1,115,425open jobs
64,401companies
189,702added this week
Browse all
Salary
≈ $16k – $39k per year (Estimated)
Location
In office (Bengaluru)
Experience
3+ years exp

First seen by Alion on Sep 30, 2026.

Overview
Company
Impact
Profile match
Backed by Warburg Pincus

This is a hands-on Information Security Operations role that combines SOC monitoring and investigation with Vulnerability Assessment and Penetration Testing (VAPT) execution.


The individual triages and investigates SOC alerts while also running vulnerability scans, web/API security testing, and SAST/DAST review with remediation tracking through to closure.


This is not a GRC analyst position; compliance or audit involvement is limited to providing accurate evidence from SOC and VAPT activities.

Principle Accountabilities (Key Result Areas) :

Job Description :

Core responsibilities across SOC monitoring, VAPT execution, and evidence management include the following :

- Monitor SOC queues and investigate alerts from Managed SOC/SIEM, endpoint, identity, email-security, DLP, VPN/proxy and endpoint-compliance sources.

- Enrich SOC alerts using user, device, IP, ASN, geo-location, application, timestamp, IOC, endpoint posture, related tickets and historical evidence.

- Document investigations with working notes, screenshots, containment status, closure rationale, ticket updates and shift handover notes.

- Execute scheduled and ad hoc vulnerability scans for infrastructure and applications; validate findings before escalation.

- Perform web application and API security testing under defined scope; mobile application testing is excluded unless separately assigned in the future.

- Review SAST/DAST findings, assist with secure-code review and coordinate with application/development owners for remediation evidence.

- Track vulnerability remediation and retesting in ServiceNow or approved workflow tools; maintain clean closure, retest and exception evidence.

- Support containment actions including account disablement, device freeze/quarantine/isolation, suspicious-session review, user outreach and restoration evidence.

- Prepare SOC monitoring inputs and VAPT status inputs including open vulnerabilities, overdue remediation, retest outcomes, repeat findings and escalation items.

- Provide security evidence from SOC/VAPT work when requested for audit/client/security review; do not own GRC program activities.

- Ensure SOC alerts are triaged consistently with evidence, classification, escalation notes and closure rationale (success measure).

- Validate, document and track infrastructure, web/API and SAST/DAST findings through remediation or retest (success measure).

- Escalate high-risk identity, endpoint, email, DLP, vulnerability and VPN/proxy events without delay (success measure).

- Maintain ServiceNow/security tickets that are complete, evidence-backed and aligned to SOC/VAPT operating expectations (success measure).

Attributes & Attitude :

- Hands-on investigative mindset with the discipline to perform practical triage and testing, not only ticket monitoring or scanner-output forwarding.

- Strong escalation discipline - knows when and how to escalate to Consultant/InfoSec lead, IT Ops, GSD, Endpoint, Development, HR/Ops, TAM or Legal based on severity and impact.

- Meticulous evidence and retesting hygiene, consistently capturing screenshots, timestamps, tool outputs, reproduction steps and closure comments.

- Clear, business-formal written communication for incident notes, vulnerability findings, remediation follow-ups and shift handovers.

- Comfortable operating across a hybrid scope - balancing SOC alert response with VAPT execution within the same role.

- Collaborative approach when coordinating with application/development owners, IT Ops and cross-functional teams on remediation evidence.

- Ownership and accountability for closure quality, without extending into GRC program ownership.

- Adaptable and detail-oriented, able to brief a Consultant/InfoSec lead with concise facts and risk indicators.

Knowledge :

Qualifications :

Minimum 3 - 5 years of experience and working knowledge across the following areas :

- SOC Operations: 3 - 5 years in SOC, MDR, InfoSec operations, endpoint security, vulnerability management or security monitoring support; BPO, healthcare, PCI or client-regulated environment exposure preferred.

- Vulnerability Assessment: Ability to run scans, validate vulnerabilities, capture evidence, prepare remediation notes and support retesting; Nessus/Qualys/OpenVAS and ServiceNow remediation tracking experience preferred.

- Web/API Testing: Working knowledge of OWASP Top 10, web/API testing methodology and manual validation using Burp Suite or OWASP ZAP; experience preparing concise technical finding write-ups preferred.

- SAST/DAST/Code Review: Ability to review tool findings, understand vulnerable code patterns and coordinate with developers under senior guidance; familiarity with SonarQube, Snyk, Semgrep, Checkmarx, Veracode or Fortify preferred.

- Communication and Evidence: Clear business-formal writing for incident notes, vulnerability findings, remediation follow-ups and shift handovers; able to brief a Consultant/InfoSec lead with concise facts and risk indicators.

- SIEM/MDR Tooling: Arctic Wolf/Aurora, Microsoft Sentinel or equivalent SIEM, Splunk/QRadar fundamentals, ServiceNow ticketing and IOC enrichment workflows.

- Identity/Endpoint Tooling: Microsoft Entra ID, Conditional Access, MFA, Defender for Endpoint, FortiEDR, Absolute, Intune/JamF, BitLocker/FileVault and endpoint evidence capture.

- Email/DLP Tooling: Abnormal AI / O365 email security, Microsoft Purview DLP, phishing/BEC/ATO investigation queues and remediation evidence.

- Network Vulnerability Tools: Nessus, Qualys, OpenVAS, Nmap, basic Metasploit validation, Wireshark and SSL/TLS testing tools.

- AD/Windows Exposure Awareness: BloodHound, PingCastle and NetExec/CrackMapExec awareness for privilege path, misconfiguration and exposure validation under supervision.

- Web/API Testing Tools: Burp Suite, OWASP ZAP, Postman, API collections and manual validation for authentication, authorization, session and input-handling issues.

- SAST Tools: Checkmarx, Veracode, SonarQube, Fortify, Snyk, Semgrep or equivalent; ability to read code paths and identify likely vulnerable patterns.

- DAST Tools: Burp Suite, OWASP ZAP, Acunetix, Invicti/Netsparker, AppScan or equivalent; validate output before raising remediation tickets.

- Cloud Security Basics: Microsoft Defender for Cloud / Azure posture review basics, AWS exposure awareness, Prowler/ScoutSuite-style output interpretation where applicable.

- Connectivity Context: FortiSASE, FortiGate, VPN, IPQS/IP2Proxy or equivalent tools for VPN/proxy/geolocation validation.

- Desirable Certifications: eJPT / PNPT / CEH Practical, CompTIA PenTest+ / Security+ / CySA+, Burp Suite certification or web testing training, Splunk Core / SIEM fundamentals - all Good to Have.

Skills

Information Security, IT Security Strategy, Security Operations Center, VAPT, Vulnerability Management, DAST, SAST, Network Security, DLP, OWASP

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,115,425 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Bengaluru
≈ $96k – $217k per year (Estimated) • In office • Full-Time • Miami
Apply
$80k – $90k per year • Equity • Remote (United States) • 7+ years exp • Seattle
Python
JavaScript
PowerShell
DevOps
Terraform
VMWare
CloudFormation
Nomad
AWS
Docker
Ubuntu
CentOS Stream
Amazon ECS
Linux
Windows
Cybersecurity
Crowdstrike
Nessus
CIS Benchmarks
NIST 800-171
Microsoft Entra ID
EnCase
Active Directory
SIEM
Apply
≈ $79k – $220k per year (Estimated) • In office • Internship • Bachelor's Degree • Atlanta
Python
Java
SQL
C++
DevOps
Azure
Windows Server
IAM
Linux
Windows
Unix
Analytics
Power BI
Management
Agile
Microsoft Office
Apply
≈ $72k – $166k per year (Estimated) • Hybrid • Full-Time • London
Python
PowerShell
DevOps
Rest API
Terraform
CI/CD
Cybersecurity
ISO 27001
GDPR
Apply
$135k – $156k per year • Remote (United States) • Secret • Full-Time
DevOps
Splunk
Cybersecurity
Microsoft Sentinel
Analytics
Power BI
Apply
≈ $104k – $236k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Austin
Databases
PostgreSQL
Oracle
AI/ML
Replicate
DevOps
Splunk
Dynatrace
AWS
Apply
$154k – $186k per year • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Bloomfield
Python
SQL
Groovy
Databases
Databricks
Apache Iceberg
Delta Lake
Apache Kafka
Apache Hudi
Teradata
AI/ML
Copilot
Spark
Model Context Protocol
Prompt Engineering
AWS Bedrock
Tokenization
DevOps
Rest API
Splunk
Terraform
Ansible
CI/CD
Jenkins
Git
AWS
Amazon EC2
Amazon S3
IAM
Amazon CloudWatch
Analytics
Tableau
ETL/ELT
Looker
Management
Agile
Scrum
Apply
≈ $103k – $201k per year (Estimated) • Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Raleigh
Databases
PostgreSQL
Oracle
AI/ML
Replicate
DevOps
Splunk
Dynatrace
AWS
Platform Engineering
Windows
Apply
≈ $80k – $176k per year (Estimated) • Remote (United Kingdom) • Full-Time • 3+ years exp • Bachelor's Degree • London
DevOps
Splunk
Apply
≈ $103k – $250k per year (Estimated) • Remote (United Kingdom) • Full-Time • 5+ years exp • Bachelor's Degree • London
DevOps
Splunk
Apply
≈ $20k – $48k per year (Estimated) • In office • 7+ years exp • Bengaluru
Apply
≈ $22k – $52k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Bengaluru
DevOps
AWS
Management
Jira
Agile
Scrum
Waterfall
Apply
In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru
DevOps
AWS
Apply
In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru
DevOps
AWS
Apply
≈ $8k – $20k per year (Estimated) • In office • Full-Time • 1+ year exp • Bachelor's Degree • Bengaluru
Management
SharePoint
Microsoft Office
Apply
≈ $15k – $36k per year (Estimated) • In office • 3+ years exp • Bengaluru
AI/ML
Machine Learning
Cybersecurity
Okta
Analytics
Tableau
Microsoft Excel
Management
Slack
Google Workspace
Apply
See all jobs
This is one of many
1,115,425 more open roles from verified company boards, updated every day.