Threat Detection and Response Analyst

Kaplan (india) Private Limited

Bengaluru/Bangalore

Not disclosed

Work from Office

Full Time

Min. 4 years

Job Details

Job Description

Threat Detection and Response Analyst II (Hybrid)

Job Title 

Threat Detection and Response Analyst II (Hybrid)

Job Description

For more than 80 years, Kaplan has been a trailblazer in education and professional advancement. We are a global company at the intersection of education and technology, focused on collaboration, innovation, and creativity to deliver a best in class educational experience and make Kaplan a great place to work.


Our offices in India opened in Bengaluru in 2018. Since then, our team has fueled growth and innovation across the organization, impacting students worldwide. We are eager to grow and expand with skilled professionals like you who use their talent to build solutions, enable effective learning, and improve students’ lives.


The future of education is here and we are eager to work alongside those who want to make a positive impact and inspire change in the world around them.

The Threat Detection and Response Analyst II is a foundational member of the security team, serving as the first line of defense against cyber threats. This role is responsible for monitoring security alerts, performing initial analysis, and escalating potential incidents. Additionally, this role will assist in refining security detections and participate in guided threat hunting activities to proactively identify threats and protect organizational assets.

Primary/Key Responsibilities

  • Alert Monitoring & Triage: Perform real-time monitoring of security alerts from tools like SIEM and EDR. Conduct initial triage of alerts using established procedures and playbooks to determine if they are true or false positives.

  • Initial Investigation: Analyze security events to gather essential information and context. Use security tools to investigate indicators of compromise (IOCs) and anomalous activity.

  • Incident Escalation: Escalate validated security incidents to Senior Level or higher analysts for in-depth investigation and response. Provide clear and concise information to support the incident response process.

  • Detection Engineering Support: Assist senior analysts in tuning and optimizing existing security alerts. Provide feedback on alert fidelity from a front-line perspective to help reduce false positives and improve the accuracy of detection rules.

  • Guided Threat Hunting: Participate in structured threat hunting missions based on hypotheses and threat intelligence provided by senior team members. Use security tools to search for evidence of specific tactics, techniques, and procedures (TTPs) within the environment.

  • Documentation: Create and maintain detailed tickets for all monitored alerts and escalated incidents. Document findings from threat hunting activities for further analysis.

  • Hybrid Schedule: 3 days remote / 2 days in office

  • 30-day notification period preferred

Minimum Qualifications

  • Bachelor's Degree in Information Systems, Engineering, IT, Computer Science, Cybersecurity, or a related field. Equivalent alternative education, skills, and/or practical experience is also acceptable.

  • 4+ years of experience in an IT, help desk, or cybersecurity role. Experience gained through internships or relevant coursework is also considered.

  • Basic understanding of common attack techniques and the MITRE ATT&CK framework.

  • Familiarity with navigating security dashboards (e.g., SIEM, EDR) to review alerts, log analysis, rule creation, and dashboarding.

  • Foundational knowledge of network protocols, operating systems (Windows, Linux), and cloud environments (AWS, Azure, GCP)

  • Familiarity with ability to perform root cause identification and remediation planning/tracking.

  • Basics of SIEM query languages (e.g., SPL, KQL) to search logs.

  • Strong attention to detail with an inquisitive and analytical mindset.

  • Excellent written and verbal communication skills for documenting and escalating issues.

Preferred Qualifications

  • Relevant entry-level security certifications (e.g., CompTIA Security+, CySA+).

  • Familiarity with scripting languages (e.g., Python, PowerShell) for automation and analysis.

  • Familiarity with SOAR platforms and developing automation playbooks.

  • Exposure to cloud security monitoring and incident response in cloud environments.

  • Exposure to regulatory compliance requirements (e.g., SOX, PCI DSS) as they relate to vulnerability management.

  • Exposure to security frameworks and standards (e.g., NIST, ISO 27001, CIS Benchmarks).

Beyond base salary, our comprehensive total rewards package includes:

Hybrid work model provides a flexible work/life balance
Voluntary Provident Fund is an additional voluntary contribution scheme associated with the statutory Employee Provident Fund (EPF)
Our Gift of Knowledge Program provides tuition assistance and substantial discounts for our employees and close family members
Comprehensive health benefits new hire eligibility starts on day 1 of employment
Generous Paid Time Off includes National holidays(10), Earned leaves(15), sick leave(12), plus one (1) volunteer day to participate and give back to our local communities
Gratuity is applicable upon completion of 5 years as per the Gratuity Act

We are committed to providing a supportive and rewarding work environment where every employee can thrive. You can learn more about our full benefits package and total rewards philosophy here.

At Kaplan, we believe in attracting, rewarding, and retaining exceptional talent. Our compensation philosophy is designed to be competitive within the market, reflecting the value we place on the skills, experience, and contributions of our employees, while taking into account labor market trends and total rewards. The specific compensation offered will be determined by a variety of factors, including but not limited to the candidate's qualifications, relevant experience, education, skills, and market data.

Location

Bangalore, KA, India

Additional Locations 

Employee Type

Employee

Job Functional Area 

Information Security

Business Unit

00091 Kaplan Higher ED

Diversity & Inclusion Statement:


Kaplan is committed to cultivating an inclusive workplace that values diversity, promotes equity, and integrates inclusivity into all aspects of our operations. We are an equal opportunity employer and all qualified applicants will receive consideration for employment regardless of age, race, creed, color, national origin, ancestry, marital status, sexual orientation, gender identity or expression, disability, veteran status, nationality, or sex. We believe that diversity strengthens our organization, fuels innovation, and improves our ability to serve our students, customers, and communities. Learn more about our culture here.

Kaplan considers qualified applicants for employment even if applicants have an arrest or conviction in their background check records. Kaplan complies with related background check regulations, including but not limited to, the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.  There are various positions where certain convictions may disqualify applicants, such as those positions requiring interaction with minors, financial records, or other sensitive and/or confidential information.

Kaplan is a drug-free workplace and complies with applicable laws. 

Experience Level

Mid Level

Job role

Work location

KAP Bangalore IND, India

Department

IT & Information Security

Role / Category

IT Security

Employment type

Full Time

Shift

Day Shift

Job requirements

Experience

Min. 4 years

About company

Name

Kaplan (india) Private Limited

Job posted by Kaplan (india) Private Limited

Apply on company website