Kaplan is a global, for-profit education company that has excelled and expanded over the years, now operating in over 30 countries worldwide. The company offers
Threat Detection and Response Analyst II
Location
India
Posted
56 days ago
Salary
0
Seniority
Senior
Job Description
Threat Detection and Response Analyst II
Kaplan
Threat Detection and Response Analyst II (Hybrid) Location: Bangalore, KA, India Hybrid Full time Job Description For more than 80 years, Kaplan has been a trailblazer in education and professional advancement. We are a global company at the intersection of education and technology, focused on collaboration, innovation, and creativity to deliver a best in class educational experience and make Kaplan a great place to work. Our offices in India opened in Bengaluru in 2018. Since then, our team has fueled growth and innovation across the organization, impacting students worldwide. We are eager to grow and expand with skilled professionals like you who use their talent to build solutions, enable effective learning, and improve students' lives. The future of education is here and we are eager to work alongside those who want to make a positive impact and inspire change in the world around them. The Threat Detection and Response Analyst II is a foundational member of the security team, serving as the first line of defense against cyber threats. This role is responsible for monitoring security alerts, performing initial analysis, and escalating potential incidents. Additionally, this role will assist in refining security detections and participate in guided threat hunting activities to proactively identify threats and protect organizational assets. Primary/Key Responsibilities - Alert Monitoring & Triage: Perform real-time monitoring of security alerts from tools like SIEM and EDR. Conduct initial triage of alerts using established procedures and playbooks to determine if they are true or false positives. - Initial Investigation: Analyze security events to gather essential information and context. Use security tools to investigate indicators of compromise (IOCs) and anomalous activity. - Incident Escalation: Escalate validated security incidents to Senior Level or higher analysts for in-depth investigation and response. Provide clear and concise information to support the incident response process. - Detection Engineering Support: Assist senior analysts in tuning and optimizing existing security alerts. Provide feedback on alert fidelity from a front-line perspective to help reduce false positives and improve the accuracy of detection rules. - Guided Threat Hunting: Participate in structured threat hunting missions based on hypotheses and threat intelligence provided by senior team members. Use security tools to search for evidence of specific tactics, techniques, and procedures (TTPs) within the environment. - Documentation: Create and maintain detailed tickets for all monitored alerts and escalated incidents. Document findings from threat hunting activities for further analysis. - Hybrid Schedule: 3 days remote / 2 days in office - 30-day notification period preferred Minimum Qualifications - Bachelor's Degree in Information Systems, Engineering, IT, Computer Science, Cybersecurity, or a related field. Equivalent alternative education, skills, and/or practical experience is also acceptable. - 4+ years of experience in an IT, help desk, or cybersecurity role. Experience gained through internships or relevant coursework is also considered. - Basic understanding of common attack techniques and the MITRE ATT&CK framework. - Familiarity with navigating security dashboards (e.g., SIEM, EDR) to review alerts, log analysis, rule creation, and dashboarding. - Foundational knowledge of network protocols, operating systems (Windows, Linux), and cloud environments (AWS, Azure, GCP) - Familiarity with ability to perform root cause identification and remediation planning/tracking. - Basics of SIEM query languages (e.g., SPL, KQL) to search logs. - Strong attention to detail with an inquisitive and analytical mindset. - Excellent written and verbal communication skills for documenting and escalating issues. Preferred Qualifications - Relevant entry-level security certifications (e.g., CompTIA Security+, CySA+). - Familiarity with scripting languages (e.g., Python, PowerShell) for automation and analysis. - Familiarity with SOAR platforms and developing automation playbooks. - Exposure to cloud security monitoring and incident response in cloud environments. - Exposure to regulatory compliance requirements (e.g., SOX, PCI DSS) as they relate to vulnerability management. - Exposure to security frameworks and standards (e.g., NIST, ISO 27001, CIS Benchmarks). Beyond base salary, our comprehensive total rewards package includes: Hybrid work model provides a flexible work/life balance Voluntary Provident Fund is an additional voluntary contribution scheme associated with the statutory Employee Provident Fund (EPF) Our Gift of Knowledge Program provides tuition assistance and substantial discounts for our employees and close family members Comprehensive health benefits new hire eligibility starts on day 1 of employment Generous Paid Time Off includes National holidays(10), Earned leaves(15), sick leave(12), plus one (1) volunteer day to participate and give back to our local communities Gratuity is applicable upon completion of 5 years as per the Gratuity Act We are committed to providing a supportive and rewarding work environment where every employee can thrive. At Kaplan, we believe in attracting, rewarding, and retaining exceptional talent. Our compensation philosophy is designed to be competitive within the market, reflecting the value we place on the skills, experience, and contributions of our employees, while taking into account labor market trends and total rewards. The specific compensation offered will