 and SAST/DAST tools.
  • Ticketing & Documentation: JIRA/Atlassian and Confluence.

Required Knowledge

Strong understanding of:

Threat Detection & Analysis | Incident Response | Network Security | IAM | Malware Analysis Fundamentals | Security Architecture | Vulnerability Management

Knowledge of PCI-DSS, SOC 2, NIST Cybersecurity Framework, and CIS Benchmarks.

Good to Have

  • Experience with Orca Security.
  • Knowledge of Kubernetes/GKE security.
  • Familiarity with Terraform and Infrastructure-as-Code security.
  • Experience in financial services or cryptocurrency security.
  • Third-party risk management (TPRM) experience.
  • Relevant certifications such as Security+, CySA+, CISSP, GIAC, or Google Cloud Professional Cloud Security Engineer.

Soft Skills

Analytical Thinking | Communication | Collaboration | Time Management | Attention to Detail | Continuous Learning

Tools

GCP | Okta | Orca Security | Rapid7 Nexpose/InsightVM | JIRA | Confluence | Windows Event Viewer | Workday