Bloomreach logo
Bloomreach

Bloomreach is a computer software company that is on a mission to empower its clients to seamlessly personalize their customer experience and, in turn, successfully grow their busi

Associate Security Analyst

Location

India

Posted

50 days ago

Salary

0

Seniority

Mid Level

Job Description

Associate Security Analyst

Bloomreach

Bloomreach is building the world’s premier agentic platform for personalization.We’re revolutionizing how businesses connect with their customers, building and deploying AI agents to personalize the entire customer journey. - We're taking autonomous search mainstream, making product discovery more intuitive and conversational for customers, and more profitable for businesses. - We’re making conversational shopping a reality, connecting every shopper with tailored guidance and product expertise — available on demand, at every touchpoint in their journey. - We're designing the future of autonomous marketing, taking the work out of workflows, and reclaiming the creative, strategic, and customer-first work marketers were always meant to do. And we're building all of that on the intelligence of a single AI engine — Loomi AI — so that personalization isn't only autonomous…it's also consistent.From retail to financial services, hospitality to gaming, businesses use Bloomreach to drive higher growth and lasting loyalty. We power personalization for more than 1,400 global brands, including American Eagle, Sonepar, and Pandora. Join the Bloomreach GIST (Global Information Security & Technology) team as an Associate Security Analyst and help protect our e-commerce environment from threats, vulnerabilities, and sophisticated attackers. Your work will have a significant impact on numerous customers across various e-commerce verticals and hundreds of millions of online users. As a core member of our globally distributed 24/7 Security Operations Team, you can work full-time from our India offices or from home. Your job will be (but not limited to) ● To Monitor, analyze & interpret security/system/application/infrastructure logs for events, configuration irregularities & potential incidents ● To leverage security tools, custom built dashboards and/or proactive identification approaches to detect anomalous activities ● Monitoring Cloud infrastructure for security-related events ● Monitoring threat/vulnerability landscape and security advisories, coordinate and escalate as appropriate ●To work with application security teams, product specialists, GRC, legal teams on active incidents and/or investigations ● To participate in a major incident call, document incident report summaries ● To document, follow and execute standard operating procedures (SOPs) ● Documenting/Managing/maintaining & following use cases, playbooks and/or knowledge base articles ● To work on incidents, requests related to security ● Owning responsibilities within a shift with a positive mindset towards growth & upskilling Professional experience, skills & requirements ● 2+ years of hands on experience as part of a 24*7 Security Operations team OR a starter with equivalent degree/specialization in the area of Cyber Security with a proven project dealing in the new age landscape (SaaS platform Security, SecOps, API/Container Security, Threat Intel/Hunting, Vulnerability Management). ● Hands on experience or deep knowledge on usage of SIEM, SOAR, EDR ( modules like TI, VM, DLP) ● Exposure or experience in using any of CSPM tools (SentinelOne, Falcon Horizon, Wiz,Sysdig,Prisma cloud,MS Defender) ● Exposure or experience in assessing, interpreting & managing vulnerabilities using relevant tools. ● Knowledge of either AWS or GCP is must ● Should possess positive attitude to participate, own & drive tasks for POCs for various tools ● Understanding of risk framework ● Ability to assess emerging trends & threats in cyber security space ● Should possess good analytical, problem-solving, and interpersonal skills. Should be able to apply & provide logical reasoning ● Knowledge of NIST framework, OSINT standards, MITRE ATT&CK framework & cybersecurity incident lifecycle is an advantage. Beginner level of understanding is mandatory ● Mandatory to work in a 24/7 rotation shift & weekends ● Possess excellent command on communication in English being a good listener, speaker & reader Your success story will be: In the first 30 days you will ● Understand the roles & responsibilities of SOC team, in-scope vs out of scope tasks ● Read & understand SOPs, Policies & working procedures of the team ● Shadow peers in day to day work, overlook tickets, alerts, incidents, understand the current state of ongoing projects/enhancements etc In the next 30 days you will (60 days from start) ● Start owning incidents, tasks as independent contributor with a peer shadowing you ● Participate in incident related calls, cross team/department meetings ● Handle SIEM/SOAR/EDR events In the next 30 days you will(90 days from start) ● You will start documenting or tweaking existing SOPs, process document ● You will bear responsibilities of representing team in forums/meetings/discussions ● You will start managing shift alone when needed ● You will adapt yourself to service improvement mindset and contribute to overall success of the team More things you'll like about Bloomreach: Culture: - A great deal of freedom and trust. At Bloomreach we don’t clock in and out, and we have neither corporate rules nor long approval processes. This freedom goes hand in hand with responsibility. We are interested in results from day one. - We have defined our 5 values and the 10 underlying key behaviors that we strongly believe in. We can only succeed if everyone lives these behaviors day to day. We've embedded them in our processes like recruitment, onboarding, feedback, personal development, performance review and internal communication. - We believe in flexible working hours to accommodate your working style. - We work virtual-first with several Bloomreach Hubs available across three continents. - We organize company events to experience the global spirit of the company and get excited about what's ahead. - We encourage and support our employees to engage in volunteering activities - every Bloomreacher can take 5 paid days off to volunteer*. - The Bloomreach Glassdoor page elaborates on our stellar 4.4/5 rating. The Bloomreach Comparably page Culture score is even higher at 4.9/5 Personal Development: - We have a People Development Program -- participating in personal development workshops on various topics run by experts from inside the company. We are continuously developing & updating competency maps for select functions. - Our resident communication coach Ivo Večeřa is available to help navigate work-related communications & decision-making challenges.* - Our managers are strongly encouraged to participate in the Leader Development Program to develop in the areas we consider essential for any leader. The program includes regular comprehensive feedback, consultations with a coach and follow-up check-ins. - Bloomreachers utilize the $1,500 professional education budget on an annual basis to purchase education products (books, courses, certifications, etc.)* Well-being: - The Employee Assistance Program -- with counselors -- is available for non-work-related challenges.* - Subscription to Calm - sleep and meditation app.* - We organize ‘DisConnect’ days where Bloomreachers globally enjoy one additional day off each quarter, allowing us to unwind together and focus on activities away from the screen with our loved ones. - We facilitate sports, yoga, and meditation opportunities for each other. - Extended parental leave up to 26 calendar weeks for Primary Caregivers.* Compensation: - Restricted Stock Units or Stock Options are granted depending on a team member’s role, seniority, and location.* - Everyone gets to participate in the company's success through the company performance bonus.* - We offer an employee referral bonus of up to $3,000 paid out immediately after the new hire starts. - We reward & celebrate work anniversaries -- Bloomversaries!* (*Subject to employment type. Interns are exempt from marked benefits, usually for the first 6 months.) Excited? Join us and transform the future of commerce experiences! If this position doesn't suit you, but you know someone who might be a great fit, share it - we will be very grateful! Any unsolicited resumes/candidate profiles submitted through our website or to personal email accounts of employees of Bloomreach are considered property of Bloomreach and are not subject to payment of agency fees. #LI-Remote

