Cyber Defense Specialist
Listed on 2026-10-04
-
IT/Tech
Cybersecurity, Security Management & Operations
Remote
Cyber Defense Specialist
ROLE DESCRIPTIONPurpose: Serve as a hands-on Cyber Defense expert responsible for advanced security operations, complex incident handling, continuous service improvement, Exposure Management, and delivery of improvement projects and After Action follow-up actions.
Location: Hybrid in Bangalore or Remote India
Role DescriptionThe Cyber Defense Specialist is a hands-on Cyber Defense expert responsible for protecting enterprise and Operating Company (OpCo) environments through advanced security monitoring, investigation, incident handling, threat analysis, and exposure reduction. The role serves as a trusted technical authority for complex security events and drives investigations from initial detection through containment, recovery, and lessons learned.
This role operates within a 24x7 security operations and follow-the-sun model. The Specialist independently handles complex incidents and incidents that require manual intervention or escalation, leads technical work streams during incidents, guides service providers, and makes sound risk-based decisions under pressure using established incident-management and escalation processes.
The role combines expert-level incident response with SOC operations, ticket and case triage, vulnerability and exposure management, DLP alert response, threat hunting, threat intelligence, detection improvement, and defensible evidence handling. A core expectation is to continuously improve the Cyber Defense service by identifying recurring weaknesses, contributing to improvement projects, strengthening standard work, and ensuring After Action Review commitments are implemented and validated.
The Cyber Defense Specialist works closely with global Security Operations leadership, managed security service providers, Cyber Defense Engineering, Infrastructure, Cloud, Identity, Network Security, application owners, GRC, Audit, Legal, HR, Privacy, and business stakeholders. The role supports regulated and customer-controlled environments where assigned, and executes work in accordance with Ralliant Business System (RBS) principles.
Key ResponsibilitiesAct as a technical responder for complex or high-severity security incidents, leading investigation, scoping, containment, eradication, recovery support, and technical validation through closure.
Perform technical incident-handling and support the incident response leads with authoritative findings, business-impact analysis, response options, decision points, and clear operational and executive-ready updates.
Perform advanced investigation and correlation across endpoint, identity, cloud, SaaS, email, network, and data-security telemetry to reconstruct attack paths, determine root cause, assess persistence, and identify affected assets, identities, and data.
Provide expert oversight of SOC monitoring, alert triage, case management, escalation, and shift handoffs; resolve ambiguous cases and ensure active work transfers without loss of context, ownership, and urgency.
Triage and govern security tickets and service requests, ensuring accurate prioritization, assignment, investigation quality, service-level discipline, documented decisions, and closure validation.
Operate SIEM and security operations platforms for advanced querying, correlation, investigation, reporting, and telemetry-quality validation; provide actionable detection and tuning recommendations.
Execute DLP investigations for complex or sensitive cases, preserve relevant evidence, determine security significance, and coordinate escalation through defined Legal, HR, Privacy, and Insider Risk workflows.
Lead technical vulnerability and exposure response by validating exploitability and attack paths, applying threat and business context, prioritizing remediation, coordinating urgent risk reduction, and verifying remediation or exception outcomes.
Conduct advanced threat analysis and targeted threat hunting, develop hypotheses, analyze adversary tactics and techniques, validate defensive assumptions, identify control gaps, and translate findings into improved detections and response actions.
Operationalize internal and external threat intelligence into investigative queries, prioritized hunts, detection requirements, response actions, and targeted advisories.
Drive continuous improvement of the Cyber Defense service by analyzing incident, alert, ticket, backlog, handoff, and service-performance trends; identify root causes and convert findings into practical improvements with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).