be determined by a variety of factors, including but not limited to the candidate's qualifications, relevant experience, education, skills, and market data. Location Bangalore, KA, India Additional Locations Employee Type Employee Job Functional Area Information Security Business Unit 00091 Kaplan Higher ED Diversity & Inclusion Statement: Kaplan is committed to cultivating an inclusive workplace that values diversity, promotes equity, and integrates inclusivity into all aspects of our operations. We are an equal opportunity employer and all qualified applicants will receive consideration for employment regardless of age, race, creed, color, national origin, ancestry, marital status, sexual orientation, gender identity or expression, disability, veteran status, nationality, or sex. We believe that diversity strengthens our organization, fuels innovation, and improves our ability to serve our students, customers, and communities. Learn more about our culture here. Kaplan considers qualified applicants for employment even if applicants have an arrest or conviction in their background check records. Kaplan complies with related background check regulations, including but not limited to, the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. There are various positions where certain convictions may disqualify applicants, such as those positions requiring interaction with minors, financial records, or other sensitive and/or confidential information. Kaplan is a drug-free workplace and complies with applicable laws.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Senior Cybersecurity Incident Response Analyst
IQVIAIQVIA is a publicly-traded healthcare intelligence company founded in 2016 upon the merger of two market leaders: Quintiles and IMS Health. With locations aroun
• Respond to alerted security events with expert analysis • Operate security controls and platforms including firewalls, EDR, intrusion prevention • Identify and analyze logs, artifacts, and evidence • Secure and preserve evidence using sound handling practices • Coordinate with internal and external stakeholders to support forensics and investigation processes • Propose and implement improvements to technical safeguards • Develop and document operational procedures and metrics
Principal Technical Consultant - SecOps & IRM
ServiceNowAs the AI platform for business transformation, we're putting AI to work across organizations — freeing people for work that matters. Making old tech work with new tech. Reaching across departments, from the front office to the back office and every office in between. Our ambition? To become the AI defining enterprise software company of the 21st century (or "AI DESCO21C," as we like to call it). With more than 8,400+ customers, we serve approximately 90% of the Fortune 500®, and we're proud to be a Fortune 100 Best Companies to Work For® and World's Most Admired Companies™. Explore your future career with us, visit www.careers.servicenow.com From Fortune. ©2026 Fortune Media IP Limited. All rights reserved. Used under license.
Company Description It all started in sunny San Diego, California in 2004 when a visionary engineer, Fred Luddy, saw the potential to transform how we work. Fast forward to today — ServiceNow stands as a global market leader, bringing innovative AI-enhanced technology to over 8,100 customers, including 85% of the Fortune 500®. Our intelligent cloud-based platform seamlessly connects people, systems, and processes to empower organizations to find smarter, faster, and better ways to work. But this is just the beginning of our journey. Join us as we pursue our purpose to make the world work better for everyone. Job Description Project Delivery - Act as the primary technical liaison for projects, representing the development team to customers and ensuring the highest quality of delivered solutions. - Oversee technical delivery, ensuring alignment with client requirements and ServiceNow best practices for SecOps implementations. - Define and architect technical solutions at a detailed level, ensuring they align with clients' business needs and technological environments. - Lead technical onboarding with clients, assessing existing processes and platform configurations to tailor solutions effectively. - Perform hands on development on the ServiceNow platform leveraging all ServiceNow technologies and capabilities; Flow Designer, REST, JavaScript, HTML, CSS, SSO, Mid-servers, and more. - Serve as an escalation point for technical issues, implementing efficiencies and driving resolution of critical path challenges. - Mentor and guide developers and consultants on best practices in technical design and SecOps management workflows. Pre-Sales Support - Partner with the pre-sales team to scope complex service engagements involving ServiceNow products and intricate integrations with client systems, with a focus on SecOps and Integrated Risk Management (IRM) - Demonstrate thought leadership by contributing to webinars, white papers, and community groups, highlighting expertise in SecOps and Integrated Risk Management (IRM) Product Collaboration - Engage with ServiceNow product teams to provide feedback and insights on new features, capabilities, and best practices. - Participate in go-to-market strategies for new service offerings, ensuring alignment with Security Operations management trends and customer needs. Qualifications Qualifications Experience: Several years experience in consulting, configuration, and implementation of complex technologies, with at least 2 years focused on enterprise architecture and technical roadmaps. SecOps Expertise: Proven track record in designing and implementing SecOps solutions, with a solid understanding of industry-specific workflows, use cases, compliance requirements, and best practices. IRM Expertise: Proven experience in defining and deploying future-state