- Location
- India
- Type
- Full-time
- Department
- Security
- Experience
- 3+ years
- Education
- Master
- Closing date
- Today
- Source
- Workday
Description
Company Overview
Join us on our mission to elevate customer experiences for people around the world. As a member of the Everise family, you will be part of a global experience company that believes in being people-first, celebrating diversity and incubating innovation. Our dedication to our purpose and people is being recognized by our employees and the industry. Our 4.6/5 rating on Glassdoor and our shiny, growing wall of Best Place to Work awards is a testament to our investment in our culture. Through the power of diversity, we celebrate all cultures for their uniqueness and strengths. With 13 centers around the world and a robust work at home program, we believe great things happen when we work with people who think differently from us. Find a job you’ll love today!
Core responsibilities across SOC monitoring, VAPT execution, and evidence management include the following:
- Monitor SOC queues and investigate alerts from Managed SOC/SIEM, endpoint, identity, email-security, DLP, VPN/proxy and endpoint-compliance sources.
- Enrich SOC alerts using user, device, IP, ASN, geo-location, application, timestamp, IOC, endpoint posture, related tickets and historical evidence.
- Document investigations with working notes, screenshots, containment status, closure rationale, ticket updates and shift handover notes.
- Execute scheduled and ad hoc vulnerability scans for infrastructure and applications; validate findings before escalation.
- Perform web application and API security testing under defined scope; mobile application testing is excluded unless separately assigned in the future.
- Review SAST/DAST findings, assist with secure-code review and coordinate with application/development owners for remediation evidence.
- Track vulnerability remediation and retesting in ServiceNow or approved workflow tools; maintain clean closure, retest and exception evidence.
- Support containment actions including account disablement, device freeze/quarantine/isolation, suspicious-session review, user outreach and restoration evidence.
- Prepare SOC monitoring inputs and VAPT status inputs including open vulnerabilities, overdue remediation, retest outcomes, repeat findings and escalation items.
- Provide security evidence from SOC/VAPT work when requested for audit/client/security review; do not own GRC program activities.
- Ensure SOC alerts are triaged consistently with evidence, classification, escalation notes and closure rationale (success measure).
- Validate, document and track infrastructure, web/API and SAST/DAST findings through remediation or retest (success measure).
- Escalate high-risk identity, endpoint, email, DLP, vulnerability and VPN/proxy events without delay (success measure).
- Maintain ServiceNow/security tickets that are complete, evidence-backed and aligned to SOC/VAPT operating expectations (success measure).
Attributes & Attitude
- Hands-on investigative mindset with the discipline to perform practical triage and testing, not only ticket monitoring or scanner-output forwarding.
- Strong escalation discipline — knows when and how to escalate to Consultant/InfoSec lead, IT Ops, GSD, Endpoint, Development, HR/Ops, TAM or Legal based on severity and impact.
- Meticulous evidence and retesting hygiene, consistently capturing screenshots, timestamps, tool outputs, reproduction steps and closure comments.
- Clear, business-formal written communication for incident notes, vulnerability findings, remediation follow-ups and shift handovers.
- Comfortable operating across a hybrid scope — balancing SOC alert response with VAPT execution within the same role.
- Collaborative approach when coordinating with application/development owners, IT Ops and cross-functional teams on remediation evidence.
- Ownership and accountability for closure quality, without extending into GRC program ownership.
- Adaptable and detail-oriented, able to brief a Consultant/InfoSec lead with concise facts and risk indicators.
Knowledge
Qualifications: Minimum 3-5 years of experience and working knowledge across the following areas:
- SOC Operations: 3-5 years in SOC, MDR, InfoSec operations, endpoint security, vulnerability management or security monitoring support; BPO, healthcare, PCI or client-regulated environment exposure preferred.
- Vulnerability Assessment: Ability to run scans, validate vulnerabilities, capture evidence, prepare remediation notes and support retesting; Nessus/Qualys/OpenVAS and ServiceNow remediation tracking experience preferred.
- Web/API Testing: Working knowledge of OWASP Top 10, web/API testing methodology and manual validation using Burp Suite or OWASP ZAP; experience preparing concise technical finding write-ups preferred.
- SAST/DAST/Code Review: Ability to review tool findings, understand vulnerable code patterns and coordinate with developers under senior guidance; familiarity with SonarQube, Snyk, Semgrep, Checkmarx, Veracode or Fortify preferred.
- Communication and Evidence: Clear business-formal writing for incident notes, vulnerability findings, remediation follow-ups and shift handovers; able to brief a Consultant/InfoSec lead with concise facts and risk indicators.
- SIEM/MDR Tooling: Arctic Wolf/Aurora, Microsoft Sentinel or equivalent SIEM, Splunk/QRadar fundamentals, ServiceNow ticketing and IOC enrichment workflows.
- Identity/Endpoint Tooling: Microsoft Entra ID, Conditional Access, MFA, Defender for Endpoint, FortiEDR, Absolute, Intune/JamF, BitLocker/FileVault and endpoint evidence capture.
- Email/DLP Tooling: Abnormal AI / O365 email security, Microsoft Purview DLP, phishing/BEC/ATO investigation queues and remediation evidence.
- Network Vulnerability Tools: Nessus, Qualys, OpenVAS, Nmap, basic Metasploit validation, Wireshark and SSL/TLS testing tools.
- AD/Windows Exposure Awareness: BloodHound, PingCastle and NetExec/CrackMapExec awareness for privilege path, misconfiguration and exposure validation under supervision.
- Web/API Testing Tools: Burp Suite, OWASP ZAP, Postman, API collections and manual validation for authentication, authorization, session and input-handling issues.
- SAST Tools: Checkmarx, Veracode, SonarQube, Fortify, Snyk, Semgrep or equivalent; ability to read code paths and identify likely vulnerable patterns.
- DAST Tools: Burp Suite, OWASP ZAP, Acunetix, Invicti/Netsparker, AppScan or equivalent; validate output before raising remediation tickets.
- Cloud Security Basics: Microsoft Defender for Cloud / Azure posture review basics, AWS exposure awareness, Prowler/ScoutSuite-style output interpretation where applicable.
- Connectivity Context: FortiSASE, FortiGate, VPN, IPQS/IP2Proxy or equivalent tools for VPN/proxy/geolocation validation.
- Desirable Certifications: eJPT / PNPT / CEH Practical, CompTIA PenTest+ / Security+ / CySA+, Burp Suite certification or web testing training, Splunk Core / SIEM fundamentals — all Good to Have.
If you’ve got the skills to succeed and the motivation to make it happen, we look forward to hearing from you.