IT Security Analyst- Mid

location_onKolkata, West Bengal, Indiascheduleकल
homeकाम का तरीका:रिमोट
trending_upअनुभव स्तर:मध्य स्तर
historyन्यूनतम अनुभव:2+ वर्ष

पद का विवरण

Position Summary

We are seeking an experienced and driven Sr. IT Security Analyst to spearhead our Microsoft security ecosystem, maintain our overall security posture, and drive vulnerability and threat management practices. In this role, you will handle L1/L2 security operations and take ownership of critical risk-reduction lifecycles. Furthermore, you will act as a key technical partner in supporting our annual SOC 2 attestation engagements, ensuring continuous alignment with compliance controls.

Key Responsibilities

1. Microsoft Security Posture & Threat Management

  • Administer, configure, and optimize the Microsoft Defender Suite (Defender for Endpoint, Cloud, Office 365, and Identity), Microsoft Purview, and Microsoft Entra ID (Azure AD).
  • Proactively manage Threat Management operations—monitoring threat intelligence feeds, performing advanced hunting, and investigating complex anomalies across Microsoft cloud and hybrid environments.
  • Continuously improve the organization’s overall defense mechanisms by tracking and maximizing Microsoft Secure Score recommendations.
  • Manage Identity and Access Management (IAM) controls, including Conditional Access Policies, Privileged Identity Management (PIM), and Multi-Factor Authentication (MFA).

2. Vulnerability Management

  • Own and drive the end-to-end Vulnerability Management lifecycle across endpoints and cloud resources utilizing Microsoft Defender Vulnerability Management and related tools.
  • Coordinate routine vulnerability scans, prioritize remediation based on risk and exploitability, and track patches through completion.
  • Collaborate with system administrators and IT teams to ensure rapid remediation of critical security flaws and misconfigurations.

3. Operations & Incident Response (L1 & L2)

  • Lead the triage, investigation, and containment of L1 and L2 security incidents, providing deep analytical insights and root-cause analyses.
  • Review Defender Policy rule changes, endpoint logs, and XDR telemetry for suspicious activities.
  • Develop, refine, and maintain operational security playbooks to streamline incident handling and response workflows.

4. SOC 2 Attestation & Compliance Support

  • Partner closely with the Compliance Manager to support SOC 2 Type I and Type II audit cycles.
  • Collect, validate, and organize technical evidence mapped to Trust Services Criteria within Microsoft environments.
  • Monitor control health, remediate security gaps identified during audits, and maintain audit-ready documentation for access reviews and change management.

Requirements

Required Qualifications & Skills

  • Experience: 2 to 3 years of hands-on experience in information security, threat operations, or vulnerability management.
  • Microsoft Expertise: Deep technical proficiency in Microsoft 365 Security & Compliance, Microsoft Entra ID, and Microsoft Defender XDR / Sentinel.
  • Core Competencies: Proven experience running formal vulnerability management programs and managing active threat/incident environments.
  • Compliance Knowledge: Practical familiarity with frameworks like SOC 2, ISO 27001, or NIST, with experience in audit preparation and evidence collection.

Soft

Skills

Excellent remote communication skills, proactive problem-solving abilities, and a collaborative mindset when working across distributed teams.

उल्लिखित कौशल

इस पद के लिए आवेदन करें

Use the application link supplied with this listing to apply to ETHICS CODE. Check the destination before entering personal information.