Related Job Pages

More Security Analyst Jobs

Remote World logo

Cybersecurity Analyst

Remote World

Model N is the leader in revenue optimization and compliance for pharmaceutical, medtech, and high-tech innovators. For more than 25 years, we have helped customers maximize revenue, streamline operations, and maintain compliance through cloud-based software, value-added services, and data-driven insights. With a focus on innovation and customer success, Model N empowers life sciences and high-tech manufacturers to bring life-changing products to the world more efficiently and profitably. Model N is trusted by over 150 of the world’s leading companies across more than 120 countries. For more information, visit www.modeln.com.

Security Analyst50 days ago

Role Description We are hiring a Cybersecurity Analyst to monitor, detect, and respond to security threats. You will play a vital role in safeguarding our infrastructure, data, and users. Key Responsibilities - Monitor security alerts and investigate potential incidents. - Conduct vulnerability assessments and penetration testing. - Implement and maintain security tools and controls. - Develop and improve incident response procedures. - Educate internal teams on security best practices. Qualifications - 2+ years of cybersecurity experience. - Familiarity with SIEM tools, IDS/IPS, and firewalls. - Understanding of OWASP, NIST, or ISO 27001 frameworks. - Experience with threat modelling and risk assessment. - Security certifications (CISSP, CEH, CompTIA Security+) are a plus.

India
Job Closed
Full TimeRemoteTeam 10,001+Since 1878H1B Sponsor

• Analisar indicadores de SST • Elaborar relatórios e dashboards • Apoiar auditorias e planos de ação • Monitorar desempenho e identificar tendências • Contribuir com melhorias nos processos de segurança

Brazil
Full TimeRemoteTeam 501-1,000Since 1999H1B No Sponsor

• Identificar e analisar ciberameaças em fontes abertas e fechadas, incluindo dark web e fóruns especializados, utilizando ferramentas OSINT e soluções de monitoramento. • Realizar análises de inteligência por meio da avaliação de ciberataques, fraudes, phishing, ransomware e outros eventos de interesse, atribuindo atores de ameaça e documentando suas táticas, técnicas e procedimentos (TTP). • Elaborar relatórios de inteligência de ameaças, avaliações de risco e recomendações, voltados para apoiar a tomada de decisões dos clientes. • Correlacionar indicadores de comprometimento (IoC) e artefatos técnicos provenientes de múltiplas fontes para identificar padrões de atividade maliciosa e possíveis exposições. • Gerenciar e manter atualizadas as informações de inteligência na plataforma de threat intelligence da SEK, incluindo o carregamento, normalização e relacionamento de indicadores, atores de ameaça, campanhas e malware. • Estruturar e analisar as informações coletadas utilizando frameworks de referência como MITRE ATT&CK, facilitando sua compreensão e reutilização por outras equipes técnicas. • Apoiar investigações de segurança fornecendo contexto de inteligência sobre atores de ameaça, campanhas e técnicas utilizadas em incidentes relevantes. • Avaliar a confiabilidade e relevância das fontes utilizadas nas investigações de inteligência. • Colaborar em investigações junto a outras equipes da SEK para enriquecer a análise e a compreensão das ameaças. • Contribuir para a geração e manutenção de coleções de inteligência, datasets ou feeds que permitam melhorar o monitoramento contínuo de ameaças. • Otimizar fluxos de trabalho e propor melhorias ou automações que permitam escalar as capacidades de análise e investigação. • Manter atualizada a base de conhecimento interna e contribuir com a geração de conteúdo técnico, como blogs ou artigos especializados.

Brazil
Job Closed
ContractRemoteTeam 11-50H1B No Sponsor

• Plan, design, and implement network, server, and storage infrastructure based on project requirements, capacity plans, and system support. • Problem solving involves basic troubleshooting following the OSI (Open Systems Interconnection) model, making or calling for equipment repairs, and problem escalation. • Monitors, troubleshoots, diagnoses, and remedies server and network related problems and failures. • Installs and configures server and network related hardware/software which meet the company’s security standards.

Florida
$58 - $60 / hour
Job Closed