Jobs›Cyber Defense

Cyber Defense Specialist

Ralliant · Work from home
Work from home
PayPay not listed
WhereWork from home
TypeFull timeMid-level
Posted2 Oct3 days ago, via Himalayas
Kaam checked
No fee, deposit or pay-to-apply signs
Good spoken and written English expected
No vehicle or licence needed
Skills they list9 named
Cybersecurity SpecialistSOC AnalystIncident Response SpecialistThreat AnalystSecurity Operations AnalystCyber Defense AnalystCybersecurity Defense AnalystCyber DefenseDefense Security Specialist
About this job

Cyber Defense Specialist

ROLE DESCRIPTION

Purpose:Serve as a hands-on Cyber Defense expert responsible for advanced security operations, complex incident handling, continuous service improvement, Exposure Management, and delivery of improvement projects and After Action follow-up actions.

Location
Hybrid in Bangalore or Remote India

Role Description

The Cyber Defense Specialist is a hands-on Cyber Defense expert responsible for protecting enterprise and Operating Company (OpCo) environments through advanced security monitoring, investigation, incident handling, threat analysis, and exposure reduction. The role serves as a trusted technical authority for complex security events and drives investigations from initial detection through containment, recovery, and lessons learned.

This role operates within a 24x7 security operations and follow-the-sun model. The Specialist independently handles complex incidents and incidents that require manual intervention or escalation, leads technical workstreams during incidents, guides service providers, and makes sound risk-based decisions under pressure using established incident-management and escalation processes.

The role combines expert-level incident response with SOC operations, ticket and case triage, vulnerability and exposure management, DLP alert response, threat hunting, threat intelligence, detection improvement, and defensible evidence handling. A core expectation is to continuously improve the Cyber Defense service by identifying recurring weaknesses, contributing to improvement projects, strengthening standard work, and ensuring After Action Review commitments are implemented and validated.

The Cyber Defense Specialist works closely with global Security Operations leadership, managed security service providers, Cyber Defense Engineering, Infrastructure, Cloud, Identity, Network Security, application owners, GRC, Audit, Legal, HR, Privacy, and business stakeholders. The role supports regulated and customer-controlled environments where assigned, and executes work in accordance with Ralliant Business System (RBS) principles.

Key Responsibilities

Act as a technical responder for complex or high-severity security incidents, leading investigation, scoping, containment, eradication, recovery support, and technical validation through closure.

Perform technical incident-handling and support the incident response leads with authoritative findings, business-impact analysis, response options, decision points, and clear operational and executive-ready updates.

Perform advanced investigation and correlation across endpoint, identity, cloud, SaaS, email, network, and data-security telemetry to reconstruct attack paths, determine root cause, assess persistence, and identify affected assets, identities, and data.

Provide expert oversight of SOC monitoring, alert triage, case management, escalation, and shift handoffs; resolve ambiguous cases and ensure active work transfers without loss of context, ownership, or urgency.

Triage and govern security tickets and service requests, ensuring accurate prioritization, assignment, investigation quality, service-level discipline, documented decisions, and closure validation.

Operate SIEM and security operations platforms for advanced querying, correlation, investigation, reporting, and telemetry-quality validation; provide actionable detection and tuning recommendations.

Execute DLP investigations for complex or sensitive cases, preserve relevant evidence, determine security significance, and coordinate escalation through defined Legal, HR, Privacy, and Insider Risk workflows.

Lead technical vulnerability and exposure response by validating exploitability and attack paths, applying threat and business context, prioritizing remediation, coordinating urgent risk reduction, and verifying remediation or exception outcomes.

Conduct advanced threat analysis and targeted threat hunting, develop hypotheses, analyze adversary tactics and techniques, validate defensive assumptions, identify control gaps, and translate findings into improved detections and response actions.

Operationalize internal and external threat intelligence into investigative queries, prioritized hunts, detection requirements, response actions, and targeted advisories.

Drive continuous improvement of the Cyber Defense service by analyzing incident, alert, ticket, backlog, handoff, and service-performance trends; identify root causes and convert findings into practical improvements with measurable outcomes.

Contribute to Cyber Defense improvement projects such as playbook modernization, workflow simplification, automation, tooling enhancements, telemetry onboarding, detection-quality improvement, case-management improvement, and service-provider integration.

Own technical and operational work packages within improvement projects, including requirements, stakeholder coordination, testing, documentation, implementation readiness, adoption support, and validation of expected outcomes.

Support After Action Reviews and ensure lessons learned result in assigned corrective actions. Track actions through completion, validate effectiveness, and escalate overdue or ineffective actions so material weaknesses are not left unresolved.

Partner with Cyber Defense Engineering and service providers to improve detection coverage and fidelity, reduce false positives, close telemetry gaps, and ensure detections remain effective as technologies and threats change.

Ensure incident records, timelines, evidence, handling decisions, and investigation reports are complete, accurate, defensible, and suitable for audits, customer inquiries, regulatory obligations, or legal review.

Contribute to operational and leadership reporting covering incident trends, response performance, alert quality, exposure remediation, recurring drivers, backlog health, improvement-project progress, and corrective-action closure.

Qualifications

Bachelor’s degree in cybersecurity

Never pay to get work. If a listing asks for a fee, it is a scam. The ten signs →

Apply on Himalayas
Opens himalayas.app in a new tab