Job Title: Information Security Analyst
Location: India
Reports To: Security & Infra Director
We are seeking an experienced and highly analytical Information Security Analyst. This role is responsible for monitoring, validating, investigating, and clarifying security events and incidents across the organization. The analyst will work extensively with the SOC team to improve detection coverage, tune and create correlation rules, enhance alert quality, and strengthen incident handling processes. The role will also be expected to bring hands-on experience and practical recommendations to support the implementation of SOAR capabilities, including automation use cases, playbooks, enrichment workflows, and response processes. The role requires strong hands-on investigation skills, solid understanding of digital forensics, and the ability to trace suspicious activity across endpoints, networks, cloud services, identity systems, and business applications. The analyst will work closely with SecOps engineers, security architects, network security experts, R&D, IT, and other stakeholders to ensure threats are detected, investigated, and handled effectively.
Key Responsibilities
·Advanced SOC Monitoring & Event Analysis
oMonitor security events, alerts, logs, and telemetry across SIEM, XDR/EDR, identity, network, cloud, endpoint, email, and other enterprise security platforms.
oPerform advanced investigation and triage of security alerts, validate incidents, reduce false positives, and determine severity, scope, business impact, and required response actions.
oAnalyze suspicious activities, attack indicators, anomalies, and behavioral patterns to identify potential threats and clarify whether events represent real security incidents.
oConduct detailed investigations using existing security tools and data sources, including logs, endpoint telemetry, network traffic, identity events, email traces, cloud activity, and threat intelligence.
oEscalate confirmed incidents, recommend containment and remediation steps, and support incident response activities in collaboration with SecOps engineers and relevant technical teams.
oDocument investigation findings, evidence, timelines, root cause, affected assets, response actions, and lessons learned in a clear and structured manner.
oPlay a key role in maintaining visibility into suspicious activities and ensuring the company can detect, trace, investigate, and respond to security incidents effectively.
·SIEM, Automation & Detection Engineering
oImprove the SIEM platform by tuning alerts, creating and maintaining correlation rules, enhancing use cases, improving log source coverage, and increasing detection accuracy.
oDesign, recommend, and implement detection improvements based on incidents, threat intelligence, attack techniques, gaps in visibility, and operational lessons learned.
oContribute experience and practical guidance toward the implementation of SOAR capabilities, including playbook design, automation use cases, alert enrichment, case management, and response workflows.
·Incident Investigation, Forensics & Threat Hunting
oLead deep-dive investigations of confirmed or suspected incidents, including endpoint, network, identity, cloud, and application-related security events.
oApply digital forensics knowledge to preserve and analyze evidence, reconstruct attack timelines, understand attacker behavior, and support root-cause analysis.
oPerform threat hunting activities to proactively identify suspicious behavior, weak detection areas, persistence mechanisms, lateral movement, privilege misuse, and data exposure indicators.
oWork with SecOps engineers, security architects, network security experts, IT, R&D, cloud, and application teams to validate findings and coordinate containment, remediation, and control improvements.
oTranslate investigation outcomes into improved detection logic, response procedures, playbooks, dashboards, and security monitoring coverage.
·Automation, Improvement & Collaboration
oUse and improve existing security tools, while proposing practical ideas, enhancements, new detection use cases, and automation opportunities to improve SOC effectiveness.
oCollaborate with SecOps and security architecture teams on new tool implementations, onboarding of log sources, integration design, alert enrichment, response automation, and future SOAR platform planning.
oContinuously improve detection and handling processes by measuring alert quality, investigation efficiency, coverage gaps, incident trends, and lessons learned from real events.
Qualifications
o5+ years of hands-on experience in SOC operations, incident investigation, security monitoring, threat detection, SIEM operations, security automation, digital forensics, or enterprise security operations.
oProven experience working as an advanced SOC analyst, Tier 2/Tier 3 analyst, incident responder, detection analyst, or similar role in complex enterprise environments.
oDeep technical knowledge of SIEM, XDR/EDR, log analysis, endpoint telemetry, identity security, network security, cloud security, email security, threat intelligence, security automation, and incident response processes.
oStrong experience analyzing logs, alerts, events, and telemetry from multiple sources to validate incidents, identify attack patterns, and determine appropriate response actions.
oHands-on experience with incident response, threat investigation, containment recommendations, root-cause analysis, attack timeline reconstruction, and post-incident improvement.
oSolid understanding of digital forensics concepts, evidence handling, endpoint investigation, malware behavior, persistence techniques, lateral movement, and attacker tactics, techniques, and procedures.
oExperience creating, tuning, and improving SIEM correlation rules, detection use cases, dashboards, alert logic, and monitoring coverage.
oExperience with security automation, playbook design, alert enrichment, case management concepts, workflow improvement, and supporting or driving SOAR implementation initiatives.
oAbility to write clear investigation summaries, incident reports, detection documentation, playbooks, runbooks, and operational recommendations.
oHands-on experience investigating Windows, Linux, endpoint, server, cloud, identity, and network-based security events.
oHands-on experience with SIEM, XDR, EDR, CASB, DLP, email security, vulnerability data, threat intelligence platforms, log management tools, and security automation technologies.
oExperience with monitoring, automation, orchestration, scripting, query languages, and workflow optimization.
oExperience working with R&D, infrastructure, network security, SecOps, and architecture teams in high-scale technical environments.

Radware is a global leader of application security and delivery solutions for multi-cloud environments. The company’s cloud application, infrastructure, and API security solutions use AI-driven algorithms for precise, hands-free, real-time protection from the most sophisticated web, application, and DDoS attacks, API abuse, and bad bots. Radware solutions empower more than 10,000 enterprise and carrier customers worldwide to adapt to market challenges quickly, maintain business continuity and achieve maximum productivity while keeping costs down. Radware’s corporate headquarters are located in the U.S. (Mahwah, NJ) and international headquarters are located in Tel Aviv. Global presence includes offices in the Americas, Europe, Middle East, Africa and Asia Pacific regions.