leading practice for GRC processes and in identifying solutions from a people, process, and technology perspective. Strong understanding and experience with leading IRM toolsets such as ServiceNow, RSA Archer, IBM OpenPages, MetricStream, and BWise. Domains: Security Operations, Enterprise Security, Security Incident Response, Vulnerability Management, Threat Intelligence, Event Management, Integrated Risk Management, Leadership Skills: Ability to influence senior leaders and stakeholders, providing clear recommendations that address business and technical challenges in SecOps contexts. Technical Skills: Proficiency in creating architectural designs, solution presentations, and integration strategies, particularly within SecOps environments. Experience with Web Technologies (XML, HTML, JavaScript, Web Services, Bootstrap, CSS, middleware, LDAP, SSO, etc.) and working with SaaS technologies Certifications: Must hold or be able to achieve within the first 90 days ServiceNow certifications for SecOps Implementation Specialist, and Certified Technical Architect within the first year. Language: Fluent in English Additional Information Work Personas We approach our distributed world of work with flexibility and trust. Work personas (flexible, remote, or required in office) are categories that are assigned to ServiceNow employees depending on the nature of their work and their assigned work location. Learn more here. To determine eligibility for a work persona, ServiceNow may confirm the distance between your primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, national origin or nationality, ancestry, age, disability, gender identity or expression, marital status, veteran status, or any other category protected by law. In addition, all qualified applicants with arrest or conviction records will be considered for employment in accordance with legal requirements. Accommodations We strive to create an accessible and inclusive experience for all candidates. If you require a reasonable accommodation to complete any part of the application process, or are unable to use this online application and need an alternative method to apply, please contact [email protected] for assistance. Export Control Regulations For positions requiring access to controlled technology subject to export control regulations, including the U.S. Export Administration Regulations (EAR), ServiceNow may be required to obtain export control approval from government authorities for certain individuals. All employment is contingent upon ServiceNow obtaining any export license or other approval that may be required by relevant export control authorities. From Fortune. ©2025 Fortune Media IP Limited. All rights reserved. Used under license. - Employee Type: Regular - Region: EMEA - Europe, Middle East and Africa - Work Persona: Flexible or Remote
Company Description Arista Networks is an industry leader in data-driven, client-to-cloud networking for large data center, campus and routing environments. What sets us apart is our relentless pursuit of innovation. We leverage the latest advancements in cloud computing, artificial intelligence, and software-defined networking to provide our clients with a competitive edge in an increasingly interconnected world. Our solutions are designed to not only meet the current demands of the digital landscape but to also anticipate and adapt to future challenges. At Arista we value the diversity of thought and perspectives that each employee brings to the table. We believe that fostering an inclusive environment, where individuals from various backgrounds and experiences feel welcome, is essential for driving creativity and innovation. Our commitment to excellence has earned us several prestigious awards, such as Best Engineering Team, Best Company for Diversity, Compensation, and Work-Life Balance. At Arista, we take pride in our track record of success and strive to maintain the highest standards of quality and performance in everything we do. Job Description Who You’ll Work With We are seeking a highly motivated and proactive Security Operations Center (SOC) Analyst to join our dynamic, remote cybersecurity team. The ideal candidate is a critical thinker, self-starter, and driven professional with hands-on experience using Crowdstrike or other EDRs. You will play a critical role in monitoring, triaging, and responding to cyber threats across our primarily Mac and Linux environments, with some Windows systems. You will work closely with a collaborative team of fellow SOC analysts, incident responders, threat hunters, and cross-functional partners across IT, engineering, and DevOps to ensure our security posture remains strong. We’re looking for someone who takes ownership, excels in high-pressure settings, and is skilled in writing CrowdStrike Query Language (CQL) (or similar) to create effective detections that protect our organization’s assets. What You’ll Do - Monitor and triage security alerts. - Build, test, and refine detections to enhance threat identification across Mac, Linux, and Windows systems. - Conduct in-depth analysis of security incidents, including malware, phishing, and advanced persistent threats, leveraging SIEM and EDR capabilities. - Perform proactive threat hunting using the SIEM and EDR features. - Investigate and respond to incidents swiftly, following established incident response protocols. - Document findings clearly and provide actionable remediation recommendations. - Collaborate with cross-functional teams to strengthen security controls and mitigate vulnerabilities. - Stay current on emerging threats, vulnerabilities, and industry trends through self-directed learning. - Participate in on-call rotation for 24x7x365 SOC coverage, demonstrating reliability and accountability. - Escalate confirmed or suspicious incidents and cases to the Incident Response team. Qualifications - 4-5+ years in a SOC and or active participant on incident response teams. - Hands-on experience with CrowdStrike (or other EDR), triaging security incidents. - Proven ability to write CQL (or similar) queries and build detections for threat monitoring. - Experience triaging alerts in a high-volume environment. - Experience with threat intelligence feeds, platform and OSINT tools (VirusTotal, etc.) - Familiarity with forensic analysis and evidence handling. Skills and Attributes: - Exceptional critical thinking and analytical skills to address complex security challenges. - Self-starter with a proven ability to take initiative and deliver results independently. - Driven mindset, thriving in fast-paced, high-pressure remote work environments. - Strong understanding of cybersecurity principles, threat landscapes, and attack vectors. - Proficiency in analyzing logs, network traffic, and endpoint data using CrowdStrike Next-Gen SIEM, particularly for Mac and Linux systems (Windows experience a plus). - Solid knowledge of incident response processes and methodologies. - Familiarity with operating systems, with primary expertise in Mac and Linux, and secondary knowledge of Windows. - High attention to detail and ability to make sound decisions under pressure. - Demonstrated commitment to continuous learning and professional development in cybersecurity. Nice-to-Have: - Write and optimize detections to detect and investigate security events. - Proficiency in scripting (e.g., Python) for automating SOC workflows. - Experience creating playbooks in Crowdstrike Fusion SOAR (or similar SOAR) - Knowledge of cloud security (GCP, AWS, and or Azure). - Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field (or equivalent experience). #LI-SZ1 Additional Information Arista stands out as an engineering-centric company. Our leadership, including founders and engineering managers, are all engineers who understand sound software engineering principles and the importance of doing things right. We hire globally into our diverse team. At Arista, engineers have complete ownership of their projects. Our management structure is flat and streamlined, and software engineering is led by those who understand it best. We prioritize the development and utilization of test automation tools. Our engineers have access to every part of the company, providing opportunities to work across various domains. Arista is headquartered in Santa Clara, California, with development offices in Australia, Canada, India, Ireland, and the US. We consider all our R&D centers equal in stature. Join us to shape the future of networking and be part of a culture that values invention, quality, respect, and fun.
Specialist, Infrastructure Operations
AllianzAllianz is a financial services company that provides insurance and finance products and services to over 85 million customers. Through its network of businesse
Title: Specialist-Infrastructure Operations_D-2318 Location: India United States Job Description: Tools Proficiency: Expertise in common tools such as ServiceNow, Jira, Confluence, SAP Office365 Services, Active Directory, Entra-ID, NetIQ Identity Manager, One Identity Manager, CIS Security Standards and Practices: Understanding of security frameworks like ISO 27001, NIST, and best practices for network security as well as GISF Lifecycle Management: Knowledge of HR lifecycle management and end-of-life processes. Collaboration: Strong interpersonal skills to work effectively with international teams and stakeholders. Supportive Attitude. Stakeholder Engagement. Communication Skills (English): Ability to communicate technical information clearly and understandably, both in writing and verbally. Cultural Awareness: Sensitivity to work in a diverse and multicultural environment. Qualifications - Bachelor's degree in Computer Science, Information Security, or a related field. Master's degree preferred. - Minimum of 5 years of experience in Identity and Access Management. Your benefits: - We offer a hybrid work model which recognizes the value of striking a balance between in-person collaboration and remote working incl. up to 25 days per year working from abroad - We believe in rewarding performance and our compensation and benefits package includes a company bonus scheme, pension, employee shares program and multiple employee discounts (details vary by location) - From career development and digital learning programs to international career mobility, we offer lifelong learning for our employees worldwide and an environment where innovation, delivery and empowerment are fostered - Flexible working, health and wellbeing offers (including healthcare and parental leave benefits) support to balance family and career and help our people return from career breaks with experience that nothing else can teach About Allianz Technology Allianz Technology is the global IT service provider for Allianz and delivers IT solutions that drive the digitalization of the Group. With more than 11,000 employees located in 20 countries around the globe, Allianz Technology works together with other Allianz entities in pioneering the digitalization of the financial services industry.We oversee the full digitalization spectrum - from one of the industry's largest IT infrastructure projects that includes data centers, networking and security, to application platforms that span from workplace services to digital interaction. In short, we deliver full-scale, end-to-end IT solutions for Allianz in the digital age. D&I statement Allianz Technology is proud to be an equal opportunity employer encouraging diversity in the working environment. We are interested in your strengths and experience. We welcome all applications from all people regardless of gender identity and/or expression, sexual orientation, race or ethnicity, age, nationality, religion, disability, or philosophy of life.




