{"id":752065,"url":"https://alion.io/job/netspend-senior-security-incident-response-analyst","title":"Senior Security Incident Response Analyst","company":{"id":678968,"name":"Netspend","domain":"netspend.com","url":"https://alion.io/company/netspend","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"B","score":75,"open_postings":3,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Noida, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":17000,"max_usd":37000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":12},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Crowdstrike","optional":false},{"name":"GCP","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"SentinelOne","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"CI/CD","optional":true},{"name":"Kubernetes","optional":true}],"status":"live","first_seen_at":"2026-07-20T16:41:15Z","employer_posted_date":"2026-07-20","last_verified_at":"2026-09-30T22:04:18Z","board_verified":true,"closed_at":null,"days_open":72,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":72},"description":"About the Company:\nNetspend Corporation is a global, vertically-integrated financial services and technology company dedicated to the delivery of innovative financial empowerment solutions to consumers worldwide. Netspend's financial products and services span prepaid, debit, cross-border payments, and loyalty solutions for consumers and enterprise partners.\nNetspend provides prepaid and debit account solutions that connect customers with secure, convenient access to global payment networks so they can manage their money and make everyday purchases. With a nationwide U.S. retail network, customers can purchase and reload Netspend products at 130,000 reload points and over 100,000 distributing locations.\nSince our founding in 1999 by industry pioneers, Netspend products have processed billions of dollars in transaction volume and served millions of customers worldwide. The company is headquartered in Austin, Texas with employees worldwide.\nJob Description:\nWe are seeking a highly skilled Senior Security Incident Response Analyst to join our global Cyber Defense organization. This individual contributor role is responsible for\ntriaging and investigating security alerts, developing and maintaining response playbooks, and ensuring the effectiveness of security logging and detection capabilities. The ideal candidate brings deep technical expertise, strong analytical skills, and a passion for improving detection and response processes at scale. This role will collaborate closely with Security Operations, Threat Detection Engineering, Platform/Infrastructure teams, and cross-functional partners across global time zones. The position is based in India and may support a follow-the-sun incident response model.\nKey Responsibilities\nIncident Monitoring & Investigation\nContinuously monitor and triage security alerts from SIEM, EDR, cloud platforms, and other detection systems\nConduct end-to-end investigations for potential security incidents, including scoping, containment recommendations, and root-cause identification\nEscalate and coordinate with global IR teams for high-severity incidents.\nPerform forensic analysis on endpoints, logs, and cloud workloads as required.\nResponse Playbooks & Process Improvement\nDesign, build, and maintain incident response playbooks covering common threat\nscenarios (malware, phishing, identity compromise, insider threat, cloud\nmisconfigurations, etc.)\nIdentify opportunities for automation and orchestration in investigation workflows\nCollaborate with Threat Detection Engineering to refine detection logic, thresholds, and alerting criteria\nDocument incident findings, lessons learned, and process improvements.\nLogging & Detection Efficacy\nEvaluate the completeness and quality of security logs across infrastructure,\napplications, and cloud environments (AWS/Azure/GCP).\nRecommend improvements in logging coverage, enrichment, and parsing to strengthen detection capabilities\nPartner with Security Engineering to validate telemetry ingestion and visibility in SIEM and EDR platforms\nConduct periodic logging health assessments and tune noisy or low-value alerts.\nStakeholder Collaboration\nWork with IT, Cloud, Engineering, and Compliance teams to ensure incident response readiness\nProvide guidance to junior analysts and regional partners when required\nSupport tabletop exercises and readiness assessments.\nRequirements\n5-8+ years of hands-on experience in Security Operations, Incident Response, threat hunting, or Detection Engineering\nStrong knowledge of SIEM platforms (e.g., Splunk, ELK, Sentinel), EDR tools\n(CrowdStrike, SentinelOne, etc.), and cloud security (AWS/GCP/Azure)\nProven ability to investigate complex security events using logs, network traffic, and\nendpoint data\nExperience building IR playbooks and standard operating procedures\nFamiliarity with MITRE ATT&CK, NIST Incident Response Framework, and modern\nadversary TTPs\nSolid understanding of logging architectures, event taxonomies, and detection pipelines.\nExcellent communication skills and ability to work independently in a global, distributed environment\nPreferred Qualifications\nRelevant certifications (GCIA, GCIH, GCFA, GNFA, Azure/AWS Security, etc.)\nExperience with SOAR automation workflows\nExposure to DevOps, Kubernetes, container security, or CI/CD pipeline monitoring\nPrior experience working in a global 24/7 operational security model","description_format":"text","description_chars":4389,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"India","iso":"IN","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Incident Response"],"lifecycle":[{"event":"open","at":"2026-09-11T15:59:21Z"}],"liveness":{"score":13,"band":"cold","label":"Long shot","p_open":1,"p_active":0.46,"p_room":0.28,"age_days":71,"expected_fill_days":23,"reasons":["conf:4","velocity","win:tail","crowd:"],"computed_at":"2026-09-30T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/netspend-senior-security-incident-response-analyst","json_url":"https://alion.io/job/netspend-senior-security-incident-response-analyst.json","meta":{"generated_at":"2026-10-01T04:39:53Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4129,"day_limit":5000,"remaining_today":871